Cannot update any antivirus or spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pozzydrive, Dec 29, 2006.

  1. Pozzydrive

    Pozzydrive Corporal

    Hi all

    Ok if anyone wants logs I will have to run everything again, however after running e.g. Bitdefender it removed a lot of stuff so did Counterspy, AVG, Spybot and Adaware, the problem I've got is that none of these programs can be updated with the latest definitions, even the paid for Norton Antivirus that is already on this laptop cannot update, Spybot stops twice through its checkng and a window appears with "There were problems with the include file C\Program Files\Spybot - Search _Destroy \Includes\Hijackers.sbi See include 'errors.Log' for details, when trying to update the definitions for Spybot an error window pops up saying "Error retrieving update file Socket error # 10061 connection refused, this seems to be the same as all the other software, cannot connect to server, AVG is the same and asks me to check the update manager, however I cannot access it, its not there, anyone any ideas.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Pozzy


    You can manually update the majority Security applications, which does aid if your webupdate functions are not working.

    I will list the manual updates to the applications you mentioned if available, you download and install or some instrcutions may need you to manually copy the definition files into a folder.


    Ad-Aware ( instructions on page )
    http://www.majorgeeks.com/Ad-aware_SE_referencefile_d726.html


    Spybot S&D
    http://www.majorgeeks.com/Spybot_Search_and_Destroy_Update_d3957.html

    Norton
    http://www.majorgeeks.com/Norton_Virus_Definitions_d3995.html


    Are you running this PC through a corporate network tho, if so you may have to adjust or add proxy settings.... or even check the firewall is not blocking these apps.

    I know for Spybot.. changing this info is done this way
    But run through the guide below as best as possible, you should be able to do most tasks.

    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Pozzydrive

    Pozzydrive Corporal

    Hi Halo

    Nice to hear from you, been a while, I was wondering is there a reason why I cannot update direct from the laptop, is it because of Malware, not one antivirus or spyware program will update and I've tried almost all of them, there must be a common denominator somewhere in my connection that can be fixed? However in the mean time will try the manual updates, tankyou very much and all the very best for the festive season.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Yes most likely it is because of malware if your connection has not changed to the internet, many malwares do block security applications from updating.

    Also as I mentioned do run through the guide and complete as many steps as possible for as soon as the malware guys have whatever logs you can attach fromt he list they will be able to start assisting you to remove the pest, you should after the cleanup routines at least be able to supply us these logs....

    Bitdefender - from step 6
    Panda Scan - from step 6
    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat
    HijackThis


    But also try to see if your apps will update in Safe Mode with Networking?

    Thank you and hope yours was good too :)
     
  5. Pozzydrive

    Pozzydrive Corporal

    Hi Halo

    Happy New Year to you and the gang, I'm going to have to call it a day on this laptop for now, still cannot implant the updated definitions into either AVG, Spybot or Adaware, tried everything, one or two downloaded programs that have to be paid for report viruses and others likes of Smitfraud says there are none, same as AVG which sometimes shows it is updated and then when I try to connect to the internet says that my Defs are 568 days out of date, but for now I'll have to leave it I'm due back to work in a couple of days and I work abroad so will have to return the laptop to family, once again thanks for your help and the help of others, take care and all the very best.

    Pozzy
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Frequently when you receive errors (especially Socket error # 10061 ) about not being able to update, it is because of 1 or 2 reasons:
    1. You are using a Proxy Server and did not configure the software you are trying to update to use your proxy.
    2. You told the software to use a Proxy Server and you don't have one.
    Neither of these are malware problems!
     
  7. Pozzydrive

    Pozzydrive Corporal

    Chaslang,

    Thanks for replying, how would I sort this out, I mean I don't see any numbers written in the proxy server section to enable connection and that also goes for my own PC which works just fine, also when I followed an online instruction about inputting proxy server info using the software address I think for Spybot or one of the others e.g.127.0.0.1 it didn't work, however if that was the case inputting such information then surely I would have to change it everytime, as each piece of software from different sources will have a different address, could you possibly walk me through it, please note I work away and will not be back home until the end of the month, therefore will not be able to sort this problem until my return, thankyou.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use a ProxyServer or don't you? If you don't use a Proxy, there is nothing to enter, you just need to make sure the software is not configured to use on. If another PC works fine on the same network and it is not configured for a proxy that means you don't have a proxy. Just make sure both PCs are configured the same way.

