Author Topic: sfloppy.sys is a rootkit?  (Read 5153 times)

0 Members and 1 Guest are viewing this topic.

olafpir

  • Guest
sfloppy.sys is a rootkit?
« on: December 08, 2011, 04:40:05 PM »
From the last definition update, Avast report me an alarm telling me that sfloppy.sys is a rookit and that I need to eliminate it.
I have read this file is a Wiondws system file and is necesary to the system.
My OS is Windows Xp SP3.
Actually running Avast Free Antivirus ver. 6.0.1367
Data Base ver. 111208-0
It is a false positive alarm?
What it be supposed I must to do? :o

Thanks
Olaf

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: sfloppy.sys is a rootkit?
« Reply #1 on: December 08, 2011, 04:46:01 PM »
Hi olafpir,

Could be an avast glitch or FP or avast could not properly deal with that file, re: http://forum.avast.com/index.php?topic=89963.0
and also see: http://forums.majorgeeks.com/showthread.php?t=248503 (at the end of that thread)

Waiting for comments?

polonus
« Last Edit: December 08, 2011, 04:49:18 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sfloppy.sys is a rootkit?
« Reply #2 on: December 08, 2011, 04:49:07 PM »
1. It is a false positive alarm?
2. What it be supposed I must to do? :o


1. Most likely..!! I wonder why it is back though..!??
2. Ignore it, as it hopefully will be fixed (again!) soon.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89182
  • No support PMs thanks
Re: sfloppy.sys is a rootkit?
« Reply #3 on: December 08, 2011, 04:49:18 PM »
Are you sure (you have the latest VPS update) as this 'false positive' first occurred on the 6th December and was corrected in a VPS update that day in 111206-2.

Use the Ignore option and don't check the 'don't tell me about this again' option.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89182
  • No support PMs thanks
Re: sfloppy.sys is a rootkit?
« Reply #4 on: December 08, 2011, 05:05:32 PM »
Update, I have just run a Custom Scan on a Full Anti-Rootkit scan and no alert with VPS 111208-0. So as I said confirm that you actually have the latest update. I will try a reboot and see if the standard anti-rootkit scan returns a hit or not.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: sfloppy.sys is a rootkit?
« Reply #5 on: December 08, 2011, 05:09:07 PM »
Hello all,

The problem with sfloppy.sys was connected only to 11120600 and 11120601 vps versions.

We are still getting some reports, but all of them are caused by the vps version I mentioned above.

Regards
J.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sfloppy.sys is a rootkit?
« Reply #6 on: December 08, 2011, 05:10:58 PM »
Hello all,

The problem with sfloppy.sys was connected only to 11120600 and 11120601 vps versions.

We are still getting some reports, but all of them are caused by the vps version I mentioned above.

Regards
J.

Thanks for this info..!! :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89182
  • No support PMs thanks
Re: sfloppy.sys is a rootkit?
« Reply #7 on: December 08, 2011, 05:20:41 PM »
The problem with sfloppy.sys was connected only to 11120600 and 11120601 vps versions.

We are still getting some reports, but all of them are caused by the vps version I mentioned above.

Thanks for the prompt response Jirka. That's what has thrown me with the OP reporting that he has VPS 111208-0, which I have run an anti-rootkit scan with the same VPS and no alert. I have just rebooted and the anti-rootkit should be about to kick in (8 minutes after boot). It has now completed and no alert, image1 extract of aswAr.log.

So I have to wonder about the OP 'olafpir' having a problem with the reported VPS and it actually being installed.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sfloppy.sys is a rootkit?
« Reply #8 on: December 08, 2011, 05:23:08 PM »
So I have to wonder about the OP 'olafpir' having a problem with the reported VPS and it actually being installed.

+1
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

olafpir

  • Guest
Re: sfloppy.sys is a rootkit?
« Reply #9 on: December 08, 2011, 11:59:36 PM »
Thanks very much to all the people that answer me ;D!

Effectively, updating (automatically) to VPS version 111208-1 (that currently is running on my PC)Avast Free did not detect the sploppy.sys file as a rookit.

Problem solved!

Thaks to all again :D!

Olaf

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sfloppy.sys is a rootkit?
« Reply #10 on: December 09, 2011, 12:02:05 AM »
Thanks very much to all the people that answer me ;D!

You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0