The Proof behind just how worthless Windows One care really is.


Recommended Posts

Log file post from SuperAntispyware at the bottom of this post

I was working on a Vista laptop for a customer. All appeared well. No virus or spyware / malware or Trojan warnings. The customer was running windows one care. he didn't have service pack 1 so I installed it. Along will all the latest updates. But I noticed his task manager was disabled. To me that spells "your infected with something".

So I downloaded a copy of SuperAntispyware and did a full system scan. Keep in mind that according to one cares information, it was recently updated and recently did a full system scan with no problems detected.

I think the screenshots speak for themselves.

SuperAntispyware

capturekt2.jpg

Windows One Care

capture1ug6.jpg

Now I do realize other antiviruses could have failed just as miserably. But one care was the one on the system and at lease now we know at lease one worthless AV on the market.

Once that got done I opened defender which said it had not done a scan in 65 days. So I do a scan. It finds nothing.

Next I do a scan with Spybot Search and destroy.

Once again the screenshots speak for themselves.

Windows Defender

defednerhs0.jpg

Spybot Search and Destroy.

spybotuz4.jpg

List of files found in the Superantispyare Log file

C:\PROGRAM FILES\SEARCH SETTINGS\KB125\SEARCHSETTINGS.DLL

Rogue.AntiSpyStorm

C:\Program Files\AntispyStorm\AntispyStorm.exe.MANIFEST

C:\Program Files\AntispyStorm\config.dat

C:\Program Files\AntispyStorm\filesbase.bin

C:\Program Files\AntispyStorm\global_virus_table.bin

C:\Program Files\AntispyStorm\ignoredomainsbase.bin

C:\Program Files\AntispyStorm\ignorefilesbase.bin

C:\Program Files\AntispyStorm\ignoreregsbase.bin

C:\Program Files\AntispyStorm\mdReg.dll

C:\Program Files\AntispyStorm\parser.exe

C:\Program Files\AntispyStorm\regbase.bin

C:\Program Files\AntispyStorm\stat.bin

C:\Program Files\AntispyStorm\uninstall.exe

C:\Program Files\AntispyStorm\uninstall.log

C:\Program Files\AntispyStorm\urlbase.bin

C:\Program Files\AntispyStorm

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntispyStorm\Uninstall AntispyStorm.lnk

