locked
Changing Live oncare settings RRS feed

  • Question

  • i have both my computers set to scan at 11:00pm every night i just checked the support log and it only doing a custom scan and its only scanning a hand full of files and i want it to do a complete scan.
    where can i change this setting?
    Thanks
    Chris

    heres some of the log

    11/26/2007 11:04 PM
    Virus and spyware scan was completed
    Scanned Items: -
    Scan Type: Custom Scan
    Scan StartTime: 11/26/2007 11:00 PM
    Scan EndTime: 11/26/2007 11:04 PM
    Total Number of Files Scanned: 9304
    Total Number of Files Not Scanned: 2
    Total Number of Threats Found: 0
    Total Number of Threats Cleaned: 0
    Total Number of Threats Removed: 0
    Total Number of Threats Quarantined: 0
    Total Number of Threats Still Present But Suspended: 0
    11/26/2007 12:45 PM
    Virus and spyware scan was completed
    Scanned Items: C:\Documents and Settings\Chris\Desktop\Eastern.Promises.R5.LiNE.XviD-COCAIN
    Scan Type: Custom Scan
    Scan StartTime: 11/26/2007 12:45 PM
    Scan EndTime: 11/26/2007 12:45 PM
    Total Number of Files Scanned: 5
    Total Number of Files Not Scanned: 0
    Total Number of Threats Found: 0
    Total Number of Threats Cleaned: 0
    Total Number of Threats Removed: 0
    Total Number of Threats Quarantined: 0
    Total Number of Threats Still Present But Suspended: 0
    11/26/2007 12:27 PM
    Virus and spyware scan was completed
    Scanned Items: C:\
    E:\
    Scan Type: Custom Scan
    Scan StartTime: 11/26/2007 11:15 AM
    Scan EndTime: 11/26/2007 12:27 PM
    Total Number of Files Scanned: 534113
    Total Number of Files Not Scanned: 1754
    Total Number of Threats Found: 1
    Total Number of Threats Cleaned: 0
    Total Number of Threats Removed: 1
    Total Number of Threats Quarantined: 0
    Total Number of Threats Still Present But Suspended:

    Tuesday, November 27, 2007 10:48 AM

Answers

  • If you wish to do a complete virus and spyware scan nightly, you would need to perform a full tune-up nightly. The scan that happens daily by default, is a light scan that checks the most common locations for infections. A deep scan only happens on demand or scheduled during a tune-up.

    -steve

     

    Tuesday, November 27, 2007 6:21 PM
    Moderator

All replies

  • If you wish to do a complete virus and spyware scan nightly, you would need to perform a full tune-up nightly. The scan that happens daily by default, is a light scan that checks the most common locations for infections. A deep scan only happens on demand or scheduled during a tune-up.

    -steve

     

    Tuesday, November 27, 2007 6:21 PM
    Moderator
  • there is no selection to do a tuneup on a daily basis only weekly?


    Tuesday, November 27, 2007 11:12 PM
  •  

    Yes, sorry - I changed my post from "schedule" to "perform" a scan. You can't schedule it for more often than weekly or it will be detrimental to your PC. The on access protection is always on, so running a full deep scan is overkill. If you absolutely want to run a full scan daily, you will need to initiate it manually.

    -steve

    Wednesday, November 28, 2007 8:08 PM
    Moderator
  • I got another Question for ya Steve
    i have some files Quarantined. I tried to go to the folder (C:\Program Files\Microsoft Windows OneCare Live\N)
    but there is no folder "N" in there, so i did a search from the command prompt and nothing there either??
    So what gives?
    Where are these files stored at?

    These are the file names
    Backdoor:Win32/Rbot.gen!A
    Backdoor:Win32/Rbot.gen!A
    Backdoor:Win32/Rbot.gen!A

    i tried to delete them but they keep coming back so i figure that there not being deleted and thats why i'm looking for that folder.

    The Next step i took was to run the safemode av scanner in safemode with command prompt and it didn't find anything but the are still picked up with OneCare Live

    I need to get rid of them!!

    I can't use my Task Manager,Command Prompt or my regedit all they do is flash on the screen

    I have been a frim believer in OneCare Live since it came out was a beta tester and all that but i'm starting to have my some second thoughts??

    Chris

    Heres what onecare live DIDN'T find and XoftSpySE DID
    The log file from the XoftSpySE Scan
    Looks like you guy got some work to do

