This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
Parents
  • Hi,

    Although manual (can be automated by using a script as well), below ar ethe steps which i followed for damage control:

    1. Go to c:\Program Files\Sophos\Sophos Anti-Virus. Search for a file name : agen-xuv.ide and delete if found
    2. Restart the Sophos AV service by going to  services.msc from the run prompt
    3. Go to run, type c:\Program Files\Sophos\AutoUpdate\almon.exe. The Sophos agent should appear on the taskbar
    4. Right click on the Sophos shield icon from the task bar and click update
    5. Once update is done, open Sophos AV, select all items from the quarantine related to this alert and click on Clear from List
    :31097
Reply
  • Hi,

    Although manual (can be automated by using a script as well), below ar ethe steps which i followed for damage control:

    1. Go to c:\Program Files\Sophos\Sophos Anti-Virus. Search for a file name : agen-xuv.ide and delete if found
    2. Restart the Sophos AV service by going to  services.msc from the run prompt
    3. Go to run, type c:\Program Files\Sophos\AutoUpdate\almon.exe. The Sophos agent should appear on the taskbar
    4. Right click on the Sophos shield icon from the task bar and click update
    5. Once update is done, open Sophos AV, select all items from the quarantine related to this alert and click on Clear from List
    :31097
Children
No Data