The Trojan:Win32/QHosts.BH is a malicious Trojan infection that mostly spreads through spam email attachments, p2p sharings, unsafe browsing, and freeware downloads. Once installed, the Trojan:Win32/QHosts.BH can cause severe damage to the windows based computers. This dangerous Trojan downloads executable files and save them along with sensitive system files as soon as it enters into your system. Whenever you try to open your windows, this application starts automatically due to which the speed of the system reduced considerably, and you are unable to perform any task on the infected system. Once installed, the Trojan:Win32/QHosts.BH modify most of the system settings including the DNS settings, domain name server setup of the computer, and browser settings. This malicious application has the ability to hijack the browser, and change your default search engine as well as a home page. All your searching efforts redirected towards phishing websites where you are encouraged to buy a certain type of products from the unknown suppliers.
The Manual Removal of Trojan:Win32/QHosts.BH
Once detected, you have to delete this dangerous Trojan virus as it can damage your computer completely. You can remove this malicious application by using any automatic removal tool that is easily available online, but if you are looking for a manual removal method, that is as under:-
Start Your Computer in the Safe Mode
Restart the infected computer, and press F8 key to access the boot option menu on the screen of your computer. From the list of boot options you have to select the safe mode option and press the enter key to restart the system in the safe mode.
Delete the Processes through Windows Task Manager
Once the computer starts working in the safe mode, you now can end the malicious processes related to this virus . Following are the processes that are required to be deleted by accessing the task manager through Ctrl+Alt+Delete keys, and under the processes tab you can see a list of process:-
%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
Delete the Associated Data
Remove the files that are associated with this virus. In this regard, following are the files that are suspicious and required to be deleted:-
Reverse the Modification in the Windows Registry
The final step of manual removal is to clean the windows registry by removing the suspicious entries. You have to click the start menu, choose Run, type RegEdit, and press OK to open the registry editor. With the help of the registry editor you have to remove the following suspicious entries:-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/QHosts.BH\DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/QHosts.BH\UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:Win32/QHosts.BH\ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
After deleting the above mentioned entries related to the Trojan:Win32/QHosts.BH you have to restart the computer in the normal mode to see the success of manual removal process.