At present Firewall is showing that files are modified and wants to connect when the file is not ( at least on disk, checked with hashes ). Either an update was pushed that introduced an issue or I have a very stealthy in memory rootkit that is changing all sort of things on the fly and not stepping on disk and Bitdefender is somehow checking for file modification in memory as well.
Behavior was introduced around 09/07/2026.
Issue :
Unchanged files on disk are being reported as changed by Bitdefender Firewall.
They do have rules already set and when new Allow/Block rule is clicked it goes in the same existing Rules under the existing file.
Setup :
Windows 11 ( fully updated )
Bitdefender Total Security ( auto updates ON )
[All Adapters set to Public] > Firewall Settings > Alert Mode ON
[General] Settings password protected as when on Autopilot the Firewall stops Alert Mode
Was there an update pushed that has anything to do with how file modification is being detected Around 09/07/2026 ?
Where we can check changelogs for updates ?
I have not yet re-installed the product as I want to know is this a simple update jump scare or a real serious infection. It may be a thing with the hash database, yet same files are being showed as 'modified' again and again ( Firefox, nvngx_update, wermgr etc. - all unchanged on disk, same file hashes )
I haven't checked last access/modified time stamp on the files, but that should not be used for any sort of algo for file change tracking on it's own or have a serious weight in one.