Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Falsely Detect Port Scan Attempt

coolcool1227
coolcool1227 ✭✭✭
edited July 2011 in Firewall

Bitdefender and detects Secondary DNS Server as Port Scan Attempt and Block it and continue to detect this repeatedly.


In the Events it display


Local IP: 192.168.1.209


Remote IP: 202.142.160.2


Kindly note that the Remote IP is Secondary DNS Server's IP.

«1

Comments

  • Although Rule for DNS over UDP and TCP are allowed. And the above said blocking is for Protocol UDP.

  • Bitdefender also detect Primary DNS Server as Port Scan Attempt and block it. And after that my Internet speed reduced very much and I've to disable and re-enable my Network Adapter.

  • yes its happened to me too! Bitdefender support people please fix this.

  • Why is version final still bugs ??????????? Speed download is very low!!!!!!!!!!! Support

  • Today Bitdefender falsely detect Primary DNS as Port Scan Attempt again. Sometimes it detects Secondary DNS also. After that the internet speed has been reduced and I've to disable and re-enable my network adapter.

    post-31288-1314157352_thumb.jpg

  • Today Bitdefender falsely detect Primary DNS as Port Scan Attempt again. Sometimes it detects Secondary DNS also. After that the internet speed has been reduced and I've to disable and re-enable my network adapter.


    I have same problem...

  • coolcool1227
    coolcool1227 ✭✭✭
    edited September 2011

    The said issue is occuring again since last two days. Bitdefender detects DNS servers assigned whatever manually or DHCP as port scan attempt. But there is no reply -_-

  • Same for me with my DNS servers even when added to whitelist.


    I brought this issue up a month ago and I'm still waiting for a response to my pm's and a solution <img class=" />

  • MaresK
    edited September 2011

    I tried everything (including adding DNS servers to whitelist). The only option is really set port scans blocking feature to off. So now I have disabled port scan blocking (but this setting is forgotten after reboot), renamed bdtl.dll, disabled automatic updates and lack of a scheduled scans. I'm seriously thinking about returning to BDIS 2011... <img class=" />

  • coolcool1227
    coolcool1227 ✭✭✭
    edited September 2011

    Now the frequency of said issue has been increased, but still there is no reply -_-

  • coolcool1227
    coolcool1227 ✭✭✭
    edited September 2011

    Bitdefender display pop-up for Port Scan attempt, but the Events are not highlighted for them may be because they are classified as "Warning".

  • Those pop-ups are just notifications. The "scan" is blocked for the DNS just until the rule is created. Considering this, you should not have any interruptions on the internet connection.


    Any of you encounter any issues with the internet connection when or after the notifications are displayed ?

  • coolcool1227
    coolcool1227 ✭✭✭
    edited September 2011
    Those pop-ups are just notifications. The "scan" is blocked for the DNS just until the rule is created. Considering this, you should not have any interruptions on the internet connection.


    Any of you encounter any issues with the internet connection when or after the notifications are displayed ?


    The rules for DNS over UDP and TCP are already created by-default and set to "allow" but even then the pop-up displayed. Kindly see the attachment. I also faced the said issue by assigning DNS either by DHCP or by entering the DNS manually and also using different ISP. And after the pop-up appear, the internet browsing reduced very much i.e. web pages load very slowly, but I can download only from torrents.


    post-31288-1315805283_thumb.jpg

  • Waiting for reply.

  • Hello,


    I have same problem too.


    port scan detected with remote IP: 192.168.1.1 ( my adsl modem's IP)


    port scan detected with remote IP: 195.175.39.40 ( My dns number)


    protocol: UDP


    DNS over UDP is allow in settings.


    And finally, internet speed goint to slow.


    This problem began to occurs since 19th September and continues every 30-40 minutes.


    Any support , please.


    Regards


    System details:


    windows , Vista 32


    Bit defender internet security 2012

  • Hello,


    I have same problem too.


    port scan detected with remote IP: 192.168.1.1 ( my adsl modem's IP)


    port scan detected with remote IP: 195.175.39.40 ( My dns number)


    protocol: UDP


    DNS over UDP is allow in settings.


    And finally, internet speed goint to slow.


    This problem began to occurs since 19th September and continues every 30-40 minutes.


