Bitdefender Runs Like A Virus

SaintJimmy
SaintJimmy ✭✭
edited August 2011 in General

Hi,


I recently installed and activated bitdefender total 2012, this was done on a clean install of win 7 x64. Ever since then my system has been running really badly.


Win 7 and bitdefender are installed on a 64GB SSD.


There is a 1TB data drive attached in RAID 0


Im using an i7 920 @3.8GHz


It looks like it's not compatible with my blue ray drive as when it's connected it takes about 15 seconds to open windows explorer or even just to right click on it from the desktop.


There is now an extra blank screen on booting windows that takes 15-20 seconds.


It's constantly hammering my hard disks.


Firefox randomly freezes for about 30 seconds.


These are just the problems that I've noticed in the first 24 hours use, don't really wan't to keep this on my PC. Please can someone help fix this or let me know how to get my money back.


My sys info:


OS Name Microsoft Windows 7 Home Premium


Version 6.1.7601 Service Pack 1 Build 7601


Other OS Description Not Available


OS Manufacturer Microsoft Corporation


System Manufacturer System manufacturer


System Model System Product Name


System Type x64-based PC


Processor Intel® Core i7 CPU 920 @ 2.67GHz, 2667 Mhz, 4 Core(s), 8 Logical Processor(s)


BIOS Version/Date American Megatrends Inc. 0108, 23/03/2010


SMBIOS Version 2.5


Windows Directory C:\Windows


System Directory C:\Windows\system32


Boot Device \Device\HarddiskVolume1


Locale United Kingdom


Hardware Abstraction Layer Version = "6.1.7601.17514"


Time Zone GMT Daylight Time


Installed Physical Memory (RAM) 6.00 GB


Total Physical Memory 5.99 GB


Available Physical Memory 3.68 GB


Total Virtual Memory 12.0 GB


Available Virtual Memory 9.39 GB


Page File Space 5.99 GB


Page File C:\pagefile.sys


Thanks.


EDIT: - Oh and now VSSERV.EXE has stopped responding and wants me to restart my pc, wondered why there was silence from my hard drives.

Comments

  • Hello,


    In order to troubleshoot the issue you are encountering please send us the following:


    1. A Support Tool log;


    [how to GENERATE A STANDALONE SUPPORT TOOL LOG]


    . Save and extract the Bitdefender_Supporttool tool to a location of your choice:


    http://www.bitdefender.com/files/Knowledge...Supporttool.exe


    . Double-click on the Bitdefender_Supporttool.exe file (if you are using Vista or Windows 7, right-click on the Bitdefender_Supporttool application file and select "Run as Administrator");


    . Fill in the required information and press the "Next" button (make sure you use a valid email address and include a detailed description of the issue you are encountering);


    NOTE! If you want to reproduce the issue and enable additional logging you will have to restart the computer and then use the Support Tool again after reproducing the issue to complete the data gathering;


    . A file will be created on your desktop (BDSP_*);


    . Upload that file to an online file hosting website such as: sendspace.com; rapidshare.com; mediafire.com then send me a PM (Private Message) with the download link.


    Kind regards,

  • Thanks DanyDan, I have sent you a PM, please let me know if there are any issues.


    Hello,


    In order to troubleshoot the issue you are encountering please send us the following:


    1. A Support Tool log;


    [how to GENERATE A STANDALONE SUPPORT TOOL LOG]


    . Save and extract the Bitdefender_Supporttool tool to a location of your choice:


    http://www.bitdefender.com/files/Knowledge...Supporttool.exe


    . Double-click on the Bitdefender_Supporttool.exe file (if you are using Vista or Windows 7, right-click on the Bitdefender_Supporttool application file and select "Run as Administrator");


    . Fill in the required information and press the "Next" button (make sure you use a valid email address and include a detailed description of the issue you are encountering);


    NOTE! If you want to reproduce the issue and enable additional logging you will have to restart the computer and then use the Support Tool again after reproducing the issue to complete the data gathering;


    . A file will be created on your desktop (BDSP_*);


    . Upload that file to an online file hosting website such as: sendspace.com; rapidshare.com; mediafire.com then send me a PM (Private Message) with the download link.


    Kind regards,

  • Hello,


    The logs are not complete. Please generate them again and make sure you wait until the window has finished gathering the info as the main file was missing from the logs you've sent (sysdump.html).


    Regards,

  • Hello,


    The logs are not complete. Please generate them again and make sure you wait until the window has finished gathering the info as the main file was missing from the logs you've sent (sysdump.html).


    Regards,


    Not sure what happened there then, I've run the tool again and sent you the new link, also is there a problem with the download from the link you gave me? As at first I thought it was broken as nothing happened, but after a few minutes it proceeded to download at 15KB/s taking over 10 minutes for the 11.9MB download.

  • Hello,


    Got the logs and they are complete now. I have found another security solution running on your PC:


    C:\Program Files\The Shield Deluxe\The Shield Deluxe 2011\avinfo.exe


    Please uninstall it from Add/Remove Programs (Programs and Features) then restart the PC. Repair BitDefender as explained below and let me know if the issue is resolved or persist.