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntispyStorm

Trojan.Unclassified/NVCOI

C:\Program Files\Temporary

Adware.AdSponsor/ISM

C:\Program Files\Spcron

Trojan.Fake-Drop/Gen

C:\WINDOWS\CTFMON32.EXE

C:\WINDOWS\ACCESSS.EXE

C:\WINDOWS\AVPCC.DLL

C:\WINDOWS\CLRSSN.EXE

C:\WINDOWS\CPAN.DLL

C:\WINDOWS\CTRLPAN.DLL

C:\WINDOWS\DIRECTX32.EXE

C:\WINDOWS\DNSRELAY.DLL

C:\WINDOWS\EDITPAD.EXE

C:\WINDOWS\EXPLORE.EXE

C:\WINDOWS\EXPLORER32.EXE

C:\WINDOWS\FUNNIEST.EXE

C:\WINDOWS\FUNNY.EXE

C:\WINDOWS\GFMNAAA.DLL

C:\WINDOWS\HELPCVS.EXE

C:\WINDOWS\INETINF.EXE

C:\WINDOWS\INTERNET.EXE

C:\WINDOWS\MSCONFD.DLL

C:\WINDOWS\MSSPI.DLL

C:\WINDOWS\MSSYS.EXE

C:\WINDOWS\MSUPDATE.EXE

C:\WINDOWS\MSWSC10.DLL

C:\WINDOWS\MSWSC20.DLL

C:\WINDOWS\MTWIRL32.DLL

C:\WINDOWS\QUICKEN.EXE

C:\WINDOWS\NOTEPAD32.EXE

C:\WINDOWS\QTTASKS.EXE

C:\WINDOWS\RUNDLL16.EXE

C:\WINDOWS\SEARCHWORD.DLL

C:\WINDOWS\SISTEM.EXE

C:\WINDOWS\SVCHOST32.EXE

C:\WINDOWS\SVCINIT.EXE

C:\WINDOWS\WINDOW.EXE

C:\WINDOWS\TIME.EXE

C:\WINDOWS\USERS32.EXE

C:\WINDOWS\WAOL.EXE

C:\WINDOWS\WIN64.EXE

C:\WINDOWS\WINAJBM.DLL

C:\WINDOWS\WINMGNT.EXE

C:\WINDOWS\X.EXE

C:\WINDOWS\XPLUGIN.DLL

C:\WINDOWS\Y.EXE

Trojan.Dropper/ASTCTL32

C:\WINDOWS\ASTCTL32.OCX

Rogue.LiveSecurityCenter-Trace

C:\WINDOWS\DEFAULT.HTM

Trojan.Downloader-Gen/Win

C:\WINDOWS\IEDLL.EXE

C:\WINDOWS\WIN32E.EXE

Trojan.Unclassified/IExplorer-Fake

C:\WINDOWS\IEXPLORER.EXE

Trojan.Unclassified/Loader-Suspicious

C:\WINDOWS\LOADER.EXE

Trojan.CWS/VBE

C:\WINDOWS\RUNDLL32.VBE

Trojan.Downloader-Systeem

C:\WINDOWS\SYSTEEM.EXE

Trojan.Downloader-SystemCritcial/Fake Alert

C:\WINDOWS\SYSTEMCRITICAL.EXE

Trojan.Unclassified/XXXVid

C:\WINDOWS\XXXVIDEO.HTA

Adware.MyWebSearch

C:\WINDOWS.OLD\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE

Edited by warwagon

wow that is a massive fail on onecares part

the only thing that I could even think to ask was onecare installed before there was a problem or as an attempt to fix one that was there?

wow that is a massive fail on onecares part

the only thing that I could even think to ask was onecare installed before there was a problem or as an attempt to fix one that was there?

Well the fact it is on there at all with that many infections living right next to it, is just sad.

I'm not sure if onecare cleans out trackign cookies, wich is what all those file items are. and it's a fairly useless thign to do anyway.

I'm also fairly sure that it doesn't mess aroudn to much in the registry other than to remove stuff that actually comes with spyware, while that other apps seems to have decided to act as a registry cleaner, wichis not a good thing.

During the deletion process with superantispyware I saw a bunch of random Exe files getting deleted from the windows directoy. one of which was Y.exe

in that case it's strange, it hsould have detected any spyware executables as log as it's properly updated, wich it appears to be.

just think what NOD32 or Kaspersky would have clean'd out

Yes, because kaspersky or nod32 did better than Antivir which is also happens to be free :rolleyes:

One Care, here, just works fine...no virus and no spyware.

Haha? :blink:

I think it's generally considered good practice to have more than one defence these days...

Personally I use Superantispyware, AVG free, CCleaner and Lavasoft Adaware and have never had a problem...

No single program is 100% perfect but they'll catch pretty much everything between them :)

One thing for sure though - I'd NEVER pay for any antivirus/antispyware program - The free ones ARE good enough

(Well, they are in my own personal experience anyway)

I think it's generally considered good practice to have more than one defence these days...

Personally I use Superantispyware, AVG free, CCleaner and Lavasoft Adaware and have never had a problem...

No single program is 100% perfect but they'll catch pretty much everything between them :)

One thing for sure though - I'd NEVER pay for any antivirus/antispyware program - The free ones ARE good enough

(Well, they are in my own personal experience anyway)

I agree, but it also depends on the user. I mean some people just install and "ok-button-bash" anything :)

Been using Vista for more than a year now, after a year I did a spyware / malware check with several programs and all it found were some cookies.

/on-topic: Kinda disappointing from one-care, not that I use it, but it should have detected at least something I'd say.

All the Anti programs have their problems. It makes me laugh when you get a person saying "Program X is the best because I have no spyware/viruses on my PC" How do they know. This thread just goes to show that is not the case.

I run Kaspersky, but I would not say to anyone it's the best, because I don't know if it's got it all. I remember years ago someone telling me AVG was the daddy and I ran it for about a year. The day I swapped, Nod32 picked up a lot of crap. The day I swapped to Kaspersky, that picked up a bit of crap as well. If I swapped again when my sub runs out, whatever I choose to use will no doubt pick up some other crap.

