Author Topic: False positive: sfloppy.sys  (Read 28166 times)

0 Members and 1 Guest are viewing this topic.

kd5

  • Guest
False positive: sfloppy.sys
« on: December 06, 2011, 02:07:15 PM »
Full path: C:\Windows\System32\drivers\sfloppy.sys

OS: Windows XP SP3


I scanned this file at virusscan.jotti.org and 20 different AV scans (including Avast) said this file is safe.  Furthermore it is a part of the Microsoft Windows operating system so removing it will just screw up the OS, so removing this false positive just screwed up a lot of people's computers.  Seems Avast has had a few dangerously false positives lately, one of which I myself reported a couple of months ago.  I hope we're a little more careful in the future.       -kd5-  
« Last Edit: December 06, 2011, 02:10:58 PM by kd5 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: False positive: sfloppy.sys
« Reply #1 on: December 06, 2011, 02:18:00 PM »
it is already posted in the Virus and Worms section

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: False positive: sfloppy.sys
« Reply #2 on: December 06, 2011, 04:00:24 PM »
See this topic, http://forum.avast.com/index.php?topic=89963.0, anti-rootkit detection in XP systems.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

whkrems

  • Guest
Re: False positive: sfloppy.sys
« Reply #3 on: December 06, 2011, 04:04:57 PM »
How about this, could sfloppy be a rootkit type file by definition?
"A rootkit is software that enables continued privileged access to a computer while actively hiding its presence from administrators by subverting standard operating system functionality or other applications."

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: False positive: sfloppy.sys
« Reply #4 on: December 06, 2011, 04:09:59 PM »
Because it is  hidden driver and it isn't digitally signed, this has obviously cause confusion in the anti-rootkit scan. So something changed in the anti-rootkit scan as it wasn't previously detected, a classic sign of a possible false positive detection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

direktx

  • Guest
Re: False positive: sfloppy.sys
« Reply #5 on: December 06, 2011, 04:15:43 PM »
avastsvc.exe --> Alureon-AOR   ???

Offline jadinolf

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1090
Re: False positive: sfloppy.sys
« Reply #6 on: December 06, 2011, 04:35:21 PM »
Good to know.  When I got it on three computers I became a little suspicious. :)
printed on 100% recycled bytes

Bart5

  • Guest
Re: False positive: sfloppy.sys
« Reply #7 on: December 06, 2011, 04:38:17 PM »
I got the same FP on win XP SP3.

Garrog

  • Guest
Re: False positive: sfloppy.sys
« Reply #8 on: December 06, 2011, 04:44:30 PM »
@direktx: if you have a suspected infection, please read http://forum.avast.com/index.php?topic=14433.0 then post in the proper place.

To others...ok maybe it's unlikely the average user needs this driver but let's call me a completist, this is the inevitable question following this cock-up:

For those of us who blindly trusted the Avast recommended option to delete the sfloppy driver - can someone please provide instructions or *official* links to fix our now incomplete systems (I need XP 32b but mileage will vary)?!?  >:( (Windows repair/hotfix/remove-re-install SP3??)

Thanks!

falcon710

  • Guest
Re: False positive: sfloppy.sys
« Reply #9 on: December 06, 2011, 04:48:01 PM »
same problem on windows xp SP3

Offline -Genesis-

  • Sr. Member
  • ****
  • Posts: 286
Re: False positive: sfloppy.sys
« Reply #10 on: December 06, 2011, 04:50:36 PM »
When i was innocent I try to remove but it need to bootscan for removal so i cancelled it.

I think Avast didnt remove the sfloppy.sys file because virus chest is empty.
« Last Edit: December 06, 2011, 05:03:51 PM by -Genesis- »
Windows 11 Pro / Windows Defender/
Ryzen 5 1600/ Aorus Gtx 1080Ti Xtreme/ Gskill Trident Z RGB 3000/ Samsung Evo 250GB/ Western Digital Black 1 TB

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Re: False positive: sfloppy.sys
« Reply #11 on: December 06, 2011, 04:56:54 PM »
For those of us who blindly trusted the Avast recommended option to delete the sfloppy driver - can someone please provide instructions or *official* links to fix our now incomplete systems (I need XP 32b but mileage will vary)?!?  >:( (Windows repair/hotfix/remove-re-install SP3??)
You can try System File Checker utility:
Code: [Select]
sfc /scannow
http://support.microsoft.com/kb/310747/
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

antonpaco

  • Guest
Re: False positive: sfloppy.sys
« Reply #12 on: December 06, 2011, 05:06:45 PM »
a lot of people followed the avast instructions that said " DELETE" and this create confusion and problems on the pc. I hope avast will be more carefull in the future in order to evoid false positive. I scan the file on some antivirus link and all, avast including said that file is safe.
Please make sure to fix the problem as soon as possible.

Offline Giraffe

  • Sr. Member
  • ****
  • Posts: 241
  • I'm not a Lama!
Re: False positive: sfloppy.sys
« Reply #13 on: December 06, 2011, 05:09:56 PM »
Avast has just popped up here telling me that this is a rootkit. Checking on line gives me the same size and the properties tell me that it's been here for over 3 years and is MS so I've left it.

Yesterday evening I did a full scan with SAS, MBAM, Malware Destroyer, Spybot S&D and a boot-time scan with Avast (I do this once a month) and there were no problems.

I don't know what deleting it would do...!
W7 Pro SP1 32 bit
Intel Core i5 5675C; 4GB DDR3 1600 RAM
Avast!: 2328; Comodo Firewall

xtinguish

  • Guest
Re: False positive: sfloppy.sys
« Reply #14 on: December 06, 2011, 05:18:39 PM »
If you deleted the file in error, on rebooting, Windows should recreate the  file automatically. If it doesn't, there are instructions on how to recreate the file from within Windows if you look in the virus and worms section. http://forum.avast.com/index.php?topic=89963.0
« Last Edit: December 06, 2011, 05:23:03 PM by xtinguish »