This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
Parents
  • Hello Nicklzk99,

    acknowledging an alert in the console does nothing on the client side

    of course one can question the current behaviour. Changing it the way you suggest would be a significant modification. Right now there's Cleanup (which you know has an effect on the client) and Acknowledge (which just clears an alert from display). Now successful action either from the console or on the client will clear the alert anyway. Apart from the risk that Acknowledge would clear information from QM which is still needed on the client (of course it can be found or recreated but ...) adding a "routine" feature for exceptional situations is not best practice. Just my opinion though.

    So why not create a cleanup definition for Shh/Updater-B that automatically fixes this mess

    Guess this would require changes to the engine and couldn't be rolled out in an IDE unless the required underlying operations were already implemented.

    Christian

    :32141
Reply
  • Hello Nicklzk99,

    acknowledging an alert in the console does nothing on the client side

    of course one can question the current behaviour. Changing it the way you suggest would be a significant modification. Right now there's Cleanup (which you know has an effect on the client) and Acknowledge (which just clears an alert from display). Now successful action either from the console or on the client will clear the alert anyway. Apart from the risk that Acknowledge would clear information from QM which is still needed on the client (of course it can be found or recreated but ...) adding a "routine" feature for exceptional situations is not best practice. Just my opinion though.

    So why not create a cleanup definition for Shh/Updater-B that automatically fixes this mess

    Guess this would require changes to the engine and couldn't be rolled out in an IDE unless the required underlying operations were already implemented.

    Christian

    :32141
Children
No Data