Jump to content

Recommended Posts

Posted

Is any one else having issues with sophos reporting a virus on all there workstation?

 

The e-mail I'm getting is:

 

Virus/spyware 'Shh/Updater-B' has been detected in "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe". Cleanup unavailable.

 

Infected file "C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe" has been deleted.

 

I hope this is a false positive after sophos updating itself and not a major issue

  • Thanks 1
Posted

yep getting a few dozen emails through to my phone

 

Sophos have said its a false positive but the problem i see is the updater is being quaranteened meaning how will it get the updated ide?

 

Apparantley if live protection is enabled it will fix itself. Hopefully the IDE will be updated before all of our pc's come on tomorrow!

Posted

I've just logged on remotely and killed the Sophos updater share for now. All our clients (well... 95% of them) are off anyway at the moment so they won't get a chance to pick up the fraked up IDE's.

 

I've got 52 machines tho (including servers) reporting it tho. All it's done is "blocked" them for now.

Posted
I was going to kill the share but its required to get the updated fix IDE?

 

Aye, I did it until the fix was out. I might just leave it dead until the morning, when sophos have a proper fix out (rather than a rushed one :p)

Posted

Just checked my work e-mail and I have 615 unread all from sophos with the last one received at 5:55 reporting a virus on the computer that hosts the sophos enterprise console

 

So I assume I'm going to have a busy day!

Posted

+1 same here

 

Virus/spyware 'Shh/Updater-B' has been detected in "C:\ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\ALUpdate.exe". Cleanup unavailable.

 

Virus/spyware 'Shh/Updater-B' has been detected in "C:\ProgramData\Sophos\AutoUpdate\cache\sophos_autoupdate1.dir\alupdate.exe".

 

Virus/spyware 'Shh/Updater-B' has been detected in "C:\ProgramData\Sophos\AutoUpdate\cache\sophos_autoupdate1.dir\alupdate.exe".

 

I could almost let Sophos off for accidentally picking up other system updates as potential but to let the software decide that their own program is virus is just plain inept. Having said that given the amount of grief Sophos has caused us over the last couple of years maybe it's right to classify itself as a virus!

Posted (edited)

I've got to say this is the first time I've had Sophos cause me a headache since 2006. The fix looks easy enough, even for those of us mad enough to have 'delete' as the default action.(*)

 

Maybe. We'll see how it goes.

 

 

(*)Turns out I'm not that mad after all. Its always nice to discover you haven't made a terrible mistake!

Edited by psydii
Posted

Yeah we got this too. Whoopdidoo.

 

A helpful chappy from the Sophos forums contributes thus:

 

Believe it or not, every last AV provider has had this screw up and some of them have been considerably worse than this. If a false positive has you in such a twist maybe you should stay clear of antivirus as a whole.

 

What a charming lad who definitely wouldn't benefit from a punch.

  • Thanks 1
Posted
Come in this morning to find out its put it self in the bin.... Im leaving it there....

 

[ATTACH=CONFIG]15240[/ATTACH]

 

[ATTACH=CONFIG]15241[/ATTACH]

 

I think I have you beaten.

Posted
Arguably that is only a mis-catagorisation. Sophos has detected RM Community connect as malware. It should be 'Potentially Unwanted Application'.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...