Author Topic: Rootkit hidden filefloppy sys  (Read 93087 times)

0 Members and 1 Guest are viewing this topic.

set1

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #75 on: December 06, 2011, 05:20:59 PM »
 >:(

The update 1) did not fix the problem - I am still getting the false positive and 2) it rebooted my computrer WITHOUT asking me while I was in the middle of writing an important work email!!!

montybanks

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #76 on: December 06, 2011, 05:27:13 PM »
Time now 1630 gmt English time.
Still getting message re rootkit kidden sfloppy/sys.
How soon before false positive fixed. any ideas??? >:(

REDACTED

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #77 on: December 06, 2011, 05:43:15 PM »
Hi

In Poland I have the same problem now. It started 30 minutes ago...

Offline calcu007

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 482
  • I'm lamma!
Re: Rootkit hidden filefloppy sys
« Reply #78 on: December 06, 2011, 05:44:13 PM »
Be sure you have the VPS 111206-2 or late
Asus Intel i7 8GB RAM , Win 8.1 64 bit, Avast IS

SaRaGoN

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #79 on: December 06, 2011, 05:51:02 PM »
With this update 111206-2 Avast fix the problem. :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89023
  • No support PMs thanks
Re: Rootkit hidden filefloppy sys
« Reply #80 on: December 06, 2011, 05:52:26 PM »
As mentioned ensure you have the latest VPS update 111206-2 and reboot 8 minutes after the boot the rootkit happens and you shouldn't get an alert.

See image extract of the end of the aswAR.log file run after a reboot on my system with that VPS.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

zing

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #81 on: December 06, 2011, 05:52:59 PM »
Yep, updated to VPS 111206-2 and it's fixed. No more rootkit messages about sfloppy.sys, after rebooting.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Rootkit hidden filefloppy sys
« Reply #82 on: December 06, 2011, 05:54:43 PM »
Cześć bombeczkaATgmail.com,

You do not want spammers on your back, then give your nick "bez małpy"
Did you update to the last engine and virus definitions?

pozdrawiam,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

msgreyberry

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #83 on: December 06, 2011, 06:20:24 PM »
Had the same problem 5 minutes ago...I was about to press "delete" but then I figured out something's not right...no viruses, no dangerous websites, no anything, nothing dangerous...using loads of precautions and antimalware engines I freaked out..Thank you Avast! for the quick update!
So I assume it is safe to "ignore" the notice?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89023
  • No support PMs thanks
Re: Rootkit hidden filefloppy sys
« Reply #84 on: December 06, 2011, 06:23:08 PM »
Yes, and ensure you have VPS 111206-2 as mentioned earlier and reboot.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline rob24

  • Full Member
  • ***
  • Posts: 113
Re: Rootkit hidden filefloppy sys
« Reply #85 on: December 06, 2011, 06:33:43 PM »
Well that seems to have sorted that OK , once I updated VPS manually to 111206-2.

What I don't understand it that on the first indication today after PC started, Avast recommended Delete followed by boot scan. The latter was clean and PC continued to start with no further warnings. I turned pc off again about an hour later, and later still I started up to the same warning, with the same recommendation. It appeared not to have deleted the file. It was at that point I consulted this thread whilst I still had the warning up, and took the advice to 'Ignore'.
Intel Core i5 CPU 4 x 3200 Mhz, 8Gb DDR3 RAM, Windows 10 64 bit, Malwarebytes' Anti-Malware 1.6 free, Superantispyware.
Samsung S3 mobile with Avast Mobile Pro and on Lenovo tablet.

BlueCrab405

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #86 on: December 06, 2011, 06:47:54 PM »
Hi all. Having the same issue this morning. Using Avast Free version on windows XP (man..i need to upgrade  ;) ). I did the same thing at first and chose delete (which did not happen).

I see in the engine and definitions update that version 111206-2 is out, however my system will not update the latest definitions for some reason. it's still stuck on 111206-0. I've been trying to update for over 2 hours now.

anyone else having this issue?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89023
  • No support PMs thanks
Re: Rootkit hidden filefloppy sys
« Reply #87 on: December 06, 2011, 07:15:15 PM »
Well that seems to have sorted that OK , once I updated VPS manually to 111206-2.

What I don't understand it that on the first indication today after PC started, Avast recommended Delete followed by boot scan.
<snip>

Certain detections will suggest doing a boot-time scan, rootkit based detections would be one area were boot-time scan would be suggested as by their nature rootkits seek to hide something (other malware). The boot-time scan operating before windows is running may well be able to see what would otherwise have been hidden if windows was running.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89023
  • No support PMs thanks
Re: Rootkit hidden filefloppy sys
« Reply #88 on: December 06, 2011, 07:16:53 PM »
Hi all. Having the same issue this morning. Using Avast Free version on windows XP (man..i need to upgrade  ;) ). I did the same thing at first and chose delete (which did not happen).

I see in the engine and definitions update that version 111206-2 is out, however my system will not update the latest definitions for some reason. it's still stuck on 111206-0. I've been trying to update for over 2 hours now.
<snip>

What errors are you getting when you try to update ?

- Try a repair of avast:
XP - Add Remove programs, select 'avast! Anti-Virus,' click the Change/Remove button and scroll down to Repair, click next and follow.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Henry-Finland

  • Guest
Re: Rootkit hidden filefloppy sys
« Reply #89 on: December 06, 2011, 07:38:35 PM »
The same as everybody else and on both computers.
Deleted and did the scan.
Vanished.

XP and Free Avast.

Henry