Hello to you!
I registered for this forum while researching the same problems like 'lorangerboy', but with the product 'BD Internet Sceurity v10'.
I'm running two pc's and for heavens sake only one of them is 'attacked' resp. 'infiltrateted' resp. 'pested' (?) and I can use the second one to connect to this forum.
History of research and results:
While updating automatically every two hours BD is showing up its trial-to-connect in the tool bar and I always felt ensured that the program will fetch its updates. This was wrong! By doing my end-of-the-year cleanup-of the-pc-system I had to recognize that the last automatically fetched updated was dated of 25th of november 2008!
Now after this long time, there is no way to remember or to clearly lineout the way of getting infiltrated - maybe while strolling along on 'meat street' or by one of those freakish spam- or junk-mails bombarding my mail-account from all over the world... I don't know and its not this important to know by now!
The results of 'nslookup' / 'tracert upgrade.bitdefender.com' are identically with those of 'lorangerboy'.
I also looked up the 'hosts'-file resp. 'lmhosts.sam'. These are looking sober.
@'Sebduc': Your idea of installing MBAM by renaming the install file is nice but didn't work out. My pested system did allow the installation from a renamed file, but there is no way to get the program started. By double-clicking, the sandglass is shown for maybe one second then there is limbo. Filemanager shows 'nothing in process', so does BDs 'action window'.
This pest is very repressive ...
In addition, the pested system will contact each and any website except all of those handling with antivirus-/malware-/etc.-protection (this includes www.bitdefender. ... with any suffix). One thing is worth to quote: This pest affects any research done with Google! Normally by clicking on the underlined first line you will be led directly to the quoted site. Not any longer ... !
One example:
-> google -> research 'bitdefender' leads to 'http://search.live.com/results.aspx?FORM=DNSAS&q=www.bitdefender.com'
-> clicking on the underlined first line belonging to the shown in green 'www.bitdefender.com' results in being warped to
-> 'http://websecurityexamine.com/scan/index.php?affid=06300' that shows up some faked system scan and a popup window where you are asked to 'return to system security and download it secure to your pc'.
Denying this shows up another popup window with even more 'pressure' (because now using the 'windows update symbol')
Denying this too you will see again the 'live.search.com'-results-window an now in front the 'normal gui-requester' that asks again to download following file -> 'install.exe' / '61,5 kb' / distributed by 'websecurityexamine.com'
Now this was getting to look pretty interesting and I was motivated to do a little more research (one of the eldest questions in police work is 'qui bono?', or : who will get the benefit?) that had in result the following:
-> Registrant of 'www.websecurityexamine.com' is a private person with an american name, residing in Nashville, Tennessee, USA
-> Registar (that means this is the company from which the registrant Mr Brooks has 'bought/lend/whatsoever' the domain 'websecurityexamine.com') is a company which belonging WHOIS-Server has the referral URL
->
http://www.webnames.ru(If interested in names, you can look them up easily by yourselves using for example 'www.nic.com' resp. 'whois.com'. My interest is NOT to point on the bad guys - this has to be interest and work of official sites - but to help BD to know at least even one 'counterpart')
Maybe this helps BD to imagine the well of the pest that is hindering my antivirus-software to work properly and to name a helpful weapon to clean up my system.
@catalin salgau -> would you please be so kind to led my informations mentioned above to your advisors and maybe you have an idea to help me and others with the same problem?
Thx for your time ...