1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Is cyber defender safe?

Discussion in 'Security and Privacy' started by Bubba, 2008/04/02.

  1. 2008/04/02
    Bubba

    Bubba Inactive Thread Starter

    Joined:
    2004/10/14
    Messages:
    268
    Likes Received:
    0
    I've recently found that I have a virus called win32qhost.mg and was trying to find a program to remove it. It says it out performs all of the well known others and lists them. Is it safe to use?
     
  2. 2008/04/02
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    No. See here and here

    I can't find anything called 'win32qhost.mg', is that a typo? And what was it that claims you have this infection on your system?
     

  3. to hide this advert.

  4. 2008/04/02
    mailman Lifetime Subscription

    mailman Geek Member

    Joined:
    2004/01/17
    Messages:
    1,901
    Likes Received:
    11
    Might be a new (or ficticious?) variant. I Googled win32qhost (without the .mg) and came up with some hits.
     
  5. 2008/04/03
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Yep, could be.
     
  6. 2008/04/03
    Bubba

    Bubba Inactive Thread Starter

    Joined:
    2004/10/14
    Messages:
    268
    Likes Received:
    0
    I was just going by what the scanner I used said. It's name is Kaspersky's on line scanner. This is the last part of the scan that shows the trojans and some spyware infections.

    C:\Documents and Settings\john\.housecall6.6\Quarantine\SeekmoTB.dll.bac_a03132 Infected: not-a-virus:AdWare.Win32.Agent.c skipped

    C:\Documents and Settings\john\My Documents\ww2rescue.exe/file451 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped

    C:\Documents and Settings\john\My Documents\ww2rescue.exe/file452 Infected: not-a-virus:Server-Proxy.Win32.MarketScore.k skipped

    C:\Documents and Settings\john\My Documents\ww2rescue.exe/file453 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

    C:\Documents and Settings\john\My Documents\ww2rescue.exe Inno: infected - 3 skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\WINDOWS\system32\drivers\etc\hosts.20070828-214029.backup Infected: Trojan.Win32.Qhost.mg skipped

    C:\WINDOWS\system32\drivers\etc\hosts.20070828-214030.backup Infected: Trojan.Win32.Qhost.mg skipped

    D:\25bbe8f1d2e98ae45a383005147b\ffastun.ffo Object is locked skipped

    D:\25bbe8f1d2e98ae45a383005147b\ffastun0.ffx Object is locked skipped

    D:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

    D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

    D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

    D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

    D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-3-31-2008( 20-7-7 ).LOG Object is locked skipped

    D:\Documents and Settings\John Matthews\Cookies\index.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\History\History.IE5\index.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\History\History.IE5\MSHist012008040120080402\index.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\Temp\~DF7716.tmp Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\Temp\~DF772D.tmp Object is locked skipped

    D:\Documents and Settings\John Matthews\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\ntuser.dat Object is locked skipped

    D:\Documents and Settings\John Matthews\NTUSER.DAT.LOG Object is locked skipped

    D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

    D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

    D:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

    D:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped

    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    D:\System Volume Information\_restore{84ED5C82-C100-4A9C-A172-5240B436D570}\RP177\A0016716.rbf Infected: not-a-virus:FraudTool.Win32.AntiSpyware.k skipped

    D:\System Volume Information\_restore{84ED5C82-C100-4A9C-A172-5240B436D570}\RP184\change.log Object is locked skipped

    D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    D:\WINDOWS\SchedLgU.Txt Object is locked skipped

    D:\WINDOWS\SoftwareDistribution\EventCache\{9D995534-9F47-4A1E-B7D8-536B4D62EC0D}.bin Object is locked skipped

    D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    D:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

    D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    D:\WINDOWS\system32\config\default Object is locked skipped

    D:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped

    D:\WINDOWS\system32\config\Internet.evt Object is locked skipped

    D:\WINDOWS\system32\config\SAM Object is locked skipped

    D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    D:\WINDOWS\system32\config\SECURITY Object is locked skipped

    D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    D:\WINDOWS\system32\config\software Object is locked skipped

    D:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped

    D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    D:\WINDOWS\system32\config\system Object is locked skipped

    D:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped

    D:\WINDOWS\system32\h323log.txt Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    D:\WINDOWS\Temp\Perflib_Perfdata_5b8.dat Object is locked skipped

    D:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped

    D:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.
     
    Last edited: 2008/04/03
  7. 2008/04/03
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Code:
    C:\Documents and Settings\john\.housecall6.6\Quarantine\SeekmoTB.dll.bac_a03132 Infected: not-a-virus:AdWare.Win32.Agent.c skipped 
    No threat, quarentined already. Delete quarantine folder.
    Code:
    C:\Documents and Settings\john\My Documents\ww2rescue.exe/file451 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped 
    
    C:\Documents and Settings\john\My Documents\ww2rescue.exe/file452 Infected: not-a-virus:Server-Proxy.Win32.MarketScore.k skipped 
    
    C:\Documents and Settings\john\My Documents\ww2rescue.exe/file453 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped 
    
    C:\Documents and Settings\john\My Documents\ww2rescue.exe Inno: infected - 3 skipped 
    Any idea what these are? If not, delete em.
    Code:
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped 
    No threat unless you use sys restore, even then, only keys.
    Code:
    C:\WINDOWS\system32\drivers\etc\hosts.20070828-214029.backup Infected: Trojan.Win32.Qhost.mg skipped 
    
    C:\WINDOWS\system32\drivers\etc\hosts.20070828-214030.backup Infected: Trojan.Win32.Qhost.mg skipped 
    These are just back ups in hosts file, also no threat, you can delete 'em if you have others.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.