    Any support , please.


    Regards


    System details:


    windows , Vista 32


    Bit defender internet security 2012


    The same problem for me, I get a Port Scan warning almost everytime I load a page, or open Chrome or other browser ... please fix this...

  • Still waiting for reply.

  • I have exactly the same problem.... if i create a rule for one of these scans then my internet disconnects until i cancel it.


    I'm actually getting really fed up of it now. Anyone know if i can just stop the popups?

  • Any reply would be appreciated. :)

  • Will be fixed on the next product update.

  • Will be fixed on the next product update.


    Ace :-) when is this planned to be?

  • rootkit
    rootkit ✭✭✭

    Hi Cavey


    We can not provide for now an ETA for the next product update, but it will be released soon.


    Thank you in advance for understanding.

  • coolcool1227
    coolcool1227 ✭✭✭
    edited October 2011

    The subject issue occur again today even with the latest Build 15.0.32.1366

  • rootkit
    rootkit ✭✭✭

    Hi ONT.


    Thank you for your feedback.


    Please follow the steps explained in the article below and send me via PM the generated log file:


    http://forum.bitdefender.com/index.php?s=&...st&p=119338


    Have a nice day.

  • Hi Cristi


    Are you saying that the problem should have been fixed in a recent release? If that's the case then I'm still seeing this very regularly...


    Mike

  • rootkit
    rootkit ✭✭✭

    Hi Cavey


    Thank you for your feedback.


    Please also follow the steps from this post and send me a PM with the results.


    We will further investigate this issue.


    Have a nice day.

  • Same thing overhere, frequent popups, about blocking a port scan of the Google DNS server.


    No problem with blocking a port scan, but the popup is quite annoying. Is there any way to get rid of the popup?

  • Hi Cristi B.



    I have the exact same problem can I send you the log file?


    Please reply


    Thanks

  • rootkit
    rootkit ✭✭✭

    Hi


    Yes please. Follow the steps from that article and send your log via PM.


    Thank you.

  • rootkit
    rootkit ✭✭✭

    Hi


    Thank you for the log.


    I've send all the data to our development team and they are working to fix this issue.


    Th update will be delivered via automatic updates without user intervention.


    As a temporary workaround, please disable Block post scans from Firewall-Settings. Don't worry, the firewall will still protect your machine.


    post-9374-1319732672_thumb.png


    We are sorry for the inconvenience. Thank you in advance for your support and understanding.

  • Even i have same problem. Hope you guys fix it.

  • Hi


    We are very sorry for any inconvenience that we may have created and we rest at your disposal for further information.


    Thank you for your support and patience.


    Have a nice day.

  • It started happening while I was on eBay, so I thought it was them. So no one is actually scanning for open ports? or trying to harm my computer?

  • Hi and welcome to our forum.


    You machine is safe, the firewall is not turned off.


    It just a small issue that it will be fixed with a product update.


    Until then, please make the following settings in the product:


    http://forum.bitdefender.com/index.php?sho...st&p=124830


    Thank you very much.

  • Any idea on when this fix will be implemented yet?


    I'm still getting this problem and it's now some 4 months now since it was first reported <img class=" />


    2011 seems to have been a poor year (IMHO) for Bit Defender, I had serious issues with BD TS 2011 x64 which never worked for me properly and although it has lesser issues BD TS 2012 x64 is turning out to be pretty poor too :rolleyes:

  • Hi Nightgaunt


    The Dev. Team is working to fix this issue, I can not provide you an ETA for this.


    It will be fixed with a product update soon.


    Thank you.

  • maxrockpro
    edited November 2011

    I have the same issue. Mostly it happens when I click the back button on either of my browsers (IE9 and Chrome). Even otherwise it happens occassionaly and the detected IP is my ADSL modem's 192.168.1.1.


    Also, my Windows explorer.exe keeps freezing while surfing. Why? No error message. I have to keep Anti Phising and Safe Search disabled or else surf at a crawling speed with 1 Mbps connection.


    Did you'll release a beta version in a hurry without proper coding and testing?


    I have already posted in the thread about Scheduled scan feature missing issue.


    This is my first disappointment with BD in 3 years.