    <XoftSpy>
    <Meta info="XoftSpySE-SP1 Tech-Support Log" time="28-11-2007-18-46-59"/>
    <ScanSettings scanActive="true" scanRegistry="true" scanSysFolders="true" scanDrives="true" scanHosts="true" scanAdvScan="true"/>
    <Debug>
    <DebugMsg event="PROCESS_FOUND" data="C:\WINDOWS\system32\cmd.exe" system-message="The operation completed successfully."  malwareName="Agent QJ Trojan"/>
    <DebugMsg event="REGKEY_FOUND" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGKEY_FOUND" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\componentid" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\locale" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\version" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\isinstalled" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\componentid" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\locale" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\version" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\isinstalled" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\windows\currentversion\uninstall\viewpointmediaplayer\displayname" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_FOUND" data="software\microsoft\windows\currentversion\uninstall\viewpointmediaplayer\uninstallstring" system-message="Only part of a ReadProcessMemory or WriteProcessMemory request was completed."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\AxMetaStream.dll" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\ClassIDs.ini" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\Components" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\DownloadedComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\MetaStreamID.ini" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\MtsAxInstaller.exe" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\NewComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\Components" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\DownloadedComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player\NewComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\Viewpoint Media Player" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\viewpoint media player\Components" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\viewpoint media player\DownloadedComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\viewpoint media player\NewComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\program files\viewpoint\viewpoint media player" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@2o7[1].txt" system-message="There are no more files."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@adrevolver[2].txt" system-message="There are no more files."  malwareName="adrevolver cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@ads.pointroll[1].txt" system-message="There are no more files."  malwareName="pointroll cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@advertising[2].txt" system-message="There are no more files."  malwareName="advertising cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@atdmt[2].txt" system-message="There are no more files."  malwareName="atdmt cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@doubleclick[1].txt" system-message="There are no more files."  malwareName="doubleclick cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@ehg-foxsports.hitbox[2].txt" system-message="There are no more files."  malwareName="hitbox cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@fastclick[1].txt" system-message="There are no more files."  malwareName="fastclick cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@highbeam.122.2o7[1].txt" system-message="There are no more files."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@hitbox[1].txt" system-message="There are no more files."  malwareName="hitbox cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@live365[1].txt" system-message="There are no more files."  malwareName="live365 cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@media.adrevolver[2].txt" system-message="There are no more files."  malwareName="adrevolver cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@media.adrevolver[3].txt" system-message="There are no more files."  malwareName="adrevolver cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@msnlivefavorites.112.2o7[1].txt" system-message="There are no more files."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@msnportal.112.2o7[1].txt" system-message="There are no more files."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@questionmarket[2].txt" system-message="There are no more files."  malwareName="questionmarket cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@scot.valueclick[2].txt" system-message="There are no more files."  malwareName="valueclick cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@tribalfusion[1].txt" system-message="There are no more files."  malwareName="tribalfusion cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@valueclick[1].txt" system-message="There are no more files."  malwareName="valueclick cookie"/>
    <DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\Chris\Cookies\chris@zedo[1].txt" system-message="There are no more files."  malwareName="zedo cookie"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player\Components" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player\Components" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_FOUND" data="c:\Program Files\Viewpoint\Viewpoint Media Player" system-message="There are no more files."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="Agent QJ Trojan" system-message="The operation completed successfully."  malwareName="Agent QJ Trojan"/>
    <DebugMsg event="REGKEY_QUARANTINE_SUCCESS" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_QUARANTINE_SUCCESS" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\windows\currentversion\uninstall\viewpointmediaplayer" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="REGVALUE_QUARANTINE_SUCCESS" data="HKEY_USERS\software\microsoft\windows\currentversion\uninstall\viewpointmediaplayer" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_QUARANTINE_SUCCESS" data="Viewpoint" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_QUARANTINE_SUCCESS" data="Viewpoint" system-message="The operation completed successfully."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_FAIL" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_FAIL" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_QUARANTINE_SUCCESS" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_QUARANTINE_SUCCESS" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_FAIL" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_FAIL" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FOLDER_QUARANTINE_SUCCESS" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_FAIL" data="Viewpoint" system-message="The system cannot find the path specified."  malwareName="Viewpoint"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="2o7.net Cookie" system-message="The operation completed successfully."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="adrevolver cookie" system-message="The operation completed successfully."  malwareName="adrevolver cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="pointroll cookie" system-message="The operation completed successfully."  malwareName="pointroll cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="advertising cookie" system-message="The operation completed successfully."  malwareName="advertising cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="atdmt cookie" system-message="The operation completed successfully."  malwareName="atdmt cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="doubleclick cookie" system-message="The operation completed successfully."  malwareName="doubleclick cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="hitbox cookie" system-message="The operation completed successfully."  malwareName="hitbox cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="fastclick cookie" system-message="The operation completed successfully."  malwareName="fastclick cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="2o7.net Cookie" system-message="The operation completed successfully."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="hitbox cookie" system-message="The operation completed successfully."  malwareName="hitbox cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="live365 cookie" system-message="The operation completed successfully."  malwareName="live365 cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="adrevolver cookie" system-message="The operation completed successfully."  malwareName="adrevolver cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="adrevolver cookie" system-message="The operation completed successfully."  malwareName="adrevolver cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="2o7.net Cookie" system-message="The operation completed successfully."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="2o7.net Cookie" system-message="The operation completed successfully."  malwareName="2o7.net Cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="questionmarket cookie" system-message="The operation completed successfully."  malwareName="questionmarket cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="valueclick cookie" system-message="The operation completed successfully."  malwareName="valueclick cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="tribalfusion cookie" system-message="The operation completed successfully."  malwareName="tribalfusion cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="valueclick cookie" system-message="The operation completed successfully."  malwareName="valueclick cookie"/>
    <DebugMsg event="FILE_QUARANTINE_SUCCESS" data="zedo cookie" system-message="The operation completed successfully."  malwareName="zedo cookie"/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@zedo[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@valueclick[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@tribalfusion[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@scot.valueclick[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@questionmarket[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@msnportal.112.2o7[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@msnlivefavorites.112.2o7[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@media.adrevolver[3].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@media.adrevolver[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@live365[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@hitbox[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@highbeam.122.2o7[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@fastclick[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@ehg-foxsports.hitbox[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@doubleclick[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@atdmt[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@advertising[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@ads.pointroll[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@adrevolver[2].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\Chris\Cookies\chris@2o7[1].txt" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_FAIL" data="c:\program files\viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FOLDER_DELETE_SUCESS" data="c:\program files\viewpoint\Viewpoint Media Player\NewComponents" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_FAIL" data="c:\program files\viewpoint\Viewpoint Media Player\MtsAxInstaller.exe" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_FAIL" data="c:\program files\viewpoint\Viewpoint Media Player\MetaStreamID.ini" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FOLDER_DELETE_SUCESS" data="c:\program files\viewpoint\Viewpoint Media Player\DownloadedComponents" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FOLDER_DELETE_SUCESS" data="c:\program files\viewpoint\Viewpoint Media Player\Components" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_FAIL" data="c:\program files\viewpoint\Viewpoint Media Player\ClassIDs.ini" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_FAIL" data="c:\program files\viewpoint\Viewpoint Media Player\AxMetaStream.dll" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FOLDER_DELETE_SUCESS" data="c:\program files\viewpoint\Viewpoint Media Player" system-message="The system cannot find the path specified."  malwareName=""/>
    <DebugMsg event="FOLDER_DELETE_SUCESS" data="c:\program files\viewpoint" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\windows\currentversion\uninstall\viewpointmediaplayer\uninstallstring" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\windows\currentversion\uninstall\viewpointmediaplayer\displayname" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\isinstalled" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\version" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\locale" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}\componentid" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\isinstalled" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\version" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\locale" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGVLAUE_DELETE_FAIL" data="software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}\componentid" system-message="The system cannot find the file specified."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_CLASSES_ROOT\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{1b00725b-c455-4de6-bfb6-ad540ad427cd}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_CLASSES_ROOT\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="REGKEY_DELETE_SUCCESS" data="HKEY_USERS\software\microsoft\active setup\installed components\{03f998b2-0e00-11d3-a498-00104b6eb52e}" system-message="The operation completed successfully."  malwareName=""/>
    <DebugMsg event="FILE_DELETE_FAIL" data="C:\WINDOWS\system32\cmd.exe" system-message="Access is denied."  malwareName=""/>
    </Debug>
    </XoftSpy>

