This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
  • Why am I still getting notifications of new "cleanups" hours after repairing the SUM?

    :30881
  • Nathan we have been dumped from the phone line numerous times at this point. Will our computers be safe if we call back tomorrow to get this resolved?

    :30883
  • Nathan, is there an uninstall tool available from Sophos to remove the AutoUpdater software?  The normal uninstaller is not working due to files being deleted earlier (I had it set to delete files it couldn't clean), and I can't seem to reinstall with the existing install in the current state.  I'd like to get a clean slate free of Sophos on these machines so I can reinstall from scratch on them.  Thanks for any help or tools you can offer.

    :30885
  • I'm seeing the same issue with my SUM(s) - I've even gone in and deleted the offending .ide file and followed the instructions to the T.  Is there a way to forcibly refresh the SUM(s) by removing them or what?  This is getting ridiculous.

    :30887
  • Still calling in - still getting dropped.

    #%R*)!&#*$&!*#$)%&!#*$)^&%!#)*$^& SOPHOS

    :30889
  • I seem to be having issues running the vb. Does not seem to do anything. I am not a script writer but really need to get all these machines updated.

    I still believe that Sophos should be actively trying to make a fixit executable. This is too big of a screw up to not.

    :30891

  • ITGal1967 wrote:

    Nathan, I am sorry to say that I selected the callback option 3 hours ago. I heard that I would get a call back in 30 minutes. Nothing - just sayin' you know that is supposed to work but apparently it is not, you may want to re-evaluate that advice. 

    This thread was the most helpful with you being the star. Not only are you helpful but you do not try to blow smoke up our skirts; you tell the truth. Thank you. 


    Thanks for letting me know, I'll look in to that for you.

    I amend my previous advice and suggest that if you need to speak with someone in support because the advice in this thread and in the KBA did not resolve your situation, please leave a call back and then continue trying to call support. We are experiencing a few issues with the phone queues dropping calls due to the volume, so please accept my deepest apologies.

    :30893

  • fdtech wrote:

    Nathan,

    I have an SEC console that refuses to update the update manager. Continual error message of  "Software Update Failed". Have restarted server and all services multiple times but am unable to connect to download updated IDEs.  Any thoughts?

    Thank you.


    If you haven't already, please take a look at

    http://www.sophos.com/en-us/support/knowledgebase/118311.aspx.

    :30895

  • kturner wrote:

    Nathan, is there an uninstall tool available from Sophos to remove the AutoUpdater software?  The normal uninstaller is not working due to files being deleted earlier (I had it set to delete files it couldn't clean), and I can't seem to reinstall with the existing install in the current state.  I'd like to get a clean slate free of Sophos on these machines so I can reinstall from scratch on them.  Thanks for any help or tools you can offer.


    I had one machine that had that issue.  Use Revo http://download.cnet.com/Revo-Uninstaller/3000-2096_4-10687648.html?tag=mncol;1  You'll get an error thrown at you, don't cancel.  Continue through the process and delete all the registry files that Revo lists in BOLD and continue to the end.  Reboot and then reinstall the client from the console.  Good luck.

    :30897
  • How can I cleanup the Quarantined items that our 2000+ computers have decided to block and even though I have done all the fixes etc. Then acknowledging the blocks through SEC it still seems like they are stuck on the device side.. As well when I go to the Update manager and click update now I get " Threat detection data update failed. "

    HELP!!!

    :30899