mwalpole Posted September 20, 2012 Posted September 20, 2012 We have had multiple reports of Sophos reporting false positives this morning. This was due to an update released by Sophos which caused it to identify some of its own files as infected. Sophos have since pushed out an automated update which resolves the issues. Further information is available at YHGfL Foundation SOPHOS Repository
m25man Posted September 20, 2012 Posted September 20, 2012 If you have set your Sophos AV Policy to Delete files on infection it could be a rather nasty cleanup operation... 1
mwalpole Posted September 20, 2012 Author Posted September 20, 2012 Hi m25man, We advise people to have their AV policy set to quarantine, and not to use delete, to protect from issues such as this one, as it can cause a large headache in trying to resolve this kind of problem. Hopefully most, if not all users are configured to use the quarantine option as advised by Sophos and ourselves. Please see page 11 on http://sophos.yhgfl.net/Downloads/Manuals/sesc_100_heng.pdf Regards Marc
clareq Posted September 20, 2012 Posted September 20, 2012 I have my sophos install set to quarantine -- now very few of my clients are updating, as the files required have been moved to quarantine. Sophos are now recommending the "deny access" option. 1
mwalpole Posted September 20, 2012 Author Posted September 20, 2012 Hi clareq, If you are having problems with getting Sophos updating correctly again, you can log a call to our YHGfL support team through your normal channels and our engineers will help you out. Regards Marc
mwalpole Posted September 21, 2012 Author Posted September 21, 2012 Please note the article on the Sophos Knowledge base page has been updated with more indepth information. Regards Marc
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now