The Proof behind just how worthless Windows One care really is.


Recommended Posts

Log file post from SuperAntispyware at the bottom of this post

I was working on a Vista laptop for a customer. All appeared well. No virus or spyware / malware or Trojan warnings. The customer was running windows one care. he didn't have service pack 1 so I installed it. Along will all the latest updates. But I noticed his task manager was disabled. To me that spells "your infected with something".

So I downloaded a copy of SuperAntispyware and did a full system scan. Keep in mind that according to one cares information, it was recently updated and recently did a full system scan with no problems detected.

I think the screenshots speak for themselves.

SuperAntispyware

capturekt2.jpg

Windows One Care

capture1ug6.jpg

Now I do realize other antiviruses could have failed just as miserably. But one care was the one on the system and at lease now we know at lease one worthless AV on the market.

Once that got done I opened defender which said it had not done a scan in 65 days. So I do a scan. It finds nothing.

Next I do a scan with Spybot Search and destroy.

Once again the screenshots speak for themselves.

Windows Defender

defednerhs0.jpg

Spybot Search and Destroy.

spybotuz4.jpg

List of files found in the Superantispyare Log file

C:\PROGRAM FILES\SEARCH SETTINGS\KB125\SEARCHSETTINGS.DLL

Rogue.AntiSpyStorm

C:\Program Files\AntispyStorm\AntispyStorm.exe.MANIFEST

C:\Program Files\AntispyStorm\config.dat

C:\Program Files\AntispyStorm\filesbase.bin

C:\Program Files\AntispyStorm\global_virus_table.bin

C:\Program Files\AntispyStorm\ignoredomainsbase.bin

C:\Program Files\AntispyStorm\ignorefilesbase.bin

C:\Program Files\AntispyStorm\ignoreregsbase.bin

C:\Program Files\AntispyStorm\mdReg.dll

C:\Program Files\AntispyStorm\parser.exe

C:\Program Files\AntispyStorm\regbase.bin

C:\Program Files\AntispyStorm\stat.bin

C:\Program Files\AntispyStorm\uninstall.exe

C:\Program Files\AntispyStorm\uninstall.log

C:\Program Files\AntispyStorm\urlbase.bin

C:\Program Files\AntispyStorm

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntispyStorm\Uninstall AntispyStorm.lnk

