Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Virus/Malware Need help! Virus keep coming back., Qhost Trojan! help!

views
     
TSMiracles
post Sep 25 2009, 01:41 PM, updated 17y ago

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
I was afk and when I come back, I saw this virus notification. It keep popping up every 2 secs as we are speaking.
I did scanned in safe mode using Malwarebytes' Anti-Malware. Yes, there are 2 detected and cleaned.

But this Qhost trojan keep coming in after reboot. I have no clue. sad.gif blink.gif


edited : yes, my AVs detected the Qhost Trojan. But after deleting it, it keeps coming back. Very persistent virus.


user posted image


This is my Hijack log.



» Click to show Spoiler - click again to hide... «


This post has been edited by Miracles: Sep 26 2009, 03:11 PM
WebWalker
post Sep 25 2009, 01:46 PM

Computer Geek
********
All Stars
12,851 posts

Joined: May 2005
From: Puchong, Selangor



If your antivirus fail to remove the virus, use other antivirus such as AVG
eXPeri3nc3
post Sep 25 2009, 02:01 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

Hmm. Reboot your computer first and let MBAM run the cleanupscript.
Peterdp
post Sep 25 2009, 02:02 PM

Getting Started
**
Junior Member
135 posts

Joined: Sep 2009
according to google,it modify the DNS server settings to point to an external site. This will prevent normal connectivity to the Internet, as domain names cannot be resolved properly.I was attacked by these kind of virus too.I somehow managed to get rid of it by deleting the connection then scan it while in safe mode.After that,i made a new connection.It works rclxms.gif I don't recommend using avg coz it's detection is not really good.Otherwise,try this link,hopefully it helps: http://www.exterminate-it.com/malpedia/remove-qhosts
TSMiracles
post Sep 26 2009, 01:46 AM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(eXPeri3nc3 @ Sep 25 2009, 02:01 PM)
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

Hmm. Reboot your computer first and let MBAM run the cleanupscript.
*
I did. MBAM asked me to reboot. i clicked Yes. And it still fails me.



QUOTE(Peterdp @ Sep 25 2009, 02:02 PM)
according to google,it modify the DNS server settings to point to an external site. This will prevent normal connectivity to the Internet, as domain names cannot be resolved properly.I was attacked by these kind of virus too.I somehow managed to get rid of it by deleting the connection then scan it while in safe mode.After that,i made a new connection.It works rclxms.gif  I don't recommend using avg coz it's detection is not really good.Otherwise,try this link,hopefully it helps: http://www.exterminate-it.com/malpedia/remove-qhosts
*
Read it and I dont think it solves my prob. my NOD32 helped me deleted it but it keeps coming back.
Peterdp
post Sep 26 2009, 11:42 AM

Getting Started
**
Junior Member
135 posts

Joined: Sep 2009
i guess reformatting is the best way.
eXPeri3nc3
post Sep 26 2009, 01:11 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



Means it's self regenerating. Hmm.

Lol too bad it's been aeons since I last helped in the malware removal scene.

Reboot to safe mode, and do a NOD32 scan and MBAM. Then reboot. See if that helps.
Peterdp
post Sep 26 2009, 01:52 PM

Getting Started
**
Junior Member
135 posts

Joined: Sep 2009
Trojan.Win32.Qhost modifies Windows host file, thus forbidding user to access well known virus protection websites, because the hosts file is used to map IP addresses to host names.
Hosts file location (XP, 2000, NT systems): %System%\drivers\etc\hosts.
Hosts file location (9X systems): %Windows%\hosts.
Virus database update service cannot be accessed as well, so your anti-virus software is not able to update. Trojan.Win32.Qhost is a risky trojan and should be removed immediately to keep your anti-virus program work properly.

Can you access to the internet? Try downloading PcTools internet security.It's trial but there's free promotion for a year by pctools.The virus kept coming back because it infected your network.
eXPeri3nc3
post Sep 26 2009, 02:04 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



Accessing the internet now is like opening a door to backdoors and viruses and say "Oh hey infect me nao!"

Please restrain any internet activity on your current infected computer, and if you need any other tools, download it from a clean PC and transfer it over. Meanwhile try the safe mode scan and see if anything new pops up.
TSMiracles
post Sep 26 2009, 02:08 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(Peterdp @ Sep 26 2009, 01:52 PM)
Trojan.Win32.Qhost modifies Windows host file, thus forbidding user to access well known virus protection websites, because the hosts file is used to map IP addresses to host names.
Hosts file location (XP, 2000, NT systems): %System%\drivers\etc\hosts.
Hosts file location (9X systems): %Windows%\hosts.
Virus database update service cannot be accessed as well, so your anti-virus software is not able to update. Trojan.Win32.Qhost is a risky trojan and should be removed immediately to keep your anti-virus program work properly.

Can you access to the internet? Try downloading PcTools internet security.It's trial but there's free promotion for a year by pctools.The virus kept coming back because it infected your network.
*
QUOTE(eXPeri3nc3 @ Sep 26 2009, 02:04 PM)
Accessing the internet now is like opening a door to backdoors and viruses and say "Oh hey infect me nao!"

