Author Topic: sf.bin  (Read 59015 times)

0 Members and 1 Guest are viewing this topic.

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: sf.bin
« Reply #15 on: April 26, 2010, 11:25:14 PM »
PLEASE it is the file that have the cache info for files not related to services or anything else"avast related"
ask igor or vlk or just run a scan and see how it will pop up an alert
http://blog.avast.com/2010/04/25/how-to-make-the-full-system-scan-6x-faster-in-10-days/
Dreams don't die, they just fall asleep.

Unfolding

  • Guest
Re: sf.bin
« Reply #16 on: April 27, 2010, 12:08:24 AM »
I'm sorry to say that I actually switched product for this reason. I have posted this as a support ticket as well without any response in the same time.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: sf.bin
« Reply #17 on: April 27, 2010, 12:13:40 AM »
Well, I don't see what we can do about it.
Sf.bin is part of avast! antivirus engine... and it's executed e.g. when a suspicious file is detected (to perform some emulation).

If Outpost, or any other products, are unable to obey the rules you set for them... that certainly should be fixed by their makers. I guess it might be slightly tricky to set such a rule (the folder of the virus database keeps changing, and the file itself changes as well) - but still, there's nothing to do on our side.

Unfolding

  • Guest
Re: sf.bin
« Reply #18 on: April 27, 2010, 11:48:18 AM »
I posted a query if this was expected behaviour - that Sf.bin wants access to Internet - and now finally I had a reply. Thanks.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: sf.bin
« Reply #19 on: April 27, 2010, 12:41:47 PM »
Well, what I'm saying is that executing Sf.bin is normal, the content of Sf.bin changing often (thus making it harder to create a rule for a 3rd party HIPS) is also normal.
Sf.bin connecting to Internet... is not, as far as I know.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sf.bin
« Reply #20 on: April 27, 2010, 12:52:56 PM »
Sf.bin connecting to Internet... is not, as far as I know.

No connection attempts to the net here at all... Only the HIPS part of comodo (D+) pops up sometimes, but not for asking to allow, just telling it's doing something, as it's set to verbose here.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Unfolding

  • Guest
Re: sf.bin
« Reply #21 on: April 27, 2010, 01:19:10 PM »
Igor, ZA notified me that Sf.bin wanted access to Internet and I blocked it at that time. Is there any reasonable explanation to that?


 

spg SCOTT

  • Guest
Re: sf.bin
« Reply #22 on: April 27, 2010, 05:03:14 PM »
At a guess (I don't really know anything about this though), could it be the webshield using the code emulation?
That would cause a connection would it not?


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sf.bin
« Reply #23 on: April 28, 2010, 01:42:29 AM »
At a guess (I don't really know anything about this though), could it be the webshield using the code emulation? That would cause a connection would it not?

The webshield connects via AvastSvc.exe not Sf.bin
If Sf.bin would connect (or even try to connect) I would have an entry in the firewall log.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Tsimmes

  • Guest
Re: sf.bin
« Reply #24 on: April 29, 2010, 10:38:22 PM »
Well, I don't see what we can do about it.
Sf.bin is part of avast! antivirus engine... and it's executed e.g. when a suspicious file is detected (to perform some emulation).

If Outpost, or any other products, are unable to obey the rules you set for them... that certainly should be fixed by their makers. I guess it might be slightly tricky to set such a rule (the folder of the virus database keeps changing, and the file itself changes as well) - but still, there's nothing to do on our side.

I have in fact given permission for sf.bin to run, both in Outpost Application Rules and Host Protection but because, as you point out, the folder and file keep changing the rules won't stick. So how on earth can this be fixed by Outpost. This problem started with v5.0.507.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: sf.bin
« Reply #25 on: April 29, 2010, 11:06:29 PM »
Igor, ZA notified me that Sf.bin wanted access to Internet and I blocked it at that time. Is there any reasonable explanation to that?

No, not really. Maybe some other program has installed system-wide hooks and is injecting itself into every created process? (just a wild guess)

This problem started with v5.0.507.

That's not possible... the Sf.bin executable, as well as other modules responsible for launching it, are fully contained in the "virus database & engine" and are completely independent of the program version. You may have an old version of the program, yet a brand new virus database - and it will behave exactly the same as with a new program build.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: sf.bin
« Reply #26 on: April 29, 2010, 11:29:51 PM »
Well, I don't see what we can do about it.
Sf.bin is part of avast! antivirus engine... and it's executed e.g. when a suspicious file is detected (to perform some emulation).

If Outpost, or any other products, are unable to obey the rules you set for them... that certainly should be fixed by their makers. I guess it might be slightly tricky to set such a rule (the folder of the virus database keeps changing, and the file itself changes as well) - but still, there's nothing to do on our side.

I have in fact given permission for sf.bin to run, both in Outpost Application Rules and Host Protection but because, as you point out, the folder and file keep changing the rules won't stick. So how on earth can this be fixed by Outpost. This problem started with v5.0.507.

Strange as I have Outpost Firewall Pro 2009 ver. 6.7.2 (3001.452.0718) and I have not had a single Outpost pop-up relating to sf.bin and it isn't in my Application Rules section of Outpost Firewall Pro.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

ktk8

  • Guest
Re: sf.bin
« Reply #27 on: July 25, 2010, 01:39:12 PM »
I'm still having problems with sf.bin popups - I'm using Sunbelt Personal Firewall. Any ideas on how to stop this? Much appreciated!

rdmaloyjr

  • Guest
Re: sf.bin
« Reply #28 on: July 25, 2010, 02:39:49 PM »
Well, what I'm saying is that executing Sf.bin is normal, the content of Sf.bin changing often (thus making it harder to create a rule for a 3rd party HIPS) is also normal.
Sf.bin connecting to Internet... is not, as far as I know.

I have the latest version of ZA Pro and I never get pop ups wanting to allow Sf.bin.  This obviously due to the auto configuration at set up 0f ZA Pro (I guess Check Point is aware of the issue) .

Quote
the content of Sf.bin changing often

This explains why I get multiple entries of Sf.bin in ZA Pro ???
« Last Edit: July 25, 2010, 02:56:10 PM by rdmaloyjr »

otuatail

  • Guest
Re: sf.bin
« Reply #29 on: September 28, 2011, 08:05:24 PM »
this is another ip address from sf.bin

224.0.0.252 28th 19:00

ZA can't fight against millions of different IP address's