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntispyStorm

Trojan.Unclassified/NVCOI

C:\Program Files\Temporary

Adware.AdSponsor/ISM

C:\Program Files\Spcron

Trojan.Fake-Drop/Gen

C:\WINDOWS\CTFMON32.EXE

C:\WINDOWS\ACCESSS.EXE

C:\WINDOWS\AVPCC.DLL

C:\WINDOWS\CLRSSN.EXE

C:\WINDOWS\CPAN.DLL

C:\WINDOWS\CTRLPAN.DLL

C:\WINDOWS\DIRECTX32.EXE

C:\WINDOWS\DNSRELAY.DLL

C:\WINDOWS\EDITPAD.EXE

C:\WINDOWS\EXPLORE.EXE

C:\WINDOWS\EXPLORER32.EXE

C:\WINDOWS\FUNNIEST.EXE

C:\WINDOWS\FUNNY.EXE

C:\WINDOWS\GFMNAAA.DLL

C:\WINDOWS\HELPCVS.EXE

C:\WINDOWS\INETINF.EXE

C:\WINDOWS\INTERNET.EXE

C:\WINDOWS\MSCONFD.DLL

C:\WINDOWS\MSSPI.DLL

C:\WINDOWS\MSSYS.EXE

C:\WINDOWS\MSUPDATE.EXE

C:\WINDOWS\MSWSC10.DLL

C:\WINDOWS\MSWSC20.DLL

C:\WINDOWS\MTWIRL32.DLL

C:\WINDOWS\QUICKEN.EXE

C:\WINDOWS\NOTEPAD32.EXE

C:\WINDOWS\QTTASKS.EXE

C:\WINDOWS\RUNDLL16.EXE

C:\WINDOWS\SEARCHWORD.DLL

C:\WINDOWS\SISTEM.EXE

C:\WINDOWS\SVCHOST32.EXE

C:\WINDOWS\SVCINIT.EXE

C:\WINDOWS\WINDOW.EXE

C:\WINDOWS\TIME.EXE

C:\WINDOWS\USERS32.EXE

C:\WINDOWS\WAOL.EXE

C:\WINDOWS\WIN64.EXE

C:\WINDOWS\WINAJBM.DLL

C:\WINDOWS\WINMGNT.EXE

C:\WINDOWS\X.EXE

C:\WINDOWS\XPLUGIN.DLL

C:\WINDOWS\Y.EXE

Trojan.Dropper/ASTCTL32

C:\WINDOWS\ASTCTL32.OCX

Rogue.LiveSecurityCenter-Trace

C:\WINDOWS\DEFAULT.HTM

Trojan.Downloader-Gen/Win

C:\WINDOWS\IEDLL.EXE

C:\WINDOWS\WIN32E.EXE

Trojan.Unclassified/IExplorer-Fake

C:\WINDOWS\IEXPLORER.EXE

Trojan.Unclassified/Loader-Suspicious

C:\WINDOWS\LOADER.EXE

Trojan.CWS/VBE

C:\WINDOWS\RUNDLL32.VBE

Trojan.Downloader-Systeem

C:\WINDOWS\SYSTEEM.EXE

Trojan.Downloader-SystemCritcial/Fake Alert

C:\WINDOWS\SYSTEMCRITICAL.EXE

Trojan.Unclassified/XXXVid

C:\WINDOWS\XXXVIDEO.HTA

Adware.MyWebSearch

C:\WINDOWS.OLD\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE

Edited by warwagon

wow that is a massive fail on onecares part

the only thing that I could even think to ask was onecare installed before there was a problem or as an attempt to fix one that was there?

wow that is a massive fail on onecares part

the only thing that I could even think to ask was onecare installed before there was a problem or as an attempt to fix one that was there?

Well the fact it is on there at all with that many infections living right next to it, is just sad.

I'm not sure if onecare cleans out trackign cookies, wich is what all those file items are. and it's a fairly useless thign to do anyway.

I'm also fairly sure that it doesn't mess aroudn to much in the registry other than to remove stuff that actually comes with spyware, while that other apps seems to have decided to act as a registry cleaner, wichis not a good thing.

During the deletion process with superantispyware I saw a bunch of random Exe files getting deleted from the windows directoy. one of which was Y.exe

in that case it's strange, it hsould have detected any spyware executables as log as it's properly updated, wich it appears to be.

just think what NOD32 or Kaspersky would have clean'd out

Yes, because kaspersky or nod32 did better than Antivir which is also happens to be free :rolleyes:

One Care, here, just works fine...no virus and no spyware.

Haha? :blink:

I think it's generally considered good practice to have more than one defence these days...

Personally I use Superantispyware, AVG free, CCleaner and Lavasoft Adaware and have never had a problem...

No single program is 100% perfect but they'll catch pretty much everything between them :)

One thing for sure though - I'd NEVER pay for any antivirus/antispyware program - The free ones ARE good enough

(Well, they are in my own personal experience anyway)

I think it's generally considered good practice to have more than one defence these days...

Personally I use Superantispyware, AVG free, CCleaner and Lavasoft Adaware and have never had a problem...

No single program is 100% perfect but they'll catch pretty much everything between them :)

One thing for sure though - I'd NEVER pay for any antivirus/antispyware program - The free ones ARE good enough

(Well, they are in my own personal experience anyway)

I agree, but it also depends on the user. I mean some people just install and "ok-button-bash" anything :)

Been using Vista for more than a year now, after a year I did a spyware / malware check with several programs and all it found were some cookies.

/on-topic: Kinda disappointing from one-care, not that I use it, but it should have detected at least something I'd say.

All the Anti programs have their problems. It makes me laugh when you get a person saying "Program X is the best because I have no spyware/viruses on my PC" How do they know. This thread just goes to show that is not the case.

I run Kaspersky, but I would not say to anyone it's the best, because I don't know if it's got it all. I remember years ago someone telling me AVG was the daddy and I ran it for about a year. The day I swapped, Nod32 picked up a lot of crap. The day I swapped to Kaspersky, that picked up a bit of crap as well. If I swapped again when my sub runs out, whatever I choose to use will no doubt pick up some other crap.

[teach to suck eggs]

The best defence is not to download stuff you know 'may' contain trojans. Avoid dodgy sites (I know some legitimate sites that have dropped a nasty payload, so nothing is 100% safe) and browse with extensions like NoScipt and Adblock active. The only 100% safe way is not go on the interwebitubes (like that'll happen!)

[/teach to suck eggs]

i got avast home edition.. I Trust it to be the best (for me)

It already proved it was better then Novell (used @ school) that proved much for me XD

One Care, here, just works fine...no virus and no spyware.

That's the point of this thread.