    127.0.0.1 is not a proxy server. That is your localhost (your PC).

    Try shutting down the any firewall software on the problem PC. Can you get updates now? If yes, that means you blocked your updates in your firewall.
     
  9. Pozzydrive

    Pozzydrive Corporal

    Hi Chaslang

    Firstly apologise for not getting back to you sooner, as I explained earlier I work away from home (overseas) and I am still over here for the next two weeks, also the laptop with the problems is not mine so could not bring it with me to fix.
    Ok down to business, I didn't know anything nor understand about proxy servers so you will have to excuse me for my ignorance, (I do think you are right though that the proxy server is not being used), I actually only know enough to get by, most of which your website has taught me, firstly I do know that the firewall is not the problem on the laptop however I found something of interest the other week in an article in the Computeractive magazine, so please find posted below, don't know how to attach, if too large then I apologise.

    Blocked Internet

    Q My computer was infected and now only shows two websites: virusbuster.com and eprotectpage.com. I cannot even get Google or Computeractive. I have Norton Antivirus and Firewall.
    How can I get rid of these two websites that are claiming to sell anti-virus programs and get Internet Explorer back?

    A Some viruses change an important Windows file called HOSTS. This is used when Windows is looking for a website. The address you type in such as www.computeractive.co.uk, mean’s nothing to a computer and has to be changed to a number. This is normally done by the ISP but Windows looks to its own settings first. If this file is changed it can stop websites from appearing or they may not be the websites you expected. Therefore you should be careful when editing this file and only do so as a last resort after a virus attack.
    To edit the hosts file, click on the Start Menu, then All Programs, Accessories and Notepad. Click on the File menu and select Open. Change the File of Type menu to All Files. Left click on My Computer along the left hand side of the window. In the main part of the window double click on Local Disc (C), Windows, system 32, drivers and then on etc. Double click on the HOSTS file (there is no file extention) to open it. A normal host file has 17 lines beginning with a # followed by a line that says ‘127.0.01 localhost’. If there are any files below this it may mean the file has been tampered with. There may be many blank lines between the authentic lines and the information added by the virus so be sure to scroll all the way down. Add a # character to the beginning of any extra lines. This will tell Windows to ignore them but leave them in the file in case they were important.

    A sure sign that a virus has attacked a PC is if websites of well known security companies such as www.symantec.com and www.mcafee.com are included in the list with the number 127.0.0.1. This tells the computer that the website is on its own disk, hence the inability to get help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you never attached any of the logs requested (not even GetRunKey, ShowNew, or HJT at a minimum which should have been possible) we don' t know what you have. There are literally thousands of infections that can block access to websites especially antispyware and antivirus software sites. Part of what is being referred to in the article you mentioned is a family of infections referred to as SmitFraud aka Zlob. Again, without logs, I cannot tell what your problem is exactly. You need to help us by giving us something more useful which is why we ask for logs. Even if the antispyware scanners we request cannot be download or run, you need to at least try each one and tell us what happens. Can you download, can you install, can you run. Where does it fail? If you cannot get updates, skip the updates (although some can be done manually like Spybot). If you cannot run without updating, skip this scanner and move on to the next step.......etc.

    We don't like to guess at fixes unless absolutely necessary because running something that is not necessary can also have negative side effects.
     
  11. Pozzydrive

    Pozzydrive Corporal

    Hi Chaslang

    As I said cannot do anything for at least another two weeks as I'm overseas, the second last email I sent, to which you replied, I had already started my journey without the laptop, I realise I had to send you logs but I had to first update the software prior to running it, however I could not update any of it, even manually for some reason it would not update, one thing that did happen was that AVG seemed to update manually but after running the program the icon in the bottom tray reverted back to grey again, so once I get back home I'll have another go will have more time then and will endeavour to get those logs sorted, sorry if I've been any trouble.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot updates can be downloaded and installed manually form here: Spybot Search and Destroy Update

    As for others like CounterSpy or AVG Antispyware, if you cannot run them skip them for now. The same goes for the two online scanners. If you cannot run them in either safe mode or normal boot mode, then skip them. However at a minimum the GetRunKey, ShowNew, and HijackThis logs will be needed for us to get a better feel for your problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds