Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Bitdefender always kicks out this program


  • Please log in to reply
12 replies to this topic

#1 muvywriter

muvywriter

  •  Avatar image
  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Missouri
  • Local time:12:47 AM

Posted 15 April 2023 - 09:04 AM

Because I am so extraordinarily non-computer savvy I'm not sure this is in the right place to post this question.  If not, would someone please direct me to the correct forum or just push this query over to where it belongs?

 

THIS COMPUTER SPECIFICATIONS

Device name      Jason

Processor            Intel® Core™ i7-6800K CPU @ 3.40GHz   3.40 GHz

Installed RAM    32.0 GB

Device ID             864972FC-40A5-467A-A2DB-12AD78DFF63B

Product ID           00326-00800-12624-AAOEM

System type        64-bit operating system, x64-based processor

Pen and touch   No pen or touch input is available for this display

Edition  Windows 10 Home

Version 22H2

Installed on         ‎9/‎29/‎2020

OS build               19045.2846

Experience           Windows Feature Experience Pack 120.2212.4190.0

 

This notification comes up several times on Bitdefender whenever I fire up this computer:

 

Suspicious connection blocked one minute ago.  Feature:  Online Threat Prevention
 
firefox.exe attempted to establish a connection relying on an expired certificate to bumper2.adobeprojectm.com. We blocked the connection to keep your data safe since websites must renew their certificates with a certification authority to stay current, and outdated security certificates represent a risk.
 
Relying on your unparalleled expertise as I have for ten years, could you please tell me what this is, if it's a problem or just a nuisance, and what to do about it? I don't have any idea what bumper2.adobeprojectm.com might be.
 
Thank you ahead of time for any help.

Edited by hamluis, 15 April 2023 - 02:17 PM.


BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  •  Avatar image
  • Moderator
  • 20,038 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:47 AM

Posted 15 April 2023 - 11:44 AM

Suggest you start a topic in the malware removal forums. Be sure to post both FRST logs.

 

Please follow the instructions in the Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help - Virus, Trojan, Spyware, and Malware Removal Help starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Help   , NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.

 

DO NOT bump your new topic. Wait for a response from one of the Team Members.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
If we are to have another contest in the near future of our national existence, I predict that the dividing line will not be Mason and Dixon’s, but between patriotism and intelligence on the one side, and superstition, ambition, and ignorance on the other. Ulysses S. Grant...Republican president who correctly predicted the cause of Trump's attempted coup.

 

 


#3 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,816 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:47 AM

Posted 16 April 2023 - 03:57 PM

And here is the VirusTotal search result for bumper2.adobeprojectm.com.
 
And here is the Hybrid Analysis search result for bumper2.adobeprojectm.com.
 
Good luck! :)

Edited by midimusicman79, 18 April 2023 - 03:37 PM.

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.


#4 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:47 AM

Posted 16 April 2023 - 07:06 PM

It's not malware related

The reason is clear the security certificate has expired

Screenshot-20230417-000449-Chrome.jpg
Screenshot-20230417-000417-Chrome.jpg

The above is from my clean and secure android phone

Edited by cryptodan, 16 April 2023 - 07:07 PM.

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#5 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,816 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:47 AM

Posted 16 April 2023 - 09:25 PM

There is an article on 10 Ways to Fix the NET::ERR_CERT_DATE_INVALID Error - Kinsta.

Good luck! :)

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.


#6 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:47 AM

Posted 16 April 2023 - 09:26 PM

There is an article on 10 Ways to Fix the NET::ERR_CERT_DATE_INVALID Error - Kinsta.

Good luck! :)


Nothing can fix this but a certificate update by Adobe in this case

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#7 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,816 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:47 AM

Posted 17 April 2023 - 03:47 AM

Thank you for pointing that out, cryptodan! :)

And I think it would be interesting to know if the OP, muvywriter, uses any Adobe software on his computer. :whistle:

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.


#8 muvywriter

muvywriter
  • Topic Starter

  •  Avatar image
  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Missouri
  • Local time:12:47 AM

Posted 20 April 2023 - 02:04 PM

I've gotten so confused by all these wonderful and welcome responses that I don't know which way to turn now.  I'm 76 years old and maybe a wee bit slower in forcing a fact or piece of information through the straining sieve of my old mind. 

 

This thing with Bitdefender is always over the same issue.  Here's a copy of the always similar notification I get from them sometimes fifty times a day:

 

"Suspicious connection blocked
2 minutes ago -Feature:Online Threat Prevention
 
firefox.exe attempted to establish a connection relying on an expired certificate to bumper2.adobeprojectm.com. We blocked the connection to keep your data safe since websites must renew their certificates with a certification authority to stay current, and outdated security certificates represent a risk."
 
Two minutes ago above is in real time.  Looks like it happens every few minutes whenever I'm at the keyboard.  I went to This PC and Control Panel, did a search of the data there, but nothing with this title was evident.  Adobe Acrobat Reader is the only program that applies to Adobe that is listed, right at the top of the Control Panel column. 
 
There is a program that I put on a month or so ago called "express.adobe.com" that isn't listed with the normal lists that is still in residence on my computer but not on the Control Panel, which was supposed to be a meme generator, but the whole world of that was so silly that I only went there once, even though it's still there.  Might be the culprit. 
 
If you guys aren't just worn out with my ignorance I'd sure like to keep trying to kick this intruder off my computer.  It might be something else entirely, but I'm just about at the limit of my computerology prowess.
 
Thanks for your patience, sirs or mademoiselles {had to look that up}.  I tell everybody I ever meet that your company is full of magicians, which is what I have encountered down all these years of our acquaintanceship.  Hope we can find another rabbit this time. Thanks for all the drudgery you have given me.  Jason Brooks


#9 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:47 AM

Posted 20 April 2023 - 02:16 PM

Download and install min-toolbox from here: https://www.bleepingcomputer.com/download/minitoolbox/
 
minitoolbox.png
 
With the following:
 
Last 10 error messages from the logs
Installed Application

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#10 muvywriter

muvywriter
  • Topic Starter

  •  Avatar image
  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Missouri
  • Local time:12:47 AM

Posted 20 April 2023 - 04:29 PM

Thanks for your assistance, Bleepin Madman.  I downloaded the minitoolbox and it did whatever it did for a few minutes, then checked out. It left behind language not a whit of which I could understand, most of it I didn't recognize. It didn't ask me to do anything else, so maybe it did it's job on its own?

 

When I see Navy and Blue and Gold together, I think of FBM submarines.  I was on the USS LEWIS AND CLARK {SSBN644}{B} for five years back when the Russians sunk our sister ship the USS SCORPION {SSN589} over near the Azores Islands, all hands lost.  A very hot Cold War.

 

Please lemme know if there's anything else I need to do in this case.  Thanks again, sir, for your help.  JB



#11 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:47 AM

Posted 20 April 2023 - 04:33 PM

Copy and paste the stuff from the file/ document it created in your next post.

Thank you for your service shipmate

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#12 muvywriter

muvywriter
  • Topic Starter

  •  Avatar image
  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Missouri
  • Local time:12:47 AM

Posted 20 April 2023 - 05:05 PM

Copy and paste the stuff from the file/ document it created in your next post.

Thank you for your service shipmate

I'm sorry, I don't know where that long list of stuff went?



#13 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:47 AM

Posted 20 April 2023 - 05:07 PM

It would likely be saved in c:\users\yourusername\Downloads

You can simply rerun it again.

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users