Home
High
Med
Low
AWA
ASA
News
Google Forum

Double Your Adwords Profits in 7 minutes!

Tools

$7 Secrets
People are making thousands of dollars using the techniques and scripts included with this popular report. And it costs only $7! [Read more...]

AdWords Secrets
Free 5-day course that can help you make money using Google AdWords.

Articles for 25 Cents Each
Get 400 exact keyword optimized articles, delivered to your inbox, every month. A new and inexpensive way to build keyword rich web sites that can make money, month after month.

Trade Links with 5,000+ Sites
This is not an automated link system. The Add URL Directory is a directory that lists over 5,000 "add url" pages that have forms that you can use to add your site and exchange links. The directory is divided into categories, helping you find sites in your topic area.

Backlink Analyzer
Automatically analyze the anchor text of all of your backlinks. Analyze your competitors' backlinks to see how you compare in the anchor text department.

SEO Web Site Templates
Web site templates that have been designed specifically for search engine optimization (SEO).




My sponsered child, Hama from Niger, Africa
A portion of the proceeds from this site help sponsor Hama from Niger. Learn more about Child Sponsorship.

QHosts



العربيه

Author Message
GoogleGuy Says







PostPosted: October 4, 2003 10:38 AM 

Importance: Medium

GoogleGuy provides info about the QHosts trojan, which has been spreading lately, hijacking Google.com and other domains.

GoogleGuy Says: [Link to quote]

Hey scumm_bar, the qhosts trojan horse actually makes a new hosts file in a directory people don't check (windows\help or winnt\help) and then changes a registry key to point to the new location. Sounds like you solved your problem already--everyone reading this does make backups, right?--but just wanted to let you know.


Paula

Posts: 1

Reply: 1



PostPosted: October 10, 2003 9:25 PM 

Someone suggested I speak to you.My google has been hijacked.I ran the removal tool for trojan.qhost but it didnt come up.I also have used spybot,Symantec .Any other clues .

thanks,


Paula

Dave

Posts: 1

Reply: 2



PostPosted: October 21, 2003 6:46 PM 

Use Google's IP address rather than www.google.com

Their IP is...

http://216.239.57.99/

noel

Posts: 3

Reply: 3



PostPosted: November 30, 2003 11:49 PM 

I seem to have QHOSTS because i cant acess the google site.But why doesnt my avg anti-virus did not detect it? Does it infect files?Im wary to download files to my other computer from teh one infected with the QHOSTS because it might crew it up.

charles

Posts: 1

Reply: 4



PostPosted: December 15, 2003 6:49 AM 

I had the Qhosts virus and the symantec Qhosts removal program did not find the virus. I went into my windows\help directory and removed the file hosts and restarted my pc. This solved the problem.

noel

Posts: 3

Reply: 5



PostPosted: February 11, 2004 4:01 PM 

I found this in my program files,internet explorer Q824145 is this the q host virus?

noel

Posts: 3

Reply: 6



PostPosted: June 26, 2004 1:46 PM 

I found this in my program files,internet explorer Q824145 is this the q host virus?

Naresh

Posts: 1

Reply: 7



PostPosted: April 2, 2005 2:50 AM 

I found the virus trojan.qhosts. I am unable repaire it.Norton antivirus detects it and removed but again it's come. Please Help me out..

Dan

Posts: 1

Reply: 8



PostPosted: April 25, 2005 12:37 AM 

I love how no one's helped here.

The suggestion of "windows\help directory and removed the file hosts and restarted my pc. This solved the problem." didn't work for me, as there is no file in that directory with the word hosts in it, let alone a file named hosts.

I also ran the Norton Removal Tool, and it did not find the virus. Ironically seconds after running the tool, the Norton AV (2005) reported I had the virus. WTF is going on!?

Dan

Dave

Posts: no

Reply: 9



PostPosted: May 30, 2005 3:05 AM 

We had something similar with the qhosts virus
I think it's a new variant.
MCafee finds & removes the infected file but the infected file still contained malicious
code that disables your virusscanner and blocks Taskmanager from starting up.

Detection:
-Check if virusscanner is disabled
-check if you can start taskmanager

Removal:
-Start in safe mode or use a third party taskmanager (like sysinternal's Process Explorer)
-Kill the infected process (infected file)
-Delete the infected file (should be in System32 dir)
-remove the regkeys that start the infected file:
HKLM\software\windows\currentversion\run\WINDOWS SYSTEM
HKLM\software\windows\currentversion\runservices\WINDOWS SYSTEM



Subscribe to this discussion: Email

Join the conversation:









Remember personal info?





Check to Subscribe to this Comment:
(email field must be filled in)



Subscribe Without Commenting