Avast WEBforum

Other => Viruses and worms => Topic started by: olafpir on December 08, 2011, 04:40:05 PM

Title: sfloppy.sys is a rootkit?
Post by: olafpir on December 08, 2011, 04:40:05 PM
From the last definition update, Avast report me an alarm telling me that sfloppy.sys is a rookit and that I need to eliminate it.
I have read this file is a Wiondws system file and is necesary to the system.
My OS is Windows Xp SP3.
Actually running Avast Free Antivirus ver. 6.0.1367
Data Base ver. 111208-0
It is a false positive alarm?
What it be supposed I must to do? :o

Thanks
Olaf
Title: Re: sfloppy.sys is a rootkit?
Post by: polonus on December 08, 2011, 04:46:01 PM
Hi olafpir,

Could be an avast glitch or FP or avast could not properly deal with that file, re: http://forum.avast.com/index.php?topic=89963.0
and also see: http://forums.majorgeeks.com/showthread.php?t=248503 (at the end of that thread)

Waiting for comments?

polonus
Title: Re: sfloppy.sys is a rootkit?
Post by: Asyn on December 08, 2011, 04:49:07 PM
1. It is a false positive alarm?
2. What it be supposed I must to do? :o


1. Most likely..!! I wonder why it is back though..!??
2. Ignore it, as it hopefully will be fixed (again!) soon.
Title: Re: sfloppy.sys is a rootkit?
Post by: DavidR on December 08, 2011, 04:49:18 PM
Are you sure (you have the latest VPS update) as this 'false positive' first occurred on the 6th December and was corrected in a VPS update that day in 111206-2.

Use the Ignore option and don't check the 'don't tell me about this again' option.
Title: Re: sfloppy.sys is a rootkit?
Post by: DavidR on December 08, 2011, 05:05:32 PM
Update, I have just run a Custom Scan on a Full Anti-Rootkit scan and no alert with VPS 111208-0. So as I said confirm that you actually have the latest update. I will try a reboot and see if the standard anti-rootkit scan returns a hit or not.
Title: Re: sfloppy.sys is a rootkit?
Post by: jsejtko on December 08, 2011, 05:09:07 PM
Hello all,

The problem with sfloppy.sys was connected only to 11120600 and 11120601 vps versions.

We are still getting some reports, but all of them are caused by the vps version I mentioned above.

Regards
J.
Title: Re: sfloppy.sys is a rootkit?
Post by: Asyn on December 08, 2011, 05:10:58 PM
Hello all,

The problem with sfloppy.sys was connected only to 11120600 and 11120601 vps versions.

We are still getting some reports, but all of them are caused by the vps version I mentioned above.

Regards
J.

Thanks for this info..!! :)
Title: Re: sfloppy.sys is a rootkit?
Post by: DavidR on December 08, 2011, 05:20:41 PM
The problem with sfloppy.sys was connected only to 11120600 and 11120601 vps versions.

We are still getting some reports, but all of them are caused by the vps version I mentioned above.

Thanks for the prompt response Jirka. That's what has thrown me with the OP reporting that he has VPS 111208-0, which I have run an anti-rootkit scan with the same VPS and no alert. I have just rebooted and the anti-rootkit should be about to kick in (8 minutes after boot). It has now completed and no alert, image1 extract of aswAr.log.

So I have to wonder about the OP 'olafpir' having a problem with the reported VPS and it actually being installed.
Title: Re: sfloppy.sys is a rootkit?
Post by: Asyn on December 08, 2011, 05:23:08 PM
So I have to wonder about the OP 'olafpir' having a problem with the reported VPS and it actually being installed.

+1
Title: Re: sfloppy.sys is a rootkit?
Post by: olafpir on December 08, 2011, 11:59:36 PM
Thanks very much to all the people that answer me ;D!

Effectively, updating (automatically) to VPS version 111208-1 (that currently is running on my PC)Avast Free did not detect the sploppy.sys file as a rookit.

Problem solved!

Thaks to all again :D!

Olaf
Title: Re: sfloppy.sys is a rootkit?
Post by: Asyn on December 09, 2011, 12:02:05 AM
Thanks very much to all the people that answer me ;D!

You're welcome.