In dire need of help with the evil Qhosts trojan horse...

K

Ky

Please help me! I am having an serious ongoing problem
with the Qhosts trojan horse. The "proper name" McAfee
gives the trojan is "Qhosts.apd". I contracted it a few
days ago and have not been able to get rid of it.. at
least not completely.

At first, I contracted the Sasser worm. I had to use my
brother's computer since I was not able to get to McAfee's
website (later I founds out the it was the Qhosts that
barred me). I downloaded new defintions (I have McAfee)
and I also ran their removal tool, Stinger. Well, Stinger
found and removed the Qhosts trojan along with Sasser and
I ran antivirus on the computer to ensure I was clean.
When i shut off the computer that night, I was virus free.

The next day i ran the Stinger tool again to make sure
Sasser was gone and I had the Qhosts trojan again.
*Everytime* I start my computer I have this trojan. I
have downloaded every available critical update and
service pack (including Q828750 for IE). I made sure that
there was no bad entries in my
C:/windows/system32/drivers/etc HOSTS file, and checked
C:/windows/help for the duplicate the trojan makes. The
HOSTS file is clean and the duplicate is not there. I
even disabled and then re-enabled System Restore when my
system was clean. Yet, every time I start up my computer,
the trojan is there. I have even run a VirusScan before I
restart my computer. It comes up clean. However, even if
I just re-start it, the trojan is in my system and the
VirusScan "cleans" the HOSTS file.

I use MSN dial-up so when my computer starts I am not even
online to contract the virus!!

I disabled all ActiveX commands and scripts, and changed
my security settings to Medium-High. I installed the
windows XP-included Firewall as well. And tell me if this
makes any sense - after I start my computer and get
online, I am actually completely able to view and navigate
an anit-virus website (symantec.com, nai.com, etc) that
the trojan is supposed to block! I can also use search
engines like google and yahoo.

What is wrong with my computer and what can I do?? Please
help!! i am about to throw my computer out the window.....
 
G

Guest

This file can get droped by trojans or worms like : W32/Polybot.gen!irc or W32/Gaobot.worm
There have been an increase in the detection of this file reported to AVERT recently. This is caused by new variants of W32/Gaobot.worms that exploit a MS04-011 vulnerability (LSASS vulnerability CAN-2003-0533). This file is dropped upon execution of the worm. Most of these worms are stealthy and are not visible from the service and process list.

First
Disabling the System Restore Utility (Windows XP Users

1. Right click the My Computer icon on the Desktop and click on Properties
2. Click on the System Restore tab
3. Put a check mark next to 'Turn off System Restore on All Drives'
4. Click the 'OK' button
5. You will be prompted to restart the computer. Click Yes
6. http://www.networkassociates.com/us/downloads

And clean... or online clean (Trend, panada..
 
K

Ky

I just wanted to let you know that I did what you advised
me to do and Panda's Virus Scan online found and removed
W32.gaobot.gen.worm! I'm now virus-free!! Thank you sooo
much!! ..I was almost at the point of re-formatting my
hard drive... :)

Thank you once again!!

Ky
-----Original Message-----
This file can get droped by trojans or worms like :
W32/Polybot.gen!irc or W32/Gaobot.worm .
There have been an increase in the detection of this file
reported to AVERT recently. This is caused by new variants
of W32/Gaobot.worms that exploit a MS04-011 vulnerability
(LSASS vulnerability CAN-2003-0533). This file is dropped
upon execution of the worm. Most of these worms are
stealthy and are not visible from the service and process
list.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

TROJAN HORSE 7
Is This a trojan horse? 7
TROJAN HORSE help 1
Trojan Horse or spyware? 1
Trojan Horse 3
trojan horse 2
Trojan Horse 2
Trojan Horse Virus 1

Top