  • Hi


    We apologize for any negative experience you have encountered with our products or our support. Your feedback is appreciated, and will be directed to the appropriate team for review, to enable us to improve our support and services.


    Now, regarding the internet slowdown issue, please check out this topic:


    http://forum.bitdefender.com/index.php?sho...st&p=125795


    Regarding the port scan issue, please make these settings in the product:


    http://forum.bitdefender.com/index.php?sho...st&p=124830


    Thank you.


  • I still have the same problem. Postscan from secondary dns detected every 4 to 5 minutes or so. The same problems on two different pc:s. Getting tired...

  • I still have the same problem. Postscan from secondary dns detected every 4 to 5 minutes or so. The same problems on two different pc:s. Getting tired...


    Hi Cristi


    No, it isn't fixed - I'm due to send you a log for a Trufos problem and I'll try to capture it in it.


    ...

  • Still not fixed. At least suggest to the developers that they could allow us the option to turn off the notification for now. As a novice programmer, I know they could easily program that into the code in no time. Also, I am not about to turn the option "block port scans" off, and I suggest no one else does that too. You never know if you might be providing an opportunity for someone or better yet a bot to footprint and collect information on the ports that you have open. Especially, if you have any specialty ports open for inbound connections. Honestly, it would not be so bad if the notification did not appear at the top of all open windows or minimize me from full screen mode.


    Thanks,


    Alex


    Security +, MCTS

  • will this problem cause lag spikes in internet usage, basically the usage goes to 0% ?

  • Nightgaunt
    edited November 2011

    Still got the same problem here too, yet another problem that has not been resolved within a reasonable time frame :(


    I mean almost 4 months since this thread alone was started, is anyone actually fixing anything in Bitdefender these days?


    That's a third of someones license time, totally unreasonable tbh and I doubt I shall be renewing again, your software has been seriously buggy in both 2011 and now 2012.

  • I've just discovered that due to this issue if I have block port scans switched on this disconnects my new tv from the dnla server even though a firewall rule is set up to allow everything on the the tv ip address.


    BD 2012 TS x64 constantly blocks port scans from the ip addresses in my own network.


    Since changing from BD2010 to 2011 and now 2012 I've had constant issues some of which have been on going for far too long now.


    Just how many employees does BD have working on these problems? I suspect in some cases none!

  • Another month has passed since anyone from BD posted to let us know the devs were working on a fix for this issue.


    No fix yet, nothing to keep us informed and worse still no deadline for a fix!


    Can someone at BD please give us some information, you must know by now what is causing this issue and at least have an estimate of when a fix will be implemented?

  • Just uninstal Bitdefender and switch to alternate solution, since they said we fixed it and they actually NOT. Thanks Bitdefender. 1 loyal customer gone forever.

  • Just uninstal Bitdefender and switch to alternate solution, since they said we fixed it and they actually NOT. Thanks Bitdefender. 1 loyal customer gone forever.


    Not that far behind you. Seriously, I am sick and tired of firing up a program for the first time, and within 5 minutes finding features that I really need to use yet the developers not only never even considered, but can't be bothered to fix. <img class=" />

  • rootkit
    rootkit ✭✭✭
    edited December 2011

    Hi guys :)


    Thank you for your feedback.


    Please follow the steps explained in the article below and send me via PM the generated log file:


    http://forum.bitdefender.com/index.php?s=&...st&p=119338


    I need to look for file version. In my opinion, in some cases, this could be generated because you don't have the latest product update installed.


    So if you still encounter this issue, please send me the log.


    Take care.

  • Nightgaunt
    edited December 2011

    @Chris, the amount of time this issue has been going on for is a total disgrace.


    As you are aware I've solved the problem myself by uninstalling BD2012 TS from my two pc's and using a competitiors internet security package which not only works but also found a number of trojans on my machine that both BD2011 TS and BD2012 TS did not find.


    I will never use your software again let alone continue to beta test it for you, the reasons?


    The slowest customer (lack of) support I've ever seen and the fact your software has more bugs than the Amazonian rain forest!


    No logs from me I'm afraid, you did however get my money and a year of my time which I think is more than enough!


    Not very constructive I'm afraid but hopefully some good feedback to take back to your marketing department and management.

This discussion has been closed.