Sophos detecting itself as SHH/Updater-B
The latest definition file for Sophos is having some unintended consequences. It is currently being discussed on their website: http://community.sophos.com/t5/Sophos-Endpoint-Protection/Is-any-one-else-seing-this-alert/td-p/29723
More to come.
Update 21:39 GMT Binary updates appear to be reaching customers now.
Keywords:
6 comment(s)
×
Diary Archives
Comments
Updated: 19 Sep 2012
"Issue: Numerous binaries are falsely detected as ssh/updater-B.
Cause: An identity released by SophosLabs for use with our Live Protection system is causing False Positives against many binaries that have updating functionality.
What To Do: Customer should ensure that endpoints are update to date with the latest IDE files. This issue is resolved with javab-jd.ide which was released at Wed, 19 Sep 2012 18:48:35 +0000.,,
.
PC.Tech
Sep 19th 2012
1 decade ago
Wreaked utter havoc.
Chavez
Sep 20th 2012
1 decade ago
Phil
Sep 20th 2012
1 decade ago
http://nakedsecurity.sophos.com/2012/09/19/sshupdater-b-fsophos-anti-virus-products/
but my message was never approved by their blog admin.
I'm hoping I can share my story here.
shh/updater-b did not only detect Sophos itself as a threat, but many other updater services as well. We have been able through our logs to pinpoint Adobe Flash, Oracle Java, Fujitsu AutoUpdater, Dell AutoUpdate Utilities, etc.
If you read what they describe in the link I provided in regards to protection levels set to move or delete infected files this is where the big problem resides. We had our Sophos install setup to move/delete infected/suspected files.
All of the auto-updaters mentioned above were deleted off hundreds of PCs. Now none of these applications will auto-update moving forward.
What makes my story unique is we are a medical facility. Our Electronic Health Records (EHR) application had a DLL used for auto-updating that application that was detected and deleted as a part of the shh/updater-b false positive fiasco. The absence of this DLL file prevented the application from opening and crashed every time you tried to load it. This created a threat to patient safety for us. Even though Sophos may have fixed the problem and fixed their own software, there is a monumental amount of work we have to do to clean up after this mess. I've worked in IT for 16 years and have NEVER had a virus/trojan/spyware/malware cause problems and disrupt our systems the way this did. Who can I trust anymore when even my security AV vendor can wreak more havoc on our systems than a virus infection outbreak can.
Brad
Sep 20th 2012
1 decade ago
Brad
Sep 20th 2012
1 decade ago
Updated: 22 Sep 2012
- http://www.sophos.com/en-us/support/knowledgebase/118323.aspx
Updated: 22 Sep 2012
- http://www.sophos.com/en-us/support/knowledgebase/118315.aspx
Updated: 22 Sep 2012
.
PC.Tech
Sep 23rd 2012
1 decade ago