PDA

View Full Version : Newest version of Sophos AV markt sb.exe as malware



[DPC]Mobster
09-22-2006, 06:10 AM
I just rebooted my system and now Sophos Anti-Virus pops up saying:

Virus Mal/Behav-044 detected in: "C:\Distributed Computing\SB\sb.exe"
My product version is 5.2.6. As a temp work-a-round I've disabled On Access Scan, but this needs to be sorted out ofcourse. I'll try and mail Sophos this afternoon

Anybody else having this problem?

tldcolli
10-03-2006, 06:48 AM
Mobster']I just rebooted my system and now Sophos Anti-Virus pops up saying:

My product version is 5.2.6. As a temp work-a-round I've disabled On Access Scan, but this needs to be sorted out ofcourse. I'll try and mail Sophos this afternoon

Anybody else having this problem?

Yes, I can't disable Sophos, so I'm going to have to (temporarily) remove SB.

Presumably this is a false-positive (hopefully!!!), so presumably SB could be slightly modified to avoid the problem. I doubt Sophos will "care" about SeventeenOrBust, so they probably won't update the virus definitions. :-(

IronBits
10-03-2006, 10:11 AM
Use AVG, (it's free http://free.grisoft.com/doc/1 ) or tell the folks that wrote your product to fix it.
It's not an sb.exe problem... ;)

tldcolli
10-03-2006, 11:11 AM
Use AVG, (it's free http://free.grisoft.com/doc/1 ) or tell the folks that wrote your product to fix it.
It's not an sb.exe problem... ;)
I don't have a choice... I'm not responsible for the anti-virus s/w!!
I have informed Sophos, but I think they'll say that the odd false-positive
is better than the odd missed virus, especially if it's only affecting some odd-ball
maths project.

umccullough
10-03-2006, 08:43 PM
I don't have a choice... I'm not responsible for the anti-virus s/w!!
I have informed Sophos, but I think they'll say that the odd false-positive
is better than the odd missed virus, especially if it's only affecting some odd-ball
maths project.

Usually most decent AV software has a place to specify exceptions. Although, I wouldn't be surprised if they've started removing this functionality to prevent possible abuse of that feature...

I dunno, I haven't been running any "always-on" AV software for years.

[DPC]Mobster
10-04-2006, 02:55 AM
Same here. It's company policy and Sophos AV is one of the best professional products around... I guess I'm just gonna finish this test and try another DC-project on this P4-2,8GHz machine...

tldcolli
10-04-2006, 04:28 AM
Usually most decent AV software has a place to specify exceptions. Although, I wouldn't be surprised if they've started removing this functionality to prevent possible abuse of that feature...

I dunno, I haven't been running any "always-on" AV software for years.

I know.... it's a PITA... :swear: I really want to get myself a new MacPro so I can do most of my stuff within OSX (virtually virus free....) I'm not sure I'll be able to swing it past my boss...

In the mean-time, I'd be quite happy to re-build or test the SB client to
try to get around this problem.

tldcolli
10-04-2006, 10:31 AM
Well, since there doesn't appear to be a solution to this, I guess I'll have
to switch to SETI or Folding....

So long, and thanks for all the fish.

Frodo42
10-04-2006, 12:44 PM
Have you tried renaming the sb.exe file?
I don't know if that solves the problem, but I remember someone talking about a virus that had been using a file named sb.exe.
It probably won't solve the problem, but at least it's worth a try.

tldcolli
10-05-2006, 06:33 AM
Have you tried renaming the sb.exe file?
I don't know if that solves the problem, but I remember someone talking about a virus that had been using a file named sb.exe.
It probably won't solve the problem, but at least it's worth a try.
No, that dosesn't help. Sophos seems to be picking up on a string for byte-sequence.
:(

tldcolli
10-06-2006, 06:30 AM
Mobster']I just rebooted my system and now Sophos Anti-Virus pops up saying:

My product version is 5.2.6. As a temp work-a-round I've disabled On Access Scan, but this needs to be sorted out ofcourse. I'll try and mail Sophos this afternoon

Anybody else having this problem?

I got an email from Sophos customer support this morning to say that the
virus definitions have been updated so that SeventeenOrBust shouldn't
be picked up as malware now.