Author Topic: PortIo.sys suspicious?  (Read 2723 times)

0 Members and 1 Guest are viewing this topic.

atryeu

  • Guest
PortIo.sys suspicious?
« on: April 17, 2013, 01:06:15 AM »
Avast popped up an alert for "PortIo.sys" located in the system32/drivers folder today. It came up with 2 different alerts... one for a folder in Avast, and the other for the explorer.exe file for Windows.  Avast moved the file to the Chest and it's coming up clean but it won't let me restore the file.

I can't find any information about the file online though, and it isn't infected. I never had any problems before. The only thing I can think of is that I had just updated a few Windows updates for XP. The error didn't come up until after I had restarted the computer.

Does anybody know what that file is and why Avast won't let me restore it since it's clean?  I have not had any problems on my computer. Everything has been running normally.

Edited to add I included a screenshot of 1 of the alerts that came up. The other one had an Avast folder under the Process instead.
« Last Edit: April 17, 2013, 01:27:21 AM by atryeu »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: PortIo.sys suspicious?
« Reply #1 on: April 17, 2013, 02:13:50 AM »
What is Portio.sys
http://www.runscanner.net/lib/PortIO.sys.html

ThreatExpert's awareness of the file "portio.sys":
http://www.threatexpert.com/files/portio.sys.html


atryeu

  • Guest
Re: PortIo.sys suspicious?
« Reply #2 on: April 17, 2013, 02:24:16 AM »
Thanks...  so it's a Windows driver from MS.  Why is Avast suddenly saying it's a suspicious file and how do I get it removed from the Chest for good? I tried awhile ago and I got the alert right off again saying Avast found the suspicious file and was moving it to the Chest.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: PortIo.sys suspicious?
« Reply #3 on: April 17, 2013, 03:02:06 AM »
right click the file in chest and upload to avast lab as possible false positive
you may add a link to this topic in case they reply
it will then be sendt at next avast auto/manual update
wait a day or two, right click the file in chest and rescan.....is it still detected?


atryeu

  • Guest
Re: PortIo.sys suspicious?
« Reply #4 on: April 17, 2013, 03:18:22 AM »
Thank you. I hope I did it right. I don't know the file details such as the actual name and version number.

It sounds like it could take a few days before it could be fixed. In the meantime, what if the file being in the Chest starts causing problems? It sounded like it helps certain programs and files open and run correctly.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: PortIo.sys suspicious?
« Reply #5 on: April 17, 2013, 03:26:51 AM »
Quote
what if the file being in the Chest starts causing problems?
what do you mean?


atryeu

  • Guest
Re: PortIo.sys suspicious?
« Reply #6 on: April 17, 2013, 03:33:47 AM »
I mean with Windows itself.... it's a driver for something. What little info I did find said the file is required for certain programs and files to run correctly, but it didn't say which ones. Being tucked away in the Virus Chest, it seems like it will cause problems with whatever programs/files it's attached to. I can't get it moved out of the Chest back into it's correct place. It keeps popping up an alert and putting it right back in the Chest :(

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: PortIo.sys suspicious?
« Reply #7 on: April 17, 2013, 03:37:07 AM »
you have to wait until the FP is fixed before you can restore it..... if it is a FP


atryeu

  • Guest
Re: PortIo.sys suspicious?
« Reply #8 on: April 17, 2013, 03:45:29 AM »
Thanks :( Hopefully it won't cause problems not having it available then.... I'm very certain it is a false positive..... I run regular scans and it would have picked it up before now if it was something serious (my last scan was 2 days ago).