This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos detecting new updates as threat #3453878

We are seeing several alerts for Sophos detecting the new AutoUpdates as a threat –

Following file and locations-

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\AutoUpdate\ALsvc.exe". Cleanup unavailable.

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\ALUpdate.exe". Cleanup unavailable.

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files (x86)\Sophos\AutoUpdate\inetconn.dll".

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update_64.exe".

Please advise if these needs to be actioned or are legitimate files.

Your Support Numbers are not working !

:30183


This thread was automatically locked due to age.
Parents
  • Hi all,

    To solve issue, on my Windows PCs, i've do as follow:
    - From the computer managment (comptmgmt.msc) i've remotely stopped the service Sophos Anti-Virus
      You can also use the "SC.EXE" from the Windows Ressource Kit to stop massively and remotely this service.
    - From the Sophos Console, i've pushed a new installation of the Anti-Virus.

    :31257
Reply
  • Hi all,

    To solve issue, on my Windows PCs, i've do as follow:
    - From the computer managment (comptmgmt.msc) i've remotely stopped the service Sophos Anti-Virus
      You can also use the "SC.EXE" from the Windows Ressource Kit to stop massively and remotely this service.
    - From the Sophos Console, i've pushed a new installation of the Anti-Virus.

    :31257
Children
No Data