About.com skrev:
Delude.B (a.k.a.QHosts-1) Trojan
On the evening of September 29th, a mysterious sequence of events led to the discovery of a new Trojan being served via a banner ad at FortuneCity.com. The banner ad was emanating from a website hosted by Everyone's Internet, Inc. Users of XP or Windows 2000 who visited the FortuneCity.com website during the infected period were subjected to having their Internet Explorer browser hijacked.
DNS settings were changed to point to 69.57.146.14 and 69.57.147.175, a new HOSTS file was dropped to their system, and the Internet Explorer startpage changed to http://www.google.com. The registry was also changed to point to the new HOSTS. Because of the HOSTS and DNS setting changes, affected users would first be redirected to the malicious site, served up advertising banners, and then redirected back to the legitimate site.
For example, an affected user who attempted to access http://www.google.com would first be redirected to 216.127.92.38, served up a range of advertisements, and then redirected back to http://www.google.com.
Läs mer här:
http://www.f-secure.com/v-descs/delude.shtml

