Serious Discussion Data leak: Avast Free or Bitdefender Free?

Jonny Quest

Level 23
Verified
Top Poster
Well-known
Mar 2, 2023
1,285
Friend if you want try to uninstall Bitdefender with its uninstallation process from the control panel and also uninstall the Agent.
After uninstalling it with "Antivirus Removal Tool" look for Bitdefender folders and files in the various folders that this tool finds (it is excellent for cleaning everything after uninstalling an AV). Use the search function, then for each path enter and delete the corresponding folders that it finds.
Then re-run the Bitdefender Free installation, so you should be able to do it, obviously using a mail account that does not have any Bitedefender subscription already active and associated.

Thanks :) The uninstall tool is the same one from your zip file (very nice, very handy :) ) It does uninstall the Agent when using it, part of the uninstall tools charm. But, it has always left a file (from experience) in Program Data/BD Logging. Unfortunately, it would be the same as my previous attempt, so I'll pass on trying it again. I would have better luck installing F-Secure 25.2 at this time ;) 😅

I did a web search and on Reddit, the answer was no, if you believe them, as far as the free version scanning the memory, at least in having that option as with the paid versions.

Thanks for your help, though :) :)

scan memory.jpg
 
Last edited:

Nunzio_77

Level 2
Thread author
Dec 3, 2023
82
The strange thing that perhaps everyone does not know or is still a mystery is that in the Free version all the other settings have a padlock symbol so they are not selectable.
The question is but are we sure that these functions are deactivated or simply blocked in active state and therefore not deactivatable or enableable at the user's choice while in the paid versions they can be modified?
For example, the Free version also blocks scripts, PUPs, adware and spyware and these settings are all blocked in the Free version.
It would be interesting to do a test to scan the process in memory to see if it is blocked or not.
 

SeriousHoax

Level 50
Verified
Top Poster
Well-known
Mar 16, 2019
3,944
I have confirmation from Bitdefender support that the default image options are the default ones in Bitdefender Free:

View attachment 287845
I don't think so unless something changed lately 🤔 It doesn't match with my own tests. Early last year, I found malwares for which BDTS's memory scanning was triggered shortly after running a malware.
I ran the same sample in BD Free and the detection occurred at a later stage by BD's behavior blocker ATC, not by memory scanning as it doesn't have it.
The scan script option in BD is AMSI. BD already has their own script emulation engine so it can scan scripts without AMSI, but AMSI was added later as an additional layer.
I verified in BD Free that it indeed does not have AMSI. It's easy to check using Process Explorer. In BDTS, BD's own amsi dll named, "antimalware_provider64.dll" is injected into powershell.exe but it wasn't in BD Free.
 
Last edited:

Nunzio_77

Level 2
Thread author
Dec 3, 2023
82
I don't think so unless something changed lately 🤔 It doesn't match with my own tests. Early last year, I found malwares for which BDTS's memory scanning was triggered shortly after running a malware.
I ran the same sample in BD Free and the detection occurred at a later stage by BD's behavior blocker ATC, not by memory scanning as it doesn't have it.
The scan script option in BD is AMSI. BD already has their own script emulation engine so it can scan scripts without AMSI, but AMSI was added later as an additional layer.
I verified in BD Free that it indeed does not have AMSI. It's easy to check using Process Explorer. In BDTS, BD's own amsi dll named, "antimalware_provider64.dll" is injected into powershell.exe but it wasn't in BD Free.
I requested further verification.
They will let me know.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top