# Virus won't let me update anti-virus software.

**URL:** <https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783>\
**Category:** Factual Questions\
**Created:** [February 14, 2009, 3:36am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783 "2009-02-14T03:36:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lakai](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@Lakai](https://boards.straightdope.com/u/Lakai)\
**Post date:** [February 14, 2009, 3:36am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/1 "2009-02-14T03:36:59Z")

</div>

Some weird things are happening with my computer that I think are caused by a virus.

First, most of the Google search results are redirecting me to advertisements.

Second, I get a network error message when I try to bring up the website that hosts Spybot Search and Destroy. I downloaded the executable file on another computer, but then could not install it on my current computer. The error message just tells me there is a network error.

Third, Ad-ware and AVG can’t update themselves. I ran both of them in safe mode, but the problems keep coming up.

As far as I know there doesn’t seem to be anything wrong with my internet connection. The only issue is that Google takes me to advertisements and a few spyware/virus prevention applications don’t work.

My OS is Vista. Any suggestions?

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [February 14, 2009, 3:50am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/2 "2009-02-14T03:50:33Z")

</div>

Download [MalwareBytes AntiMalware](http://www.malwarebytes.org/mbam.php). Install and update. If it won’t scan, rename the executable (mbam.exe) to malbytes.exe, and run it again.

---

<div class="post-metadata">

**Author:** ![Polycarp](https://avatars.discourse-cdn.com/v4/letter/p/82dd89/32.png) [@Polycarp](https://boards.straightdope.com/u/Polycarp)\
**Post date:** [February 14, 2009, 4:08am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/3 "2009-02-14T04:08:28Z")

</div>

[A possiblae culprit](http://www.networkworld.com/news/2009/012309-downadup-conflicker-worm.html), based on the behavior described in the OP. (I don’t have advice, but happened on that while updating my AVG today, so offered it for what it may be worth.)

---

<div class="post-metadata">

**Author:** ![Madgolf](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@Madgolf](https://boards.straightdope.com/u/Madgolf)\
**Post date:** [February 14, 2009, 4:48am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/4 "2009-02-14T04:48:20Z")

</div>

I second Malwarebytes. It is the 2009 superstar like Spybot was in 2003.

I bet Vundo/Virtumonde is your culprit.

---

<div class="post-metadata">

**Author:** ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)\
**Post date:** [February 14, 2009, 6:43am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/5 "2009-02-14T06:43:26Z")

</div>

> [@Polycarp](#):
>
> [A possiblae culprit](http://www.networkworld.com/news/2009/012309-downadup-conflicker-worm.html), based on the behavior described in the OP. (I don’t have advice, but happened on that while updating my AVG today, so offered it for what it may be worth.)

This is a bad virus.

> [@](#):
>
> REDMOND, Wash. — Feb. 12, 2009 — Today, Microsoft Corp. announced a partnership with technology industry leaders and academia to implement a coordinated, global response to the Conficker (aka Downadup) worm. Together with security researchers, Internet Corporation for Assigned Names and Numbers (ICANN) and operators within the Domain Name System, Microsoft coordinated a response designed to disable domains targeted by Conficker. **Microsoft also announced a $250,000 reward** for information that results in the arrest and conviction of those responsible for illegally launching the Conficker malicious code on the Internet.

Source: [http://www.microsoft.com/Presspass/press/2009/feb09/02-12ConfickerPR.mspx](http://www.microsoft.com/Presspass/press/2009/feb09/02-12ConfickerPR.mspx)

---

<div class="post-metadata">

**Author:** ![Lakai](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@Lakai](https://boards.straightdope.com/u/Lakai)\
**Post date:** [February 14, 2009, 9:29pm UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/6 "2009-02-14T21:29:54Z")

</div>

It was Vundo.

My grueling two day battle has come to an end. It was taken apart by Malwarebytes, one byte at a time.

I couldn’t download Malwarebytes on my infected computer (website was blocked), but I managed to do it on my laptop and transfer it over.

Once it deleted Vundo, my internet connection wouldn’t work. For some reason there was no address for the DNS server. Once I put that in everything worked fine.

Excellent advice guys. Thanks to everyone.

---

<div class="post-metadata">

**Author:** ![tim-n-va](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tim-n-va/32/3001_2.png) [@tim-n-va](https://boards.straightdope.com/u/tim-n-va)\
**Post date:** [February 15, 2009, 1:42am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/7 "2009-02-15T01:42:31Z")

</div>

Glad you solved it. For anyone else having a similar problem, one more data point: I can’t remember the specific virus but my son had one on his computer that put bogus entries in the hosts file for all of the major AV companies. These were added after enough blank lines that the bogus entries didn’t appear on the screen unless you scrolled down. Since the host file is usually checked before any DNS check, this was an effective block of updates.

---

<div class="post-metadata">

**Author:** ![Myglaren](https://avatars.discourse-cdn.com/v4/letter/m/f1d935/32.png) [@Myglaren](https://boards.straightdope.com/u/Myglaren)\
**Post date:** [February 15, 2009, 2:51am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/8 "2009-02-15T02:51:19Z")

</div>

Install the Spybot Search & Destroy hosts file then lock it.

---

<div class="post-metadata">

**Author:** ![Madgolf](https://avatars.discourse-cdn.com/v4/letter/m/d6d6ee/32.png) [@Madgolf](https://boards.straightdope.com/u/Madgolf)\
**Post date:** [February 15, 2009, 4:34am UTC](https://boards.straightdope.com/t/virus-wont-let-me-update-anti-virus-software/485783/9 "2009-02-15T04:34:16Z")

</div>

As a follow up to my correct deduction of Vundo…

I tried once to eradicate the newest incarnation of Vundo by hand. It was a valiant effort but I was defeated.

The reason I went after it without the help of Malwarebytes is that I accidentally stumbled upon a site who wanted to charge me for the download and of course I thought “Nertz to that!”. This is in November when the new variations surfaced.

I tried every tried and true method - Spybot, Kaspersky, Spysweeper, and the traditional Vundo-killer (via plugin) Ad-Aware. (Vundo is six years old) I worked in safe mode, I worked with Ultimate Boot Disk, I did every thing right - killed all suspicious processes, shut down system Restore, manually killed every new file that showed on reboot. There was nothing that could kill this infestation.

After six hours total over a weekend, I revisited a Malwarebytes thread and found out it is not generally a paid program and downloaded the real one from the source. (palmface)

This was the only time Kaspersky let me down and one of the few times I could not handle an infection by hand even with severe time investment.

Frankly I am surprised Vundo is not written about more than it is. I consider their crapulent technique legendary. I know it is introduced legally to the consumer, but man is it a royal pain.

Regarding the last post - via Wiki: Spybot Search & Destroy is able to block generations of Vundo that are older than Trojan.Vundo.F. Some modern variants of Vundo can exploit the presence of Spybot Search & Destroy by infecting TeaTimer.exe, a program that is bundled with Spybot.

> **[Vundo](https://en.wikipedia.org/wiki/Vundo)**
>
> The Vundo Trojan (commonly known as Vundo, Virtumonde or Virtumondo, and sometimes referred to as MS Juan) is either a Trojan horse or a computer worm that is known to cause popups and advertising for rogue antispyware programs, and sporadically other misbehavior including performance degradation and denial of service with some websites including Google and Facebook. It also is used to deliver other malware to its host computers. Later versions include rootkits and ransomware.
> A Vundo infection ...
