can't perform searches

  • Thread starter Thread starter Mona
  • Start date Start date
M

Mona

On any search engine, like Yahoo, when I type in a search
request, it takes a long, long time and then I get an
error page. Any suggestions?
 
Hi Mona - You've apparently gotten infected with the QHosts trojan. Read
here for information:

http://www.sarc.com/avcenter/venc/data/trojan.qhosts.html
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100719
http://www3.ca.com/virusinfo/virus.aspx?ID=37191


Try the following:

1. Be sure that you install hotfix 828750 which fixes the exploit that this
virus uses:

http://www.microsoft.com/windows/ie/downloads/critical/828750/default.asp

2. Update and run a complete Anti-Virus software check of your system. Most
of the major AV companies have updated their latest signatures to detect
this virus (for Network Associates (McAfee), be sure to get the EXTRADAT.exe
update from the above page as well as your regular update).

3a. If running your AV doesn't clean it up, go to this page, read the
directions CAREFULLY (particularly about the Restore option) and download
and run the removal tool:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html

3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be removed
by the Removal Tools, and you'll need to do a search to find and just delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
Thank you, both of you. The symantec fix did not work,
but the Brown University tool did. I was not familiar
with this virus, so this was a huge help.
-----Original Message-----
Hi Mona - You've apparently gotten infected with the QHosts trojan. Read
here for information:

http://www.sarc.com/avcenter/venc/data/trojan.qhosts.html
http://us.mcafee.com/virusInfo/default.asp? id=description&virus_k=100719
http://www3.ca.com/virusinfo/virus.aspx?ID=37191


Try the following:

1. Be sure that you install hotfix 828750 which fixes the exploit that this
virus uses:

http://www.microsoft.com/windows/ie/downloads/critical/828 750/default.asp

2. Update and run a complete Anti-Virus software check of your system. Most
of the major AV companies have updated their latest signatures to detect
this virus (for Network Associates (McAfee), be sure to get the EXTRADAT.exe
update from the above page as well as your regular update).

3a. If running your AV doesn't clean it up, go to this page, read the
directions CAREFULLY (particularly about the Restore option) and download
and run the removal tool:

http://securityresponse.symantec.com/avcenter/venc/data/tr ojan.qhosts.removal.tool.html

3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.z
ip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30- 03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be removed
by the Removal Tools, and you'll need to do a search to find and just delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader. exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32 \DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
Mona said:
On any search engine, like Yahoo, when I type in a search
request, it takes a long, long time and then I get an
error page. Any suggestions?


.
 
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
HI Kathleen - You've apparently gotten infected with the QHosts trojan. Read
here for information:

http://www.sarc.com/avcenter/venc/data/trojan.qhosts.html
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100719
http://www3.ca.com/virusinfo/virus.aspx?ID=37191


Try the following:

1. Be sure that you install hotfix 828750 which fixes the exploit that this
virus uses:

http://www.microsoft.com/windows/ie/downloads/critical/828750/default.asp

2. Update and run a complete Anti-Virus software check of your system. Most
of the major AV companies have updated their latest signatures to detect
this virus (for Network Associates (McAfee), be sure to get the EXTRADAT.exe
update from the above page as well as your regular update).

3a. If running your AV doesn't clean it up, go to this page, read the
directions CAREFULLY (particularly about the Restore option) and download
and run the removal tool:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html

3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be removed
by the Removal Tools, and you'll need to do a search to find and just delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
Is cpanel associated with Qhosts? I thought it wasn't.

--
Install the latest IE cumulative patch for protection against QHost:
http://www.microsoft.com/security/security_bulletins/ms03-040.asp
More information about QHosts can be found here:
http://www.mvps.org/inetexplorer/darnit_3.htm#qhost
________________________________________
Sandi - Microsoft MVP since 1999 (IE/OE)
http://www.mvps.org/inetexplorer

Jim Byrd said:
HI Kathleen - You've apparently gotten infected with the QHosts trojan. Read
here for information:

http://www.sarc.com/avcenter/venc/data/trojan.qhosts.html
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100719
http://www3.ca.com/virusinfo/virus.aspx?ID=37191


Try the following:

1. Be sure that you install hotfix 828750 which fixes the exploit that this
virus uses:

http://www.microsoft.com/windows/ie/downloads/critical/828750/default.asp

2. Update and run a complete Anti-Virus software check of your system. Most
of the major AV companies have updated their latest signatures to detect
this virus (for Network Associates (McAfee), be sure to get the EXTRADAT.exe
update from the above page as well as your regular update).

