BitDefender- outbound attempt from quarantine?

Discussion in 'other anti-virus software' started by acr1965, Aug 27, 2007.

Thread Status:
Not open for further replies.
  1. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    I installed BD 10 free edition and ran a scan. It identified one of my HP update files as malware and placed it in quarantine. I then shut down BD. Later I saw an alert pop up from Online Armor fw stating there was an outbound connection attempt. The file was marked as coming from BD quarantine and the IP address was to Hewlett-Packard. Has anyone else encountered a similar issue as this?
     
  2. kinwolf

    kinwolf Registered Member

    Joined:
    Oct 19, 2006
    Posts:
    271
    I had a problem with some HP utility file too some months ago. The file changed the home page of IE to point to HP support and was doing other stuff, like phoning home, that seem to be enough to be classified as riskware even if it's from HP.

    Now in your case, my guess is that since you shut down bitdefender, the quarantine area isn't really working anymore and the file is phoning home.

    Personally, after reporting it as a possible FP for months to BD, I ended up deleting that file. Too much trouble and it's not useful anyway.

    Kin
     
  3. Thug21

    Thug21 Registered Member

    Joined:
    Jun 17, 2007
    Posts:
    141
    Location:
    Illinois
    I would think that even if you shut down the Bitdefender, the file would still stay quarantined. The files should be encrypted and meant to stay there securely.
     
  4. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    Yeah, that's the purpose of quarantining it, it should then be unable to run or otherwise do anything at all.. Not sure what's going on there.. but it would appear that BD didn't do something properly.. If not needed, I think I would just delete that file anyway...
     
  5. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    Yes that was my concern. The log file from Online Armor states the following-

    C: Documments and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\Backweb-137903.exe, Outgoing Access Blocked, Port 480
     
  6. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    it sounds like BD is trying to submit the quarentined files to their analyists.

    your online armour is blocking this.

    well thats what i think, however... i aint sure with BD 10 free.
     
  7. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    I ran the IP address of the destination and it came back as HP.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.