[teach to suck eggs]

The best defence is not to download stuff you know 'may' contain trojans. Avoid dodgy sites (I know some legitimate sites that have dropped a nasty payload, so nothing is 100% safe) and browse with extensions like NoScipt and Adblock active. The only 100% safe way is not go on the interwebitubes (like that'll happen!)

[/teach to suck eggs]

i got avast home edition.. I Trust it to be the best (for me)

It already proved it was better then Novell (used @ school) that proved much for me XD

One Care, here, just works fine...no virus and no spyware.

That's the point of this thread.

I would suggest you take a few minutes to download and install another one, such as SuperAntiSpyware or Spybot, and just scan with those to make sure. Not every program is going to detect everything, and it's much better to have two or even three to make sure you're completely safe.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I'm not sure about that, but it at least "does" a version of 7.1 that this brand new card doesn't....
    • Floorp 12.15.2 by Razvan Serea Floorp is a cutting-edge web browser that combines the trusted foundation of Mozilla's Firefox with a unique Japanese perspective, offering users an exceptional online experience. This open-source browser prioritizes privacy, customization, and security. Floorp is transparent, with no user tracking or data sharing, and it's completely open source. With a strict no-tracking policy and full transparency, your personal information remains private. As an open-source project, Floorp not only shares its source code but also its build environment, inviting users to contribute and build their unique versions. The regular updates, based on Firefox ESR, ensure that you always have the latest features and security enhancements. Floorp key features: Strong Tracking Protection: Floorp offers robust tracking protection, safeguarding users from malicious tracking and fingerprinting on the web. Flexible Layout: Customize Floorp's layout to your heart's content, including moving the tab bar, hiding the title bar, and more for a personalized browsing experience. Switchable Design: Choose from five distinct designs for the Floorp interface, and even switch between OS-specific designs for a unique look Regular Updates: Based on Firefox ESR, Floorp receives updates every four weeks, ensuring up-to-date security even before Firefox's releases. No User Tracking: Floorp prioritizes user privacy by abstaining from collecting personal information, tracking users, or selling user data, with no affiliations with advertising companies. Completely Open Source: The full source code for Floorp is open to the public, allowing transparency and enabling anyone to explore and build their own version. Dual Sidebar: Floorp features a versatile built-in sidebar for webpanels and browsing tools, making it perfect for multitasking and quick access to bookmarks, history, and websites. Flexible Toolbar & Tab Bar: Customize your browser with Tree Style Tabs, vertical tabs, and bookmark bar modifications, catering to both beginners and experts in customization. User-Centric Web Experience: Floorp prioritizes user privacy and collaboratively blocks harmful trackers. Floorp 12.15.2 changelog: fix: reset tab drag state on dragend to prevent position offset (#2488) by @Ryosuke-Asano in #2497 fix(workspaces): hide split view wrapper when all tabs are hidden by @Ryosuke-Asano in #2495 fix(split-view): prevent stuck pointer-events:none after drag on web content by @Ryosuke-Asano in #2492 feat(design): add Gecko 152 CSS variable aliases and Lepton compatibility layer by @Ryosuke-Asano in #2494 fix(workspaces): exitOnLastTabClose no longer quits Floorp when closing the last tab by @Ryosuke-Asano in #2498 Download: Floorp 64-bit | 95.0 MB (Open Source) Links: Floorp Website | Github Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I can barely recall getting web results from a file search... I must've turned it off long ago. 26H2 is Insider's Preview build 26300.8697, which I am running, atm. It is not available for people running the standard commercial builds of Windows--only for the beta test Insider's group. But anyway, as mentioned in the thread, this feature has been around for a long time...
    • Speak for yourself. I saw it on Feedly, came here to read it, and did read it until the steps to activate. I skipped them to read the last paragraph. I knew it was probably not "the most requested feature", but knowing Neowin, I knew the article was going to talk about a feature nonetheless. I've seen Neowin in its best and worst.
    • See if this article I wrote the other day works for you.
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!