Question

Tacoman

Young grasshopper
Joined
Oct 5, 2015
Messages
83
Reaction score
16
I have been getting a warning messages from MalwareBytes. I attached one but erased the IP address and the Port. The port it is trying is correct, the IP address is never the same. It references Blue Iris specifically. Can anyone tell me what is going on? MalwareBytes is apparently doing it job. Should I be concerned?
InkedCapture.jpg
 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
25,041
Reaction score
48,819
Location
USA
It is not a problem.

It is how the "unknown Publisher" or "potential virus" or "compromised" messages are generated (just called virus moving forward in the rest of this post for simplicity).

It is not a virus, rather it is whatever antivirus you are using has flagged it as a potential virus. Some programs look at the total number of users and below a certain number, it is flagged. These specialty type files/programs get false positives all the time.

You can check the file with VirusTotal , an antivirus website owned by Google that runs it thru a lot of different antivirus algorithms.

But you should exclude BI from these programs or it will cause problems.
 

Tacoman

Young grasshopper
Joined
Oct 5, 2015
Messages
83
Reaction score
16
Thanks I will check VirusTotal. Why should I exclude BI? What kind of problem could it cause if I just leave everything the way it is? Everything works fine.
 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
25,041
Reaction score
48,819
Location
USA
You may think it is not having a problem (maybe it is or maybe it isn't), but it can impact the CPU% or recording or any other item.

Or one day it may just quarantine the whole program and you lose whatever happened from the quarantine until you free it.

From the help file:

Antivirus. These monitor files or folders for changes, looking for threats. These may
interfere by locking files which Blue Iris is actively modifying or attempting to delete. For
smooth and efficient software operation, you should exempt the database and clips storage
folders. Blue Iris never creates or uses executable code in these folders.

Application and process scanning. These monitor actively running software and every byte of
information sent or received for suspicious activity. These are by-far the most intrusive and
can greatly affect software performance. For proper efficient software operation it is highly
recommended that you exempt the BlueIris.exe executable as well as the supporting file
BlueIrisAdmin.exe from this type of scanning.

In the past, this type of “security” software has
been responsible for otherwise unexplained memory leaks and broken camera streams.
These software like to “cache” network communication, and in the case of a camera video
stream, this can be gigabytes of information each day, often overwhelming memory or disc
resources with endless “temp” files.

BlueIris.exe should be added as a Process exclusion, while the C:\BlueIris folder should be
excluded as a Folder.

Here’s what the exemption should look like in Malwarebytes:

1680743072539.png
 

Flintstone61

Known around here
Joined
Feb 4, 2020
Messages
6,636
Reaction score
10,964
Location
Minnesota USA
Check your BI logs in the Status icon
if the IP's match the malware bytes, it's port sniffers, maybe cuz your not on a VPN. or Zero tier.
1680762466075.png
 
Top