This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
Parents
  • @akurk I have just gone through this process on a network of 20 and I can verify that the applications flagged in Quarantine do still in fact work here in my scenerio. I have done a few random checks on systems and my tests show Flash Player, Java and QuickBooks updater are sitting in Quarantine but all of those applications appear to be functioning fine after I have the FP corrected.

    Keep in mind my Cleanup options are set to the defaul to "Deny access only". I did have one user who did a Cleanup in Quarantine himself and ended up deleting the items. This happened to be Sophos files and I did have to "re-protect" that system from SCC.

    I am still working on cleaning out the Quarantine issue however... Our server has 218 items in Quarintine at the moment... I have been researching this for about 15 minutes and the only option I see is to deal with it locally - not so bad for me with 20 systems - but I feel sorry for you larger networks out there.

    :31009
Reply
  • @akurk I have just gone through this process on a network of 20 and I can verify that the applications flagged in Quarantine do still in fact work here in my scenerio. I have done a few random checks on systems and my tests show Flash Player, Java and QuickBooks updater are sitting in Quarantine but all of those applications appear to be functioning fine after I have the FP corrected.

    Keep in mind my Cleanup options are set to the defaul to "Deny access only". I did have one user who did a Cleanup in Quarantine himself and ended up deleting the items. This happened to be Sophos files and I did have to "re-protect" that system from SCC.

    I am still working on cleaning out the Quarantine issue however... Our server has 218 items in Quarintine at the moment... I have been researching this for about 15 minutes and the only option I see is to deal with it locally - not so bad for me with 20 systems - but I feel sorry for you larger networks out there.

    :31009
Children
No Data