Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Open DNS updater false positive Backdoor.IRC.Bot

Created: 06 Sep 2010 | 2 comments
Lamont_Sanford's picture
0 0 Votes
Login to vote

All of a sudden I'm getting a notification that OpenDNS updater is a threat.  Is this a know issue?  See attached jpeg

Comments

dave_c's picture
07
Sep
2010
0 Votes 0
Login to vote

I just started having the

I just started having the exact same issue.  Same messages.  I contacted OpenDNS and they said it wasn't their issue but wanted me to uninstall the updater and reinstall using a newer version.  I uninstalled and rebooted the server.  The file was copied back again and SEP deleted it with the same message.  No matter what I do to delete the file it keeps coming back.  I ran a full system scan using SEP and found nothing.  I have tried a couple of maleware detectors but found nothing.  Symantec says that SEP will take care of Backdoor.IRC.bot but it is only doing a partial job.  I have not reinstalled the OpenDNS updater at this time.  Sorry, no solution just confirmation of the problem.

dave_c's picture
13
Sep
2010
0 Votes 0
Login to vote

Lamont, I don't know if you

Lamont, I don't know if you found a solution but here is what I think / did:  You are correct that the OpenDNS Updater is discovered as a false positive by SEP.  I don't believe there is a actual problem.  I received no help from Symantec on this issue.

Here is the response from OpenDNS:

Hello,

Our current Updater does not install to Temp, nor does our old Windows 2003 one.

We recommended that you delete the reported file and downloaded the newest version of Marc's Updater (because you have Server 2003); http://updater.marc-hoersken.de/ .

-Tyler.
OpenDNS Support
 

In order to uninstall OpenDNS Updater you will need to first stop the running service as their uninstaller will not do that.  Once the service is stopped you can uninstall the program and delete any remaining files.

Download, install and configure Marc's Updater from the link above.

After I did this I had no more issues with SEP on this server.  The new updater seems to work fine.

I hope this helps.  Dave