I would suggest you take a few minutes to download and install another one, such as SuperAntiSpyware or Spybot, and just scan with those to make sure. Not every program is going to detect everything, and it's much better to have two or even three to make sure you're completely safe.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • It wouldn't be hard for me to turn off my TV, if I had one. For one thing, I never scroll Instagram. The only reason I have an account is because Meta created one when it merged the account systems for its various services.
    • OpenAI's new GPT-5.5-Cyber tops Claude Mythos 5 in vulnerability benchmark by Pradeep Viswanathan OpenAI today announced a major expansion of Daybreak, a cybersecurity initiative designed to help defenders find, validate, and fix software vulnerabilities earlier in the development process. The availability of powerful AI models has definitely changed the cybersecurity landscape by making vulnerability discovery much faster. However, the bigger bottleneck for the industry is now patching those vulnerabilities. Impacted software teams need to validate the discovered issues, understand their impact, develop fixes, test them, and deploy patches. Back in March, OpenAI launched a preview of Codex Security, which uses agentic reasoning with automated validation to discover high-impact issues and actionable fixes specific to the codebase. Since then, it has scanned more than 30 million commits across over 30,000 codebases; more than 70,000 findings were marked as fixed by human reviewers, while over 500,000 findings were automatically determined to be fixed. Now, OpenAI is releasing an updated Codex Security plugin that can run deep scans, review recent code changes, generate security reports, trace attack paths, validate findings, and create codebase-specific patches for human review. It can also triage findings from existing scanners, advisories, bug bounty reports, and ticketing systems. OpenAI says the plugin can export results to vulnerability management systems and integrate with workflows using SARIF files, CodeQL queries, the Codex CLI, and the Codex app. Back in May, OpenAI announced the preview of GPT-5.5-Cyber, a new model built on top of the recently released GPT-5.5, designed for specialized cybersecurity work. Today, OpenAI launched the full version of GPT-5.5-Cyber through a limited release for verified defenders. On CyberGym, GPT-5.5-Cyber scored 85.6%, compared with 81.8% for GPT-5.5 and 83.8% for Claude Mythos 5. It also scored 39.5% on ExploitGym, compared with 25.95% for GPT-5.5, and 69.8% on SEC-bench Pro, compared with 63.1%. OpenAI also announced the new Daybreak Cyber Partner Program, which will allow security vendors and service providers to use GPT-5.5 with Trusted Access for Cyber in their products and services. Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, IBM, Palo Alto Networks, Proofpoint, SentinelOne, Wiz, Zscaler, and others were listed as initial partners for this program. OpenAI is also launching Patch the Planet with Trail of Bits, HackerOne, Calif, researchers, and maintainers. More than 30 open-source projects have committed to participate, including cURL, Go, Python, Sigstore, and pyca/cryptography.
    • AMD confirms 26.6.2 FSR driver breaks on many Windows PCs by Sayan Sen Earlier today AMD released a major graphics driver update as it brings support for FSR 4.1 to Radeon RX 7000 series GPUs. The new update, version 26.6.2, also brings support for Assassin's Creed Black Flag Resynced and more. And while the driver technically supports Windows 10 version 21H2 and newer, the tech giant has confirmed that there is a major issue with the new driver on non-Windows 11 PCs as it fails to launch properly on such systems. The error message says, "The version of AMD Software that you have launched is not compatible with your currently installed AMD graphics driver." Therefore on the surface it looks like a compatibility problem. AMD has also confirmed that the device manager will display the yellow bang or yellow exclamation sign alongside your GPU under the Display adapters dropdown. Here is what the Radeon team's official advisory recommends to affected users: "Users Running Windows 10 and AMD Software: Adrenalin Edition 26.6.2 May Encounter Yellow Bang in Device Manager Affecting AMD Radeon RX Series Graphics ... Our Engineers are currently investigating this issue and will provide a fix once it is available. Affected users may revert to AMD Software: Adrenalin Edition 26.6.1 as a temporary workaround." As such you should revert back to the previous 26.6.1 driver which was released earlier this month. In case you were looking to play Assassin's Creed Black Flag Resynced and DOOM: The Dark Ages | Revelations you will probably have to wait a while if you want the driver to support those games officially. You can find the support article here on Microsoft's website.
    • https://uupdump.net/selectlang...7829-4524-978d-7b5fe79263e3
    • A McDonald's restaurant uses about 1.5 to 2 million gallons of water per year for operations like food preparation, cleaning, and restrooms. That is a lot less than the 2,083 gallons of water per megawatt hour mentioned above.
  • Recent Achievements

    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      208
    3. 3
      PsYcHoKiLLa
      100
    4. 4
      Michael Scrip
      88
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!