Q host TROJAN Please Help

  • Thread starter Thread starter art
  • Start date Start date
A

art

Here is the situation.. after reading several posts.. i
have already ran the host scan on symmantec .. nothing
shows up but after looking up hosts in my help i do have
the search engine files as perscribed..

this is what i have done

a) Downloaded the microsoft patch..
b) Downloaded and ran the search and destroy
c) downloaded the Hijacker tool
d) deleted the things in my Hosts (help file) with the
search engine names

but i still am having the same problem

PLease someone help. It would be greatly appreciated
 
Update:
I have deleted the hosts (help file again)
rebooted and this has done the trick..
my question now is..

have i gotten rid of the bug???
please note that after using all the programs.. only
deleting the files inside the host help file by hand did
the trick..

please help thanks
 
art said:
Here is the situation.. after reading several posts.. i
have already ran the host scan on symmantec .. nothing
shows up but after looking up hosts in my help i do have
the search engine files as perscribed..

this is what i have done

a) Downloaded the microsoft patch..
b) Downloaded and ran the search and destroy
c) downloaded the Hijacker tool
d) deleted the things in my Hosts (help file) with the
search engine names

but i still am having the same problem

PLease someone help. It would be greatly appreciated

Did you successfully run the "Hijack This" tool and post your logs?
More info on that if have not completed this task.
http://mvps.org/winhelp2002/unwanted.htm

HTH


--

siljaline MS MVP IE/OE

(Please reply to group, as reply address is invalid, so that we can all benefit)


"Arguing with anonymous strangers on the Internet is a sucker's game
because they almost always turn out to be -- or to be indistinguishable from
-- self-righteous sixteen-year-olds possessing infinite amounts of free time."
- Neil Stephenson, _Cryptonomicon_
 
Hi Art - See if these directions help:

You've apparently gotten infected with the QHosts virus. Read here for
information:

http://www.sarc.com/avcenter/venc/data/trojan.qhosts.html
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100719
http://www3.ca.com/virusinfo/virus.aspx?ID=37191


Try the following:

1. Be sure that you install hotfix 828750 which fixes the exploit that this
virus uses:

http://www.microsoft.com/windows/ie/downloads/critical/828750/default.asp

2. Update and run a complete Anti-Virus software check of your system. Most
of the major AV companies have updated their latest signatures to detect
this virus (for Network Associates, be sure to get the EXTRADAT.exe update
from the above page as well as your regular update).

3. If running your AV doesn't clean it up, go to this page, read the
directions CAREFULLY (particularly about the Restore option) and download
and run the removal tool:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html

If that still doesn't clean it up (and a number of people are reporting that
it did not), then follow the Manual Removal instructions there. The
following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis (link on Hosts page)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings, and you'll need to find and delete
them all, per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Now go to normal HOSTS file location (Windows XP\2000
Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or Windows 98\ME Location: -
C:\WINDOWS) and rename the "hosts" that it created to "HOSTS" (no quotes,
all caps, no extension). If you've been using your HOSTS file for ad
blocking (see http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted
Ads with a Hosts File), then you'll need to reset the new default you've
created up for that purpose.

See if this helps.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
-----Original Message-----
Update:
I have deleted the hosts (help file again)
rebooted and this has done the trick..
my question now is..

have i gotten rid of the bug???
please note that after using all the programs.. only
deleting the files inside the host help file by hand did
the trick..

please help thanks

The "bug" got to you because you didn't have the MS patch
for EI. It's program was to creat the fake "Hosts" info.
you got the patch now and cleaned up the "hosts" files
(hope you did a search for "hosts" and looked at all of
them because I had TWO, one in Windows\system and one in
Windows\help) so the next time you run into this "bug" it
won't be able do anything to you.
 
-----Original Message-----
Here is the situation.. after reading several posts.. i
have already ran the host scan on symmantec .. nothing
shows up but after looking up hosts in my help i do have
the search engine files as perscribed..

this is what i have done

a) Downloaded the microsoft patch..
b) Downloaded and ran the search and destroy
c) downloaded the Hijacker tool
d) deleted the things in my Hosts (help file) with the
search engine names

but i still am having the same problem

PLease someone help. It would be greatly appreciated
.
***I have done the same things and am having the same
problem. When is Microsoft going to help us.???
 
Carolyn,
[manual method]
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html

You can detect "Qhosts" via a new beta version of HijackThis
http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip
[more info]
http://forums.spywareinfo.com/index.php?showtopic=12127

For instruction on using HijackThis!
http://www.mvps.org/winhelp2002/unwanted.htm
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid
--
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top