View Full Version : Newest version of Sophos AV markt sb.exe as malware
[DPC]Mobster
09-22-2006, 06:10 AM
I just rebooted my system and now Sophos Anti-Virus pops up saying:
Virus Mal/Behav-044 detected in: "C:\Distributed Computing\SB\sb.exe"
My product version is 5.2.6. As a temp work-a-round I've disabled On Access Scan, but this needs to be sorted out ofcourse. I'll try and mail Sophos this afternoon
Anybody else having this problem?
tldcolli
10-03-2006, 06:48 AM
Mobster']I just rebooted my system and now Sophos Anti-Virus pops up saying:
My product version is 5.2.6. As a temp work-a-round I've disabled On Access Scan, but this needs to be sorted out ofcourse. I'll try and mail Sophos this afternoon
Anybody else having this problem?
Yes, I can't disable Sophos, so I'm going to have to (temporarily) remove SB.
Presumably this is a false-positive (hopefully!!!), so presumably SB could be slightly modified to avoid the problem. I doubt Sophos will "care" about SeventeenOrBust, so they probably won't update the virus definitions. :-(
IronBits
10-03-2006, 10:11 AM
Use AVG, (it's free http://free.grisoft.com/doc/1 ) or tell the folks that wrote your product to fix it.
It's not an sb.exe problem... ;)
tldcolli
10-03-2006, 11:11 AM
Use AVG, (it's free http://free.grisoft.com/doc/1 ) or tell the folks that wrote your product to fix it.
It's not an sb.exe problem... ;)
I don't have a choice... I'm not responsible for the anti-virus s/w!!
I have informed Sophos, but I think they'll say that the odd false-positive
is better than the odd missed virus, especially if it's only affecting some odd-ball
maths project.
umccullough
10-03-2006, 08:43 PM
I don't have a choice... I'm not responsible for the anti-virus s/w!!
I have informed Sophos, but I think they'll say that the odd false-positive
is better than the odd missed virus, especially if it's only affecting some odd-ball
maths project.
Usually most decent AV software has a place to specify exceptions. Although, I wouldn't be surprised if they've started removing this functionality to prevent possible abuse of that feature...
I dunno, I haven't been running any "always-on" AV software for years.
[DPC]Mobster
10-04-2006, 02:55 AM
Same here. It's company policy and Sophos AV is one of the best professional products around... I guess I'm just gonna finish this test and try another DC-project on this P4-2,8GHz machine...
tldcolli
10-04-2006, 04:28 AM
Usually most decent AV software has a place to specify exceptions. Although, I wouldn't be surprised if they've started removing this functionality to prevent possible abuse of that feature...
I dunno, I haven't been running any "always-on" AV software for years.
I know.... it's a PITA... :swear: I really want to get myself a new MacPro so I can do most of my stuff within OSX (virtually virus free....) I'm not sure I'll be able to swing it past my boss...
In the mean-time, I'd be quite happy to re-build or test the SB client to
try to get around this problem.
tldcolli
10-04-2006, 10:31 AM
Well, since there doesn't appear to be a solution to this, I guess I'll have
to switch to SETI or Folding....
So long, and thanks for all the fish.
Frodo42
10-04-2006, 12:44 PM
Have you tried renaming the sb.exe file?
I don't know if that solves the problem, but I remember someone talking about a virus that had been using a file named sb.exe.
It probably won't solve the problem, but at least it's worth a try.
tldcolli
10-05-2006, 06:33 AM
Have you tried renaming the sb.exe file?
I don't know if that solves the problem, but I remember someone talking about a virus that had been using a file named sb.exe.
It probably won't solve the problem, but at least it's worth a try.
No, that dosesn't help. Sophos seems to be picking up on a string for byte-sequence.
:(
tldcolli
10-06-2006, 06:30 AM
Mobster']I just rebooted my system and now Sophos Anti-Virus pops up saying:
My product version is 5.2.6. As a temp work-a-round I've disabled On Access Scan, but this needs to be sorted out ofcourse. I'll try and mail Sophos this afternoon
Anybody else having this problem?
I got an email from Sophos customer support this morning to say that the
virus definitions have been updated so that SeventeenOrBust shouldn't
be picked up as malware now.
Powered by vBulletin® Version 4.2.4 Copyright © 2025 vBulletin Solutions, Inc. All rights reserved.