• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / Sophos false positive quarantines itself with Shh/Updater-B detection

Sophos false positive quarantines itself with Shh/Updater-B detection

2012-09-23 by Jason

In the accelerating race against viruses and malware, a trade-off we are seeing more frequently are the false-positives. Companies like Avast, McAfee, and others have all experienced them and last week was Sophos’ turn. The company’s anti-virus software would report that “‘Virus/spyware’ Shh/Updater-B has been detected and moved to quarantine” on Windows computers.

Sophos started detecting its own auto-update mechanisms and some others like Adobe Flash. Of course, this could prevent Sophos from being able to automatically address the problem with the next definition update. If your policy was set to only quarantine items, the updater files can be restored from quarantine from the Sophos Enterprise Console. If your policy was set to delete the files, you are in a worse position and are recommended to change your policy to quarantine first.

A support forum thread was opened September 19th and has since received over 1000 replies and over 37,800 views. The company acknowledged the issue in a knowledge base article and a blog post. The blog post received 97 comments from individuals hoping to find a solution to the problem while Sophos reports receiving a high number of calls.

The knowledge base articles have been updated through the week with them receiving another update today. Sophos has provided recovery instructions for:

  • Standalone installations
  • Sophos Control Center
  • Enterprise Console

Sophos would be in a hard position to explain how this false positive made it past quality assurance. Some false positives are understandable if they occur on select operating systems or with certain legitimate software (like Avast’s false-positive with Steam). It would be impossible to test against all legitimate software out there but when it is the included updating mechanism and popular, free software like Adobe Flash, it seems like the QA step might have been skipped all together.

Best of luck if you’re trying to recover and we can hope Sophos puts more policies and procedures in place to prevent this from happening again.

Filed Under: Security and Privacy, Software

Trending

  • Cyberbullying and Teenagers – Protect Kids Using Mobile Phone Parental Control
    In Security and Privacy
  • A Basic, Non-technical Understanding of Computer Security Issues
    In Media, Security and Privacy
  • Samsung reveals their Galaxy S5 Android smartphone and three new Gear
    In Hardware, Gadgets, and Products

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • Configure Outlook to recurring appointments for the last weekday of the month Configure Outlook to recurring appointments for the last weekday of the month
  • Creating and editing views in phpMyAdmin Creating and editing views in phpMyAdmin
  • 3d rendering circuit cloud for cloud computing technology Build and Deploy a Modern Web 3.0 Blockchain App in 2022
  • Telecom Application Development: When to Outsource Telecom Application Development: When to Outsource
  • Printer printing document wirelessly from mobile phone or smartphone wifi connection vector flat cartoon illustration, file air print on fax or ink jet via cellphone bluetooth modern design Why Your Business Needs Online Fax Services In 2022
  • 6 Best Ways to Protect Your Business Account 6 Best Ways to Protect Your Business Account
  • How to download videos from Instagram How to download videos from Instagram
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • Build and Deploy a Modern Web 3.0 Blockchain App in 2022
  • Telecom Application Development: When to Outsource
  • Why Your Business Needs Online Fax Services In 2022

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2022 · Magazine Pro Theme on Genesis Framework · WordPress · Log in