Open DNS updater false positive Backdoor.IRC.Bot
Created: 06 Sep 2010 | 2 comments
All of a sudden I'm getting a notification that OpenDNS updater is a threat. Is this a know issue? See attached jpeg
discussion Filed Under:
All of a sudden I'm getting a notification that OpenDNS updater is a threat. Is this a know issue? See attached jpeg
Comments
I just started having the
I just started having the exact same issue. Same messages. I contacted OpenDNS and they said it wasn't their issue but wanted me to uninstall the updater and reinstall using a newer version. I uninstalled and rebooted the server. The file was copied back again and SEP deleted it with the same message. No matter what I do to delete the file it keeps coming back. I ran a full system scan using SEP and found nothing. I have tried a couple of maleware detectors but found nothing. Symantec says that SEP will take care of Backdoor.IRC.bot but it is only doing a partial job. I have not reinstalled the OpenDNS updater at this time. Sorry, no solution just confirmation of the problem.
Lamont, I don't know if you
Lamont, I don't know if you found a solution but here is what I think / did: You are correct that the OpenDNS Updater is discovered as a false positive by SEP. I don't believe there is a actual problem. I received no help from Symantec on this issue.
Here is the response from OpenDNS:
Hello,
Our current Updater does not install to Temp, nor does our old Windows 2003 one.
We recommended that you delete the reported file and downloaded the newest version of Marc's Updater (because you have Server 2003); http://updater.marc-hoersken.de/ .
-Tyler.
OpenDNS Support
In order to uninstall OpenDNS Updater you will need to first stop the running service as their uninstaller will not do that. Once the service is stopped you can uninstall the program and delete any remaining files.
Download, install and configure Marc's Updater from the link above.
After I did this I had no more issues with SEP on this server. The new updater seems to work fine.
I hope this helps. Dave
Would you like to reply?
Login or Register to post your comment.