Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Virus/Malware Need help! Virus keep coming back., Qhost Trojan! help!

views
     
TSMiracles
post Sep 25 2009, 01:41 PM, updated 17y ago

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
I was afk and when I come back, I saw this virus notification. It keep popping up every 2 secs as we are speaking.
I did scanned in safe mode using Malwarebytes' Anti-Malware. Yes, there are 2 detected and cleaned.

But this Qhost trojan keep coming in after reboot. I have no clue. sad.gif blink.gif


edited : yes, my AVs detected the Qhost Trojan. But after deleting it, it keeps coming back. Very persistent virus.


user posted image


This is my Hijack log.



» Click to show Spoiler - click again to hide... «


This post has been edited by Miracles: Sep 26 2009, 03:11 PM
TSMiracles
post Sep 26 2009, 01:46 AM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(eXPeri3nc3 @ Sep 25 2009, 02:01 PM)
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

Hmm. Reboot your computer first and let MBAM run the cleanupscript.
*
I did. MBAM asked me to reboot. i clicked Yes. And it still fails me.



QUOTE(Peterdp @ Sep 25 2009, 02:02 PM)
according to google,it modify the DNS server settings to point to an external site. This will prevent normal connectivity to the Internet, as domain names cannot be resolved properly.I was attacked by these kind of virus too.I somehow managed to get rid of it by deleting the connection then scan it while in safe mode.After that,i made a new connection.It works rclxms.gif  I don't recommend using avg coz it's detection is not really good.Otherwise,try this link,hopefully it helps: http://www.exterminate-it.com/malpedia/remove-qhosts
*
Read it and I dont think it solves my prob. my NOD32 helped me deleted it but it keeps coming back.
TSMiracles
post Sep 26 2009, 02:08 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(Peterdp @ Sep 26 2009, 01:52 PM)
Trojan.Win32.Qhost modifies Windows host file, thus forbidding user to access well known virus protection websites, because the hosts file is used to map IP addresses to host names.
Hosts file location (XP, 2000, NT systems): %System%\drivers\etc\hosts.
Hosts file location (9X systems): %Windows%\hosts.
Virus database update service cannot be accessed as well, so your anti-virus software is not able to update. Trojan.Win32.Qhost is a risky trojan and should be removed immediately to keep your anti-virus program work properly.

Can you access to the internet? Try downloading PcTools internet security.It's trial but there's free promotion for a year by pctools.The virus kept coming back because it infected your network.
*
QUOTE(eXPeri3nc3 @ Sep 26 2009, 02:04 PM)
Accessing the internet now is like opening a door to backdoors and viruses and say "Oh hey infect me nao!"

Please restrain any internet activity on your current infected computer, and if you need any other tools, download it from a clean PC and transfer it over. Meanwhile try the safe mode scan and see if anything new pops up.
*
Yes, I can access to the internet.

I already scanned few times in safe mode. Virus is persistent. Keeps coming back even though my AV removed it. I thought of the virus could be in the backup files in system restore. But the system restore is turned off already. And now I cant even turn it on. =_="

This post has been edited by Miracles: Sep 26 2009, 02:09 PM
TSMiracles
post Sep 26 2009, 06:42 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
Mm, it's not tht i cant delete it. my NOD32 detected it but it just keep coming back.
TSMiracles
post Sep 28 2009, 09:44 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
QUOTE(gnush85 @ Sep 26 2009, 11:22 PM)
did you made full scan on your computer?the virus seems located in C:\Recycler, hidden system folder or system32 folder
i never handle this virus before, not sure how to fix it
Removal tool
alternatively u can try Combofix, just run in normal windows, it can terminate explorer automatically
btw make sure u clean all your cookies using Ccleanercoz in ur case, the virus seems want to attack and change your host file, it may come from your pc or network..
*
Mm. you sure bout it?


QUOTE(khoo011 @ Sep 26 2009, 11:29 PM)
try scan the virus in safe mode or scan by using dos
*
I did say I scanned in safe mode.

QUOTE(Peterdp @ Sep 27 2009, 05:27 PM)
do you get redirected to other websites?
*
Nope, cos NOD32 keep deleting the virus. I dont think it has the chance to redirect me to another site.






A good Samaritan told me to download HostsXpert.
QUOTE
# Right click on HostsXpert.zip and select Extract All....
# Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
# Click on the Browse button. Click on Desktop. Then click OK.
# Once done, check (tick) the Show extracted files box and click Finish.
# Once extracted, HostsXpert folder will open.
# Double click on HostsXpert.exe to start it.
# On your left hand side, click on Restore MS Hosts File (see screenshot below, boxed up in red).
user posted image
# Mark it as read only after that.
Now, Qhost Trojan is gone. But new problems surfaced. sad.gif

TSMiracles
post Sep 28 2009, 09:57 PM

★ Detective /K ★
******
Senior Member
1,171 posts

Joined: Dec 2006
Erm, it restores the default hosts file then after marking it as "Read only..", the clean hosts file could not be replaced by Qhost Trojan. Thus stopping it from coming back. The same theory as autorun.inf by Flash Disinfector, if im not mistaken. =x cos the person told me to do so, didnt tell me in detail what it does lol.


Added on September 28, 2009, 10:13 pm

http://forum.lowyat.net/topic/1177405
<-- made new topic for new problem.

so this Qhost Trojan is solved.

This post has been edited by Miracles: Sep 28 2009, 10:13 PM

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0193sec    0.61    6 queries    GZIP Disabled
Time is now: 13th December 2025 - 01:45 AM