Frank C
2006-08-27, 00:53
Hi:
I experienced the following From Norton while updating Hosts File with Spybot.
Attempted Intrusion "Goidr DNS Request" from your machine against 192.168.1.1 was detected and blocked.
Intruder: CAMP(Numeric IP adr)(nnnn).
Risk Level: Medium.
Protocol: UDP.
Attacked IP: nnn.nnn.n.n.
Attacked Port: domain(53).
I ran scans with Norton, Ad-Aware, Spy Sweeper and Spybot. I detected no errors.
I looked at the following registry key (as specified by Symantec) and found no changes
When Spyware.Goidr runs, it does the following:
1. Adds the value:
"goidr"="%Sysem%\goidr.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Goidr.exe file runs when you start Windows.
I believe this is a false positive from Norton.
I experienced the following From Norton while updating Hosts File with Spybot.
Attempted Intrusion "Goidr DNS Request" from your machine against 192.168.1.1 was detected and blocked.
Intruder: CAMP(Numeric IP adr)(nnnn).
Risk Level: Medium.
Protocol: UDP.
Attacked IP: nnn.nnn.n.n.
Attacked Port: domain(53).
I ran scans with Norton, Ad-Aware, Spy Sweeper and Spybot. I detected no errors.
I looked at the following registry key (as specified by Symantec) and found no changes
When Spyware.Goidr runs, it does the following:
1. Adds the value:
"goidr"="%Sysem%\goidr.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Goidr.exe file runs when you start Windows.
I believe this is a false positive from Norton.