• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / Sophos Endpoint clean-up resets certain Windows security settings to default values

Sophos Endpoint clean-up resets certain Windows security settings to default values

2015-07-22 by Jason

Sophos takes an apparently divisive action when it cleans a computer from a detected threat (adware, malware, spyware, or virus). During the clean-up, Sophos implements a threat remediation effort to not only remove the detected file but also reset dozens of Windows security-related settings to their default values.

Some people think this is Sophos overstepping its role while others think it is a common sense action for security software to take. The threat remediation steps change over 80 configurations that are common malware targets including enabling UAC (User Account Control), checking Exe signatures from IE downloads, don’t hide desktop icons, allow Windows Run, enable Task Manager, and many other settings. For the full list, you can review Sophos Knowledge Base article 118583.

This remediation effort is the default behavior for Sophos to take after a clean-up. If you need to have UAC disabled or some other behavior persist, you can set those settings specifically through Group Policy or you can opt-out of this behavior by creating a Registry key.

From Sophos support, here are the steps to disable and enable threat remediation:

Disabling threat remediation

  1. Open Regedit and navigate to the following location:
    32-bit: HKLMSoftwareSophosSAVServiceApplication
    64-bit: HKLMSoftwareWOW6432NodeSophosSAVServiceApplication
  2. Create a Key at this location called: CCOverride
  3. Threat remediation is now disabled.

Enabling threat remediation

  1. Open Regedit and navigate to the following location:
    32-bit: HKLMSoftwareSophosSAVServiceApplication
    64-bit: HKLMSoftwareWOW6432NodeSophosSAVServiceApplication
  2. Delete Key at this location called: CCOverride
  3. Threat remediation is now enabled.

Filed Under: Security and Privacy, Software

Trending

  • The growth of Magento for e-commerce
    In Infographics
  • The 2011 Consumer Electronics Show – What You Need To Know and What You’ve Already Missed
    In Hardware, Gadgets, and Products, News
  • Prevent the latest exploit in Adobe Acrobat, Disable JavaScript
    In Code, Security and Privacy, Software, Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • What is the AllJoyn Router Service on Windows 10? What is the AllJoyn Router Service on Windows 10?
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • How a DirecTV bill really works in 2015 How a DirecTV bill really works in 2015
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in