• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / Sophos false positive quarantines itself with Shh/Updater-B detection

Sophos false positive quarantines itself with Shh/Updater-B detection

2012-09-23 by Jason

In the accelerating race against viruses and malware, a trade-off we are seeing more frequently are the false-positives. Companies like Avast, McAfee, and others have all experienced them and last week was Sophos’ turn. The company’s anti-virus software would report that “‘Virus/spyware’ Shh/Updater-B has been detected and moved to quarantine” on Windows computers.

Sophos started detecting its own auto-update mechanisms and some others like Adobe Flash. Of course, this could prevent Sophos from being able to automatically address the problem with the next definition update. If your policy was set to only quarantine items, the updater files can be restored from quarantine from the Sophos Enterprise Console. If your policy was set to delete the files, you are in a worse position and are recommended to change your policy to quarantine first.

A support forum thread was opened September 19th and has since received over 1000 replies and over 37,800 views. The company acknowledged the issue in a knowledge base article and a blog post. The blog post received 97 comments from individuals hoping to find a solution to the problem while Sophos reports receiving a high number of calls.

The knowledge base articles have been updated through the week with them receiving another update today. Sophos has provided recovery instructions for:

  • Standalone installations
  • Sophos Control Center
  • Enterprise Console

Sophos would be in a hard position to explain how this false positive made it past quality assurance. Some false positives are understandable if they occur on select operating systems or with certain legitimate software (like Avast’s false-positive with Steam). It would be impossible to test against all legitimate software out there but when it is the included updating mechanism and popular, free software like Adobe Flash, it seems like the QA step might have been skipped all together.

Best of luck if you’re trying to recover and we can hope Sophos puts more policies and procedures in place to prevent this from happening again.

Filed Under: Security and Privacy, Software

Trending

  • Intel Compute Stick, a sold out success?
    In Hardware, Gadgets, and Products
  • Product review: O2 Hurricane canless air system
    In Hardware, Gadgets, and Products, Reviews
  • White House Details International Strategy For Cyberspace
    In News, Security and Privacy

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Wal-Mart’s Low Tech Solution to a Shocking Problem Wal-Mart's Low Tech Solution to a Shocking Problem
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • What is the AllJoyn Router Service on Windows 10? What is the AllJoyn Router Service on Windows 10?
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in