cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Level 13
Report Inappropriate Content
Message 11 of 19

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

I have also opened a service request, They hadn't heard of an issue at that poiint.

Highlighted
Level 13
Report Inappropriate Content
Message 12 of 19

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

Support confirm false positive:

"If the customer was using or has used Spybot searchand destroy or other anti-malware tools that added entries within the hostsfile it was detected incorrectly with the 6874 dat. This has already been fixedand should not occur in the next dat onwards."

Apologies for any inconvenience caused by this detectionin the 6874 DAT release.

View solution in original post

Highlighted

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

Same issue here with ver 8.7  upgrading to ver 8.8  I will post my results. 

Highlighted
Level 7
Report Inappropriate Content
Message 14 of 19

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

Just to note that I saw the issue on a number of 8.8 installs, so I think the version really has little to do with it, and that it's the FP in the DAT combined with other factors.

Highlighted

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

I can confirm this occurring on 8.8 P2 installations where Spybot S&D is also installed.

It does seem to be only installation with the 6874DAT installed other machines with 6873 and under do not seem to be affected.

Highlighted
Level 7
Report Inappropriate Content
Message 16 of 19

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

Hi,

Same problem for us on few computers running Version 8.5 or 8.7i of viruscan enterprise runing the 6874DAT file.

The file is detected in C:\windows\system32\drivers\etc\hosts.

For one pc, the file UNS.exe from Intel Management engine was detected as Generic QHosts.c.

Installing the Viruscan enterprise 8.8 as corrected this problem on all PC.

I follow this post to see what the outcome is.

Highlighted

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

I see this since today on a couple of machines with VSE 8.7 P5. In our case it seems to be related to spybot's modified hosts file also.

Maybe this is a false positive due to this signature change: http://www.mcafee.com/threat-intelligence/malware/default.aspx?id=1553211

Message was edited by: nbaumann on 10/24/12 11:10:31 AM CEST
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 18 of 19

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

The DAT 6875 just got released before lunch CDT. Have forced our ePO server to install and deploy to all our managed systems. since deploying the DAT, I have not seen anymore of the Qhosts alerts.

Re: VSE 8.8 Generic QHosts.c detections

Jump to solution

I have been pushing out the newest DAT and have not had any new detection since then.

Thank you to everyone for your feedback.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community