Please restrain any internet activity on your current infected computer, and if you need any other tools, download it from a clean PC and transfer it over. Meanwhile try the safe mode scan and see if anything new pops up.
*
Yes, I can access to the internet.

I already scanned few times in safe mode. Virus is persistent. Keeps coming back even though my AV removed it. I thought of the virus could be in the backup files in system restore. But the system restore is turned off already. And now I cant even turn it on. =_="

This post has been edited by Miracles: Sep 26 2009, 02:09 PM
Peterdp
post Sep 26 2009, 02:17 PM

Getting Started
**
Junior Member
135 posts

Joined: Sep 2009
since you have tried almost everything,i suggest it's time to reformat your hard drive.I have been attacked twice,the first time i have to reformat my hard drive but i managed to get rid of it at the second time.
gyver
post Sep 26 2009, 04:12 PM

Regular
******
Senior Member
1,067 posts

Joined: Mar 2005
I don't believe format is the best solution. Please try A Squared first. It never failed me before.

http://www.emsisoft.com/en/software/free/

Please disable your system restore first and maybe do a manual clean in safe mode if still fail. Refer to this:

http://www.antivirusworld.com/articles/virus/qhost.php


Added on September 26, 2009, 4:13 pmBTW please disable your LAN @ internet access while you are cleaning smile.gif

This post has been edited by gyver: Sep 26 2009, 04:13 PM
kyzson69
post Sep 26 2009, 04:45 PM

Psychiatric Patient
*****
Senior Member
939 posts

Joined: Jun 2009
From: ~~ GGTherapy ~~

I use hav same problem like you, then I use bitdefender, problem solve, but my fren reconmend panda... he said very useful too...
gyver
post Sep 26 2009, 04:52 PM

Regular
******
Senior Member
1,067 posts

Joined: Mar 2005
It doesn't matter what type of antivirus you use. As long as can detect and clean, then it is ok. Some can detect and then you have to manually remove.

But if you are stuck like TS, it doesn't hurt to try and download all these free tools first rather than reformating. Reformating is like old school win98 days smile.gif

After cleaning don't forget to uninstall the tools. No use keeping them as TSR since resource hogging only.
TSMiracles
post Sep 26 2009, 06:42 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
Mm, it's not tht i cant delete it. my NOD32 detected it but it just keep coming back.
Peterdp
post Sep 26 2009, 07:00 PM

Getting Started
**
Junior Member
135 posts

Joined: Sep 2009
try open task manager.. is there anything called "Win32/Qhost" in your processes?
gnush85
post Sep 26 2009, 11:22 PM

Customizy
******
Senior Member
1,012 posts

Joined: Aug 2007
From: Heaven of Hell


did you made full scan on your computer?the virus seems located in C:\Recycler, hidden system folder or system32 folder
i never handle this virus before, not sure how to fix it
Removal tool
alternatively u can try Combofix, just run in normal windows, it can terminate explorer automatically
btw make sure u clean all your cookies using Ccleanercoz in ur case, the virus seems want to attack and change your host file, it may come from your pc or network..

This post has been edited by gnush85: Sep 26 2009, 11:23 PM
khoo011
post Sep 26 2009, 11:29 PM

Casual
***
Junior Member
326 posts

Joined: Nov 2004


try scan the virus in safe mode or scan by using dos
Peterdp
post Sep 27 2009, 05:27 PM

Getting Started
**
Junior Member
135 posts

Joined: Sep 2009
do you get redirected to other websites?
TSMiracles
post Sep 28 2009, 09:44 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(gnush85 @ Sep 26 2009, 11:22 PM)
did you made full scan on your computer?the virus seems located in C:\Recycler, hidden system folder or system32 folder
i never handle this virus before, not sure how to fix it
Removal tool
alternatively u can try Combofix, just run in normal windows, it can terminate explorer automatically
btw make sure u clean all your cookies using Ccleanercoz in ur case, the virus seems want to attack and change your host file, it may come from your pc or network..
*
Mm. you sure bout it?


QUOTE(khoo011 @ Sep 26 2009, 11:29 PM)
try scan the virus in safe mode or scan by using dos
*
I did say I scanned in safe mode.

QUOTE(Peterdp @ Sep 27 2009, 05:27 PM)
do you get redirected to other websites?
*
Nope, cos NOD32 keep deleting the virus. I dont think it has the chance to redirect me to another site.






A good Samaritan told me to download HostsXpert.
QUOTE
# Right click on HostsXpert.zip and select Extract All....
# Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
# Click on the Browse button. Click on Desktop. Then click OK.
# Once done, check (tick) the Show extracted files box and click Finish.
# Once extracted, HostsXpert folder will open.
# Double click on HostsXpert.exe to start it.
# On your left hand side, click on Restore MS Hosts File (see screenshot below, boxed up in red).
user posted image
# Mark it as read only after that.
Now, Qhost Trojan is gone. But new problems surfaced. sad.gif


2 Pages  1 2 >Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0207sec    0.76    5 queries    GZIP Disabled
Time is now: 12th December 2025 - 09:48 AM