zercon,
You say the message is coming from GroupShield for exchange, but this sounds just like the message that NetShield throws up, and I’ll bet it is identifying one of the files in you mail queue that is infected….. If you are running NetShield on that Exchange box, then that is where your pop-ups are coming from. Check Programs>Network Associates>Alert Manager Configuration and at the 'summary' tab you will see "Network Message" and "\\Local System". You can remove them here by highlighting "\\Local System" and clicking remove, or you can do it from the "Network" tab, same thing.