This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
Parents
  • Yep just showed up on my network about 20 minutes ago...now currently showing about 70% of my computers as having virus/spyware, phone ringing off the hook with employees asking why Sophos has detected a threat and a line of people outside my door nearly the whole way down the hall.

    Same thing others are reporting...

    Shh/Updater-B  located in program files\Sophos\AutoUpdate\ALsvc.exe  at the work station and from server path ProgramData\Sophos\Update Manager\Update Manager\Warehouse\  then various hex named dat files

    in the CID\5000\SAVSCFXP\savxp\program files\sophos\sophos anti-virus\web intellgence\swi_update_64.exe

    in CIDs\5000\SAVSFXP\sau\program files\sophos\autoupdate\ALsvc.exe

    ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\ALUpdate.exe

    also the Almonres.dll file in various case varations (ALMonres, AlMonres, almonres etc).

    Whats going on?

    :29903
Reply
  • Yep just showed up on my network about 20 minutes ago...now currently showing about 70% of my computers as having virus/spyware, phone ringing off the hook with employees asking why Sophos has detected a threat and a line of people outside my door nearly the whole way down the hall.

    Same thing others are reporting...

    Shh/Updater-B  located in program files\Sophos\AutoUpdate\ALsvc.exe  at the work station and from server path ProgramData\Sophos\Update Manager\Update Manager\Warehouse\  then various hex named dat files

    in the CID\5000\SAVSCFXP\savxp\program files\sophos\sophos anti-virus\web intellgence\swi_update_64.exe

    in CIDs\5000\SAVSFXP\sau\program files\sophos\autoupdate\ALsvc.exe

    ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\ALUpdate.exe

    also the Almonres.dll file in various case varations (ALMonres, AlMonres, almonres etc).

    Whats going on?

    :29903
Children
No Data