This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
Parents

  • havoc64 wrote:

    havoc, try that on your SUM server first. The endpoints seem to be taking the update once it's available, but the false positive is preventing the SUM from being able to download the fixed file. Endpoints that haven't been rebooted yet and didn't have the files moved or deleted should recover on next update.

    I'm working on finding a workaround for systems that had the files deleted that doesn't require a reinstall. As soon as I have something I'll let you all know.

    Nathan,

    I tried that on our server and I got an error after I started the service that says...

    ALMon

    Error Loading External Resources (0x8007007e)


    Almon is just the system tray shield. Was the Sophos Update Manager able to download after you performed those steps?

    :30481
Reply

  • havoc64 wrote:

    havoc, try that on your SUM server first. The endpoints seem to be taking the update once it's available, but the false positive is preventing the SUM from being able to download the fixed file. Endpoints that haven't been rebooted yet and didn't have the files moved or deleted should recover on next update.

    I'm working on finding a workaround for systems that had the files deleted that doesn't require a reinstall. As soon as I have something I'll let you all know.

    Nathan,

    I tried that on our server and I got an error after I started the service that says...

    ALMon

    Error Loading External Resources (0x8007007e)


    Almon is just the system tray shield. Was the Sophos Update Manager able to download after you performed those steps?

    :30481
Children
No Data