473,396 Members | 1,784 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,396 software developers and data experts.

Windows Live OneCare help

I just started using Windows Live OneCare, I had been using Norton, but was
unable to fix the problems I was having. I have yet been unsuccessful with
OneCare as well. I keep getting the same warning from OneCare, one is for
Adware, the other is for a trojan, I clean both, but almost immediatly, I get
the same warning? My Windows Defender is also shut down, not by me as I have
no idea how to do this(or to turn it back on), but am still recieving alerts
from defender. When I clicked on the link to fix theu the defender alert, the
web page was not available, and since then have been recieving windows alerts
telling me that it cannot find file, please be sure address is correct, with
an address I am completly unfamaliar with...... it reads cannot fnd
'file:///C:/WINDOWS/system32/drivers/pt.htm'

When I click on "ok" or to "X" out the popup, it gpes to an IE page, the
never loads, and freezes up my comp. can someone help me out here? Im
LOST!!!!
Oct 9 '07 #1
2 4164
"Jrxtuser1" <Jr*******@discussions.microsoft.comwrote in message
news:A6**********************************@microsof t.com...
>I just started using Windows Live OneCare, I had been using Norton, but was
unable to fix the problems I was having. I have yet been unsuccessful with
OneCare as well. I keep getting the same warning from OneCare, one is for
Adware, the other is for a trojan, I clean both, but almost immediatly, I
get
the same warning? My Windows Defender is also shut down, not by me as I
have
no idea how to do this(or to turn it back on), but am still recieving
alerts
from defender. When I clicked on the link to fix theu the defender alert,
the
web page was not available, and since then have been recieving windows
alerts
telling me that it cannot find file, please be sure address is correct,
with
an address I am completly unfamaliar with...... it reads cannot fnd
'file:///C:/WINDOWS/system32/drivers/pt.htm'

When I click on "ok" or to "X" out the popup, it gpes to an IE page, the
never loads, and freezes up my comp. can someone help me out here? Im
LOST!!!!

You have either a virus, some nasty malware, or both.
Have you tried booting in safe mode, then running your AV and anti-malware?
For more and better advice on using Live OneCare, try posting in a group for
OneCare, rather than in this .NET programming group.

To find the group you need:

http://www.microsoft.com/communities...D-2224A4FEB3EA

In the Search box put "Live OneCare" (without the quotes), then click Go to
find articles and groups related to your issue.

Oct 9 '07 #2
I will give you instructions on how to do a scan with OneCare on safemode
hope this helps

How to remove viruses by using Windows Live OneCare in safe mode
View products that this article applies to.
Article ID : 925222
First Published: : 9/8/2006
Last Reviewed: : 2/2/2007
Revision : 2.1
Modification Type : Minor
Language Locale : en-us
Article Status : Published
Confidentiality : Public
MICROSOFT INTERNAL SUPPORT INFORMATION
BUG #: 33150 (MSNIA Support Quality Response Team)
INTRODUCTION
Windows Live OneCare provides a command-line tool to remove or to quarantine
viruses in safe mode. This article describes how to use this tool.
MORE INFORMATION
You cannot remove some viruses when Microsoft Windows is running in its
usual mode. You must remove these viruses in safe mode. Windows Live OneCare
provides a tool to remove or to quarantine viruses in safe mode.

Important Use this tool only if a support agent directs you to do this.

To use this tool, follow these steps:
1. Restart the computer in safe mode.
2. Click Start, click Run, type cmd , and then press ENTER.
3. Type the following command, and then press ENTER:
cd %PROGRAMFILES%\Microsoft Windows OneCare Live
4. Type SafeModeAVScanner , include the options that are provided by
support personnel, and then press ENTER.
If you type SafeModeAVScanner without options, the following help appears:
C:\Program Files\Windows Live OneCareSafeModeAVScanner
Windows Live OneCare Safe Mode Virus and Spyware Scanning Tool
Usage: SafeModeAVScanner.exe [–s | –d < directory to scan >] [–b –h]
SafeModeAVScanner options
Usage: SafeModeAVScanner.exe [–s | –d < directory to scan >] [–b –h]
• -s scans the whole computer.
Note You cannot use -d together with this option.
• -d filepath scans a specified file or folder.
• -b scans the boot sector. When you use this option, memory is not scanned.
• -h performs a heuristic scan. This kind of scan looks for behavior that
may indicate the presence of a virus.
Sample usage • SafeModeAVScanner –s –h
These options use heuristic-based detection to scan the whole computer.
• SafeModeAVScanner –d c:\Users –h –b
These options scan the c:\Users folder and all boot sectors.

you could also search this on the registry to look for the infection and
delete it manualy

possible locations of viruses, spywares...
c:\windows\prefetch
c:\windows\temp

Registry:

hklm/software/ms/software/currversion/run, runonce,runonceex,runservices
hkcu/software/ms/software/currversion/run, runonce,runonceex,runservices
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows
NT/CurrentVersion/Winlogon/Shell - nail.exe
The loading feature will normally be in the right pane of the following keys
and will usually refer to the file name of the threat. Check these keys for
suspicious entries:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunServices

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunServicesOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer\Run

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnceEx

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunServices

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunServicesOnce

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\Explorer\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Windows\AppInit_DLLs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler

HKEY_CLASSES_ROOT\comfile\shell\open\command

HKEY_CLASSES_ROOT\piffile\shell\open\command

HKEY_CLASSES_ROOT\exefile\shell\open\command

HKEY_CLASSES_ROOT\txtfile\shell\open\command

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
With this branch selected, look in the right pane for the value: Userinit
This value should contain only C:\WINDOWS\system32\userinit.exe, and have no
additional programs specified after the comma.

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
With this branch selected, look in the right pane for the value: load
This value should be blank.

