This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is any one else seing this alert - Shh/Updater-B False positives

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable. This is trickling in as alerts but at an alarming rate.

:29723


This thread was automatically locked due to age.
  • @Sandy....

    "I must emphasize that we apologize for all of the disruption caused to our many customers and partners worldwide. We recognize the issue is very serious, and are doing everything we can to resolve it."

    Thanks, now who do we see about reimbursement of costs...............

    :31295
  • I would like to see a Worldwide press release from the President of this company that the person(s) responsible for this were IMMEDIATELY fired.
    :31299
  • this isn't the first time we had this of late (never this bad) but at least 3 times in the past couple of months updates have come out that have caused issues with NAC, infact there was one earlier yesterday I all of a sudden had a load of machines showing  assessment faliure AGAIN!  I still have quite a few showing it now!

    :31305
  • Simply....Incredible and Stupid

    :31311
  • What is the current binary everyone is seeing deployed?  Currently I show 1.3.2.176 which is the version I had yesterday when this mess started! 

    :31315
  • Someone said a 3 month licesne extension??? How about a frigging year!!

    Luckily only 2 files from Autoupdate was removed to quarantine, so I can just copy the contents of a working machine and paste it in and then they are able to update... but that is over 350 machines and 30 servers... 

    Man oh man.. 

    Where do I send my bill?

    :31317
  • Who wants a license extension to continue with this madness? How about paying for users to switch to something reliable. Ouch.

    :31319

  • putty wrote:

    What is the current binary everyone is seeing deployed?  Currently I show 1.3.2.176 which is the version I had yesterday when this mess started! 


    Hi Putty,

    The update is contained in an IDE, not a binary update. You are running the latest version of the Sophos Update Manager. Please be sure that you have downloaded and deployed javab-jd.ide to your endpoints. Please see the advisory for further assistance if you are having difficulty downloading the updated IDE.

    :31321

  • Nik_Nak2 wrote:

    There are many extra steps here that are not required. Please see our advisory for instructions to assist with recovery.

    :31323
  • What is sad with your step is that they don't always work.

    If you move/delete the quarantine file, your step are useless because they suppose that file like alsvc.exe, almon.exe and other are still there... those are just the sophos file, just don't get us started on other software like acrobat, java, google update that are screwed also...

    ML

    :31325