This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
Parents
  • Looks like a lot of folks arent reading the entire thread, so I'll repeat this.

    If you had Cleanup set to MOVE viruses to quaratine, you will probably need more than BAT scripts that only do part of the repair job! Many other programs were broken by this such as Adobe Reader, Flash, Google, and Sprint related stuff.

    FixSAV.vbs

    I came up with my own script that parses the SAV.log file and copies ALL files back to their original locations. If you deleted them, you're sunk and would have to copy from another computer I guess.

    I also added some stuff from ktremain and KUSA's scripts to get the service restarted and almon (tray icon) running.

    Make sure you put those sophos folder exclusions in first and deploy the new policy or else this could be undone again.

    Good luck!

    :31501
Reply
  • Looks like a lot of folks arent reading the entire thread, so I'll repeat this.

    If you had Cleanup set to MOVE viruses to quaratine, you will probably need more than BAT scripts that only do part of the repair job! Many other programs were broken by this such as Adobe Reader, Flash, Google, and Sprint related stuff.

    FixSAV.vbs

    I came up with my own script that parses the SAV.log file and copies ALL files back to their original locations. If you deleted them, you're sunk and would have to copy from another computer I guess.

    I also added some stuff from ktremain and KUSA's scripts to get the service restarted and almon (tray icon) running.

    Make sure you put those sophos folder exclusions in first and deploy the new policy or else this could be undone again.

    Good luck!

    :31501
Children
No Data