If you suspect that a system is infected, then examine each of these keys.
Determine whether Value Name or Value Data, including the (Default) value,
refers to a suspicious file.

Browser Helper Object (BHO)
Looking for suspicious entries that may have been added as a BHO is much
more complex than looking at the values of the keys shown above, as most BHOs
are legitimate. Also, this requires you to look at two different areas in the
registry.

Go to:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects
Directly under that key, in the left pane, look for any CLSID sub keys.

They will look similar to this example:

{06949E9F-C8D7-4D59-B87D-797B7D6BE0B3}
Write down each of the strings that you find (or copy and paste it into
Notepad.)
Browse to and expand the subkey:

HKEY_CLASSES_ROOT\CLSID\<string of letters and numbers>

where <string of letters and numbersis what you wrote down in step 3.

Under the expanded subkey, select the InProcServer32 key.

In the right pane, in the Name and Data columns--including the (Default)
value--look for any file name that look suspicious.

Search either the hard drive or the Web--or both--to either confirm or deny
these suspicions. Only if you can confirm that the file name is linked to a
malevolent file should you delete the value.
Other load points

Another possible method that is used to load an infector is to hide a file
and place it--or a shortcut to it--in one of the StartUp folders. In Windows
NT-based environments, there can be multiple StartUp folders.
On the Windows desktop, right-click Start Open All Users.
Double-click Programs.
Double-click Startup.
Look for any suspicious files. Normally these will be shortcuts, but you may
find .exe, .hta, or similar files. Be sure to set the view options to Show
all files and to display file extensions.
Repeat steps 2 through 4 for the current user's StartUp group by
right-clicking Start and then clicking Open.
Less common are loaders that hackers have placed on the system. These can be
located in many different locations. In many cases, they can be found only by
scanning with your Symantec antivirus product using current definitions.

Due to the nature of Windows 2000/XP, many threats run as a process, so that
they can be protected by the operating system after they are executed. To
look for these, open the Task Manager and look for them on the Processes tab.
Because there are many processes running, you must either know the name of a
specific process to look up (for example, as described in a virus write-up)
or the names of processes that normally run on your computer.
Close all programs, saving any work.
Press Ctrl+Shift+Esc to open the Task Manager.
On the Process tab, click Image Name twice to sort the processes.
Look through the list for possible threats. When a suspicious process is
located, select it, and then click End Process.
You can now locate and delete the loader files, and then remove any load
points from the registry.
--
Prevention is better than cure
"PvdG42" wrote:
"Jrxtuser1" <Jr*******@discussions.microsoft.comwrote in message
news:A6**********************************@microsof t.com...
I just started using Windows Live OneCare, I had been using Norton, but was
unable to fix the problems I was having. I have yet been unsuccessful with
OneCare as well. I keep getting the same warning from OneCare, one is for
Adware, the other is for a trojan, I clean both, but almost immediatly, I
get
the same warning? My Windows Defender is also shut down, not by me as I
have
no idea how to do this(or to turn it back on), but am still recieving
alerts
from defender. When I clicked on the link to fix theu the defender alert,
the
web page was not available, and since then have been recieving windows
alerts
telling me that it cannot find file, please be sure address is correct,
with
an address I am completly unfamaliar with...... it reads cannot fnd
'file:///C:/WINDOWS/system32/drivers/pt.htm'

When I click on "ok" or to "X" out the popup, it gpes to an IE page, the
never loads, and freezes up my comp. can someone help me out here? Im
LOST!!!!


You have either a virus, some nasty malware, or both.
Have you tried booting in safe mode, then running your AV and anti-malware?
For more and better advice on using Live OneCare, try posting in a group for
OneCare, rather than in this .NET programming group.

To find the group you need:

http://www.microsoft.com/communities...D-2224A4FEB3EA

In the Search box put "Live OneCare" (without the quotes), then click Go to
find articles and groups related to your issue.

Oct 26 '07 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
by: pavan | last post by:
hi friends,this is pavan,my project is to add a toolbar to windows live messenger in vc++ 6.0 or above,the toolbar must be like sweetIM toolbar for MSN messenger,can any one help me in how to write...
9
by: aaronluna | last post by:
Hi All, I was wondering if it is possible to easily convert an asp.net user control (.ascx) into an equivalent windows app. I plan on simply duplicating the user control in a c# windows app...
1
by: =?Utf-8?B?ZHVlY2U=?= | last post by:
I am having problems with onecare, it won't finish installing, have tried many different attempts, emails, phone, etc.------ when i run REGETIT it gets a system 32 error--- this product worked fine...
1
by: =?Utf-8?B?SEQ=?= | last post by:
hi, i recently bought a new laptop with vista home premium and downloaded windows live messenger but about 3 seconds after login, the program stops responding and needs to close down. I see a...
2
by: Ayoson | last post by:
Hiya! Can ayone help me out here? My Folder Options has disappeared from the Tools menu so I cannot access my Hidden files. The Run command button has disappeared from my Start menu. My...
1
by: baluMunugoti | last post by:
Hi to all.. We are going to develop an asp.net website which supports accessing the windows live spaces.. we need to integrate windows live spaces in asp.net application..like accessing live...
1
by: =?Utf-8?B?QWRwcm9m?= | last post by:
Why is Adaware suddely incomaptible with OneCare? Just about two weeks ago I began to get a warning, indicating that I should remove adaware because it dangerously interferes with OneCare (up until...
1
by: =?Utf-8?B?QWRwcm9m?= | last post by:
Since I installed OneCare I have noticed my computer slowing down significantly. Has anyone else experieced this?
0
by: Charles Arthur | last post by:
How do i turn on java script on a villaon, callus and itel keypad mobile phone
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
0
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
0
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing,...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.