3a. If running your AV doesn't clean it up, go to this page, read the
directions CAREFULLY (particularly about the Restore option) and download
and run the removal tool:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html

3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be removed
by the Removal Tools, and you'll need to do a search to find and just delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
Kathleen said:
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
Hi Sandi - I honestly don't know in this case. The rest of the symptoms are
pure QHosts, and the variants seem to be growing daily, so my first thought
was to have her check that and then proceed from there.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
Sandi - Microsoft MVP said:
Is cpanel associated with Qhosts? I thought it wasn't.


Jim Byrd said:
HI Kathleen - You've apparently gotten infected with the QHosts trojan. Read
here for information:

http://www.sarc.com/avcenter/venc/data/trojan.qhosts.html
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100719
http://www3.ca.com/virusinfo/virus.aspx?ID=37191


Try the following:

1. Be sure that you install hotfix 828750 which fixes the exploit that this
virus uses:

http://www.microsoft.com/windows/ie/downloads/critical/828750/default.asp

2. Update and run a complete Anti-Virus software check of your system. Most
of the major AV companies have updated their latest signatures to detect
this virus (for Network Associates (McAfee), be sure to get the EXTRADAT.exe
update from the above page as well as your regular update).

3a. If running your AV doesn't clean it up, go to this page, read the
directions CAREFULLY (particularly about the Restore option) and download
and run the removal tool:
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html
3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be removed
by the Removal Tools, and you'll need to do a search to find and just delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
Kathleen said:
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
I'm on a hijacking mailing list, and I'm sure we were sent the files that
cause the cpanel infection... I'll check and let you know.

--
Install the latest IE cumulative patch for protection against QHost:
http://www.microsoft.com/security/security_bulletins/ms03-040.asp
More information about QHosts can be found here:
http://www.mvps.org/inetexplorer/darnit_3.htm#qhost
________________________________________
Sandi - Microsoft MVP since 1999 (IE/OE)
http://www.mvps.org/inetexplorer

Jim Byrd said:
Hi Sandi - I honestly don't know in this case. The rest of the symptoms are
pure QHosts, and the variants seem to be growing daily, so my first thought
was to have her check that and then proceed from there.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
Sandi - Microsoft MVP said:
Is cpanel associated with Qhosts? I thought it wasn't.
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html
3b. An alternative that by report may work better than the Symantec
tool
is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be removed
by the Removal Tools, and you'll need to do a search to find and just delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan
to
use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In Kathleen <[email protected]> typed:
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
Thanks Sandi.

--
Regards, Jim


In
Sandi - Microsoft MVP said:
I'm on a hijacking mailing list, and I'm sure we were sent the files that
cause the cpanel infection... I'll check and let you know.


Jim Byrd said:
Hi Sandi - I honestly don't know in this case. The rest of the symptoms are
pure QHosts, and the variants seem to be growing daily, so my first thought
was to have her check that and then proceed from there.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html
3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY
PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting
that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be
removed
by the Removal Tools, and you'll need to do a search to find and just
delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the "Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been
using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a
Hosts
File), then you'll need to reset the new default you've created up for
that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In Kathleen <[email protected]> typed:
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
Hi Jim,

Now I see the source for the confusion; Qhosts doesn't hijack you and send
you to the cpanel site, it sends you to a third party site that has been
shut down and *then* cpanel comes into play, which is a relief, because
cpanel is a 'legitimate' business, unlike the search engines/porn sites that
are normally the domain of hijackers/viruses.

--
Install the latest IE cumulative patch for protection against QHost:
http://www.microsoft.com/security/security_bulletins/ms03-040.asp
More information about QHosts can be found here:
http://www.mvps.org/inetexplorer/darnit_3.htm#qhost
________________________________________
Sandi - Microsoft MVP since 1999 (IE/OE)
http://www.mvps.org/inetexplorer


Jim Byrd said:
Thanks Sandi.

--
Regards, Jim


In
Sandi - Microsoft MVP said:
I'm on a hijacking mailing list, and I'm sure we were sent the files that
cause the cpanel infection... I'll check and let you know.


symptoms
are
http://www.microsoft.com/windows/ie/downloads/critical/828750/default.asp
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html
3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY
PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting
that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike
Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS
file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files
on
your machine with the trojan's settings some of which cannot not be
removed
by the Removal Tools, and you'll need to do a search to find and just
delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the
"Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file
that
it
created to "HOSTS" (no quotes, all caps, no extension). If you've been
using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a
Hosts
File), then you'll need to reset the new default you've created up for
that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well
as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In Kathleen <[email protected]> typed:
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
OK Sandi - that makes sense.

--
Regards, Jim


In
Sandi - Microsoft MVP said:
Hi Jim,

Now I see the source for the confusion; Qhosts doesn't hijack you and send
you to the cpanel site, it sends you to a third party site that has been
shut down and *then* cpanel comes into play, which is a relief, because
cpanel is a 'legitimate' business, unlike the search engines/porn sites that
are normally the domain of hijackers/viruses.


Jim Byrd said:
Thanks Sandi.

--
Regards, Jim


In
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html
3b. An alternative that by report may work better than the Symantec tool is
the Brown University Removal Tool, here:

http://software.brown.edu/dist/w-cleanqhosts.html THIS WOULD BE MY
PRIMARY
RECOMMENDATION

If that still doesn't clean it up (and a number of people are reporting that
it did not with the Symantec tool), then follow the Manual Removal
instructions at the link in 3a. The following is courtesy of Mike
Burgess:

"Does a HOSTS file still exist in Windows\Help?
Trojan Qhosts hijacks the HOSTS file, however unlike normal
redirectors,
this one hides the HOSTS file in the "Windows\Help" folder. It then
creates entries that redirects all major search engines to a website.
Note: this website has now been removed, thus the DNS errors.
[more info]
http://www.mvps.org/winhelp2002/hosts.htm (bottom of page)
Run the beta version of HijackThis
(http://www.spywareinfo.com/~merijn/files/beta/hijackthis.zip)
_______________________________________
Mike Burgess http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS
file
http://www.mvps.org/winhelp2002/hosts.htm [updated 9-30-03]
Please post replies to this Newsgroup, email address is invalid"


Just to follow up on this - there may be multiple different HOSTS files on
your machine with the trojan's settings some of which cannot not be
removed
by the Removal Tools, and you'll need to do a search to find and just
delete
them all, or clean them per the manual directions at the Symantec site.

4. You probably will then need to restore your HOSTS file if you plan to use
it for DNS speedup and/or ad blocking. Download the Hosts File Reader:

http://members.shaw.ca/techcd/VB_Projects/HostsFileReader.exe

To create a new Default version of HOSTS, run the program, click the
"Read
Hosts File" button, click the button labeled "Reset Defaults" and click
"Save Changes." Note that this is NOT a recreation of your original
HOSTS
file, but a brand new "initialized" one. Now go to normal HOSTS file
location (Windows XP\2000 Location: - C:\WINDOWS\SYSTEM32\DRIVERS\ETC
or
Windows 98\ME Location: - C:\WINDOWS) and rename the "hosts" file that it
created to "HOSTS" (no quotes, all caps, no extension). If you've been using
your HOSTS file for ad blocking (see
http://www.mvps.org/winhelp2002/hosts.htm Blocking Unwanted Ads with a Hosts
File), then you'll need to reset the new default you've created up for that
purpose. (Recommended, BTW - it also blocks a lot of "malware" as well as
offensive advertising.)


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In Kathleen <[email protected]> typed:
I also suddenly can't use any search engines (as of last
week). I get the "page can not be found" error when
trying a MSN or Yahoo search and when I try to do a Google
search I end up at cPanel. ???

I've tried re-installing IE6 and the latest updates, etc
and that doesn't work (although it also seems that the
attempt to re-install doesn't actually finish either.)

I've also scanned for and cleaned off viruses and
installed all the latest critical Windows updates (I'm
using Windows 2000)

Can anyone help me?

Thanks in advance!
:)
 
I have the same issue but what appears more complex is that

I do not have any single reference to the any of the regsirty entries
Or I do not have any other host file just the single one at
system32\drivers\etc
I do not have the bldmp temp directory.

I have applied adware, spybot, hijackthis, the beta hijack this, the
BROWN university qhost finder tool, symantecs qhost finder, updated AV
signatures.

I have applied the ms-patches too.

I have gone through all the recommended registry strings adviced by
many in different groups...not a single one exist. I deleted the host
...recreated a new one...re installed tcpip....

but no go at all. i can't access google, yahoo, yahoo mail and quite
a number of other web sites tooo... I can only the google groups by
using other browsers.

There is something being overlooked...some kind of camouflage cleverly
done here
by QHOST and mixture of variants. MY os is Xp Professional SP1.

Kindly keep up u r great work guys and see if you can find a fix ...

Cheers Thanks.
 
Back
Top