Google Forum

Double Your Adwords Profits in 7 minutes!


$7 Secrets
People are making thousands of dollars using the techniques and scripts included with this popular report. And it costs only $7! [Read more...]

AdWords Secrets
Free 5-day course that can help you make money using Google AdWords.

Articles for 25 Cents Each
Get 400 exact keyword optimized articles, delivered to your inbox, every month. A new and inexpensive way to build keyword rich web sites that can make money, month after month.

Trade Links with 5,000+ Sites
This is not an automated link system. The Add URL Directory is a directory that lists over 5,000 "add url" pages that have forms that you can use to add your site and exchange links. The directory is divided into categories, helping you find sites in your topic area.

Backlink Analyzer
Automatically analyze the anchor text of all of your backlinks. Analyze your competitors' backlinks to see how you compare in the anchor text department.

SEO Web Site Templates
Web site templates that have been designed specifically for search engine optimization (SEO).

My sponsered child, Hama from Niger, Africa
A portion of the proceeds from this site help sponsor Hama from Niger. Learn more about Child Sponsorship.



Author Message
GoogleGuy Says

PostPosted: October 4, 2003 10:38 AM 

Importance: Medium

GoogleGuy provides info about the QHosts trojan, which has been spreading lately, hijacking Google.com and other domains.

GoogleGuy Says: [Link to quote]

Hey scumm_bar, the qhosts trojan horse actually makes a new hosts file in a directory people don't check (windows\help or winnt\help) and then changes a registry key to point to the new location. Sounds like you solved your problem already--everyone reading this does make backups, right?--but just wanted to let you know.


Posts: 1

Reply: 1

PostPosted: October 10, 2003 9:25 PM 

Someone suggested I speak to you.My google has been hijacked.I ran the removal tool for trojan.qhost but it didnt come up.I also have used spybot,Symantec .Any other clues .




Posts: 1

Reply: 2

PostPosted: October 21, 2003 6:46 PM 

Use Google's IP address rather than www.google.com

Their IP is...


Posts: 3

Reply: 3

PostPosted: November 30, 2003 11:49 PM 

I seem to have QHOSTS because i cant acess the google site.But why doesnt my avg anti-virus did not detect it? Does it infect files?Im wary to download files to my other computer from teh one infected with the QHOSTS because it might crew it up.


Posts: 1

Reply: 4

PostPosted: December 15, 2003 6:49 AM 

I had the Qhosts virus and the symantec Qhosts removal program did not find the virus. I went into my windows\help directory and removed the file hosts and restarted my pc. This solved the problem.


Posts: 3

Reply: 5

PostPosted: February 11, 2004 4:01 PM 

I found this in my program files,internet explorer Q824145 is this the q host virus?


Posts: 3

Reply: 6

PostPosted: June 26, 2004 1:46 PM 

I found this in my program files,internet explorer Q824145 is this the q host virus?


Posts: 1

Reply: 7

PostPosted: April 2, 2005 2:50 AM 

I found the virus trojan.qhosts. I am unable repaire it.Norton antivirus detects it and removed but again it's come. Please Help me out..


Posts: 1

Reply: 8

PostPosted: April 25, 2005 12:37 AM 

I love how no one's helped here.

The suggestion of "windows\help directory and removed the file hosts and restarted my pc. This solved the problem." didn't work for me, as there is no file in that directory with the word hosts in it, let alone a file named hosts.

I also ran the Norton Removal Tool, and it did not find the virus. Ironically seconds after running the tool, the Norton AV (2005) reported I had the virus. WTF is going on!?



Posts: no

Reply: 9

PostPosted: May 30, 2005 3:05 AM 

We had something similar with the qhosts virus
I think it's a new variant.
MCafee finds & removes the infected file but the infected file still contained malicious
code that disables your virusscanner and blocks Taskmanager from starting up.

-Check if virusscanner is disabled
-check if you can start taskmanager

-Start in safe mode or use a third party taskmanager (like sysinternal's Process Explorer)
-Kill the infected process (infected file)
-Delete the infected file (should be in System32 dir)
-remove the regkeys that start the infected file:
HKLM\software\windows\currentversion\run\WINDOWS SYSTEM
HKLM\software\windows\currentversion\runservices\WINDOWS SYSTEM

Subscribe to this discussion: Email

Join the conversation:

Remember personal info?

Check to Subscribe to this Comment:
(email field must be filled in)

Subscribe Without Commenting