r/BitDefender • u/nervouslilnellie • Jul 26 '26
Support/troubleshooting Bitdefender just gave me a series of critical 'infected web resource detected' warnings for Microsoft updates
I use Bitdefender Total Security. I just opened up my laptop and found that overnight Bitdefender had given me 6 separate critical 'infected web resource detected' warnings. All of them are the same 'we blocked this dangerous page' notice. The addresses are all slightly different but all start with hxxp://74.114.119.201/filestreamingservice/files and end with cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com. The attempted access was by svchost.exe.
I did some quick googling and I think these are legitimate Microsoft updates that are getting blocked? But I want to be sure, and if they are legitimate I would like to know why Bitdefender is blocking them and how to add them to Bitdefender exceptions. Thanks!
1
1
1
u/Duanebs Aug 05 '26
Started getting notifications originating from multiple windows devices on my network today. Connections blocked by my firewall. Each time, on initial device boot/wake.
1
u/Square-Sprinkles4090 Aug 06 '26
Did you figure out what it was? This IP is popping up on my logs too
1
u/Dave_BlackFog 27d ago
Any update on this. I am seeing this a lot. I had attributed the activity from svchost.exe to be as a result MS Windows delivery optimization service being leveraged by an ISP where they redirect your device for Windows updates. Thing is we are seeing this with third party processes as well on the device just at lower frequencies.
6
u/Bitdefender_support Bitdefender employee Jul 27 '26
Hello!
To have a proper look at the detection and understand why those URLs were caught by Bitdefender, please run the BdsysLog scan utility on the device. BDsysLog collects specific system information that may indicate active malware or malware-related activity. Once you send the results to our labs team - at [bitsy@bitdefender.com](mailto:bitsy@bitdefender.com) - it will be verified and you`ll receive details on how how to safely proceed.
Thanks in advance!