    Wednesday, November 28, 2007 11:15 PM
  • To remove files from quarantine, open OneCare, click on Change Settings, go to the antivirus tab and click on the Quarantine button.

    They are hidden from the OS - quarantined.

    Without reading through your log file, if you have infections not detected by OneCare, see here:

    http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=662566&SiteID=2

    However, a quick scan shows a load of tracking cookies and orphan registry entries as "malware." That's not true, although it does make the other products look impressive. OneCare does not prevent or manage cookies. You can do that in the browser settings.

    -steve

     

    Thursday, November 29, 2007 3:01 AM
    Moderator
  • I cannot remove files from quarantine.

    I open OneCare, click on Change Settings, go to the Virus and spyware tab and click on the Quarantine button.

    The Manage files in quarantine window comes up, followed immediately by and error message telling me that "The virus and spyware protection serice has encountered an unknown problem. Please try again later. if the problem persists, contact support".

    I've tried many times. It persists.

    I haven't heard back from support yet.

    John

    Friday, October 3, 2008 7:24 AM
  • There is a corrupt entry in your Quarantine folder.

     

    Have a look here: 

    http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=2811486&SiteID=2

     

    -steve

    Monday, October 6, 2008 5:22 PM
    Moderator
  • I guess this problem is still around because I failed to file an official bug report, and I’m still not sure how to do that. The “solution” that I presented is only a workaround for what I am almost certain can be fixed by modifying the error-handling code. If the indexing engine is not being halted, as I believe is the case, then the error-handling routine needs to either ignore this read error, or to delete the unreadable entry, rather than throw up a modal error message.

    The latest “updated version” of the fix is presented in this thread: http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=3576257&SiteID=2

    GreginMich

     

    Monday, October 6, 2008 6:14 PM
  • Thanks, GreginMich.

    The OneCare team is aware of the bug and I would expect that it is on the list for fixing, but the question would be how deep into the code do they have to go. Hopefully it will be fixed in 3.0 or sooner.

    By the way, could you drop me an email at sboots@mvps.org with OneCare Forum in the subject and make sure your nickname is in the message body? Thanks.

    -steve

     

    Tuesday, October 7, 2008 2:05 PM
    Moderator