    1. Click on the START menu button;


    2. Search for "BitDefender 2012";


    3. Select "Repair or Remove";


    4. Select "Repair";


    5. Follow the onscreen instructions and restart the PC when requested;


    Please let me know if the issue is now resolved.


    Best regards,

  • Thanks for your reply again, I not quite sure what to do now, like I said this is a clean install of win 7 and Bitdefender is the onlyu virus protection I have installed. As far as I can tell 'The Shield Deluxe 2011' is a rogue security application that does a fake scan and pretends to fix your virus problems for a fee. I have never and would never install such an application.


    'The Shield Deluxe 2011' isn't present in add remove programs and there is nothing in C:\Program Files\ or C:\Program Files (x86). I also can't find anything in the processes currently running:


    Logfile of Trend Micro HijackThis v2.0.4


    Scan saved at 18:14:16, on 26/08/2011


    Platform: Windows 7 SP1 (WinNT 6.00.3505)


    MSIE: Internet Explorer v9.00 (9.00.8112.16421)


    Boot mode: Normal


    Running processes:


    C:\Program Files\Bitdefender\Bitdefender 2012\Antispam32\pchooklaunch32.exe


    D:\Steam\Steam.exe


    C:\Users\JimmyMac\AppData\Roaming\Dropbox\bin\Dropbox.exe


    C:\Windows\SysWOW64\rundll32.exe


    C:\Users\JimmyMac\AppData\Local\Citrix\ICA Client\concentr.exe


    C:\Users\JimmyMac\AppData\Local\Citrix\ICA Client\wfcrun32.exe


    C:\Program Files (x86)\Mozilla Firefox\firefox.exe


    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe


    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


    F2 - REG:system.ini: UserInit=userinit.exe


    O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry


    O4 - HKLM\..\Run: [ConnectionCenter] "C:\Users\JimmyMac\AppData\Local\Citrix\ICA Client\concentr.exe" /startup


    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun


    O4 - HKCU\..\Run: [steam] "D:\Steam\Steam.exe" -silent


    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-21-2888124793-505230597-558529978-1003\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')


    O4 - HKUS\S-1-5-21-2888124793-505230597-558529978-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')


    O4 - Startup: Dropbox.lnk = JimmyMac\AppData\Roaming\Dropbox\bin\Dropbox.exe


    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics


    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab


    O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareup...13/CTPIDPDE.cab


    O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwareup...015/CTSUEng.cab


    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup...15118/CTPID.cab


    O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\JimmyMac\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll


    O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\JimmyMac\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll


    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)


    O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe


    O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe


    O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe


    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)


    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)


    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)


    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)


    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)


    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)


    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe


    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)


    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)


    O23 - Service: SafeBox - BitDefender - C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe


    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)


    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)


    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)


    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)


    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe


    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe


    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)


    O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe


    O23 - Service: BitDefender Desktop Update Service (UPDATESRV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe


    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)


    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)


    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)


    O23 - Service: BitDefender Virus Shield (VSSERV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe


    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)


    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)


    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)


    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)


    --


    End of file - 8022 bytes


    Hello,


    Got the logs and they are complete now. I have found another security solution running on your PC:


    C:\Program Files\The Shield Deluxe\The Shield Deluxe 2011\avinfo.exe


    Please uninstall it from Add/Remove Programs (Programs and Features) then restart the PC. Repair BitDefender as explained below and let me know if the issue is resolved or persist.


    1. Click on the START menu button;


    2. Search for "BitDefender 2012";


    3. Select "Repair or Remove";


    4. Select "Repair";


    5. Follow the onscreen instructions and restart the PC when requested;


    Please let me know if the issue is now resolved.


    Best regards,

  • Hello,


    This is what I have found in the logs you've generated and sent on August 24th:


    56    avinfo.exe    3588    2920    2    Normal


    I have created a ticket for you and escalated to my colleagues from Malware. They will contact you further via email.


    Ticket ID: 201108241055376.

    post-20064-1314676706_thumb.jpg

  • Hello,


    This is what I have found in the logs you've generated and sent on August 24th:


    56    avinfo.exe    3588    2920    2    Normal


    I have created a ticket for you and escalated to my colleagues from Malware. They will contact you further via email.


    Ticket ID: 201108241055376.


    Is it not just Bitdefender? - C:\Program Files\Bitdefender\Bitdefender 2012\avinfo.exe


    Or is it definitely something else.

  • Hello,


    I would like to see a more complex log therefore I've sent you instructions via email on how to generate them. Please reply via email with the requested log files.


    Thank you!

  • Hello,


    I would like to see a more complex log therefore I've sent you instructions via email on how to generate them. Please reply via email with the requested log files.


    Thank you!


    Sorry for the delay, I have now replied to your email with the required information.

  • Hi Jimmy,


    I've replied to your ticket: 201108241055376.


    Regards,