pagefiles.sys makes me crazy !!

hello,

my pc has some problem with pagefiles.sys …

i cant open my drive by double click! i have to right click on my drive and choose explore to open the drive … moreover, once i connect new hard disk or flash memory it move to it …

In addition, i downloaded the new version of avast 5.0 and nothing happen…

it shows me this massage …

malware blocked
object: C:pagefiles.sys
infection: VBS:AutoRun-U [Wrm]
Action: Deleted
Process: C:\WINDOWS\system32\wscript.exe

malware blocked
object: d:pagefiles.sys
infection: VBS:AutoRun-U [Wrm]
Action: Deleted
Process: C:\WINDOWS\system32\wscript.exe

malware blocked
object: e:pagefiles.sys
infection: VBS:AutoRun-U [Wrm]
Action: Deleted
Process: C:\WINDOWS\system32\wscript.exe

the massage does not stop

363/363 and it keep increasing … any help pleaseeeee !! :frowning:

enter the safe mode and run dr.web cure it! scan
after rebooting
do a boot time scan by avast
then run ccleaner registry clean to solve registry problems.

you shouldn’t have a pagefile on each drive; I guess your system has been seriously infected. try to download and run MalwareByte http://www.malwarebytes.org/
the other thing is I don’t know if you made a typo or not, pagefile.sys doesn’t take an “s” (pagefiles), so if it’s no typo, it means those files haven’t been generated by Windows from the pagefile interface.
This auto-run process that you got is the source of your issue, see here to disable it first:
http://support.microsoft.com/kb/967715

But your system probably needs further cleaning, I guess Essexboy will notice this thread :wink:

you shouldn't have a pagefile on each drive
Microsoft tell the users to do that ;D ;D ;D ;D and dr.web cure it has the ability to clean the infections and there will be mo further clean ;)

Microsoft tell the users to put a page file on each drive… you got a link? did Dr Web tell you ? ;D

edit: by drive I mean partition OK…as to the advice to set one page file on each physical disk, I consider it bs, completely useless.

Microsoft tell the users to put a page file on each drive... you got a link?
i think you got a help and support in your windows open it and scan for pagefile.sys
did Dr Web tell you ?
three days ago the same virus and the same problem resolved on a windows xp sp2 by dr.web cure it"i cant talk to the spiders,how dr.web will tell me Logos?use your updated mind."

supercracker, sounds you came back to this forum with all the bullshit you use to post a while ago, hope that won’t last too long and you’ll go back as soon as possible to your native hole; keep hacking happily ;D… or take a few days off in the Golan heights :smiley:

day for you day on you

supercracker, sounds you came back to this forum with all the bullshit you use to post a while ago
thanks for your welcome,you are a very good person.
hope that won't last too long and you'll go back as soon as possible to your native hole
i dont think so
keep hacking happily
its really better than your posting
... or take a few days off in the Golan heights
nice idea from where you got all those new ideas,if i you i will work as a countries advisor

look, superspammer …you’re such a clown :smiley: … but an unaware one.

Its just exuberance of youth. :wink:
http://www.merriam-webster.com/netdict/exuberant

you got an English word too for that ??? ;D

http://www.larousse.fr/dictionnaires/francais/exubérant

exubérant, exubérante adjectif (latin exuberans, -antis)

Back to the topic :wink:

There is actually an exclusion built into avast! to ignore the pagefile.sys on all drives (IIRC the ?:\Page… accounts for this…)
So I don’t know what is happening there…

Also a search of the forum would have yielded many results concerning this…

@ UaEe and Scott,
This was the case for the on-access scanners in 4.8 but not for the on-demand and this is where the detections were coming. This has been carried over in 5.0 File System Shield exclusions, image1, but this exclusion doesn’t appear in the avast Settings, Exclusions, image2, so I would suggest you add that same exclusion into there. Note the exclusion in the image is one I created for my system.

I see… thanks David, hadn’t realised that… :slight_smile:

(I thought the ‘Malware Blocked’ was an on access thing…)

-Scott-

Yes, looking the message looks more like on-access so this is a weird one, that there is a detection on pagefile.sys. The detection looks like wscript.exe is the one accessing or modifying the pagefile.sys resulting in the alert on pagefile.sys as the exclusion in my image1 shows a read and write to pagefile.sys are allowed, but not execution.

So other checks are required, MBAM as Logos suggested.
See http://www.systemlookup.com/search.php?type=filename&client=malwaresearch-ff&search=wscript.exe

@ Logos,
you can legitimately split your pagefile.sys over multiple Drives (not partitions on a single drive) I used to do it so I had a small fixed size pagefile.sys (to stop pagefile fragmentation) in my c:\ and a larger one in my second HDD. This one however does look suspect as I doubt there are three HDDs each with their own pagefile.sys.

This one however does look suspect as I doubt there are three HDDs each with their own pagefile.sys.

this was exactly my point :wink:

as to page file usage, since I’ve seen how well a system can behave almost without using that at all (I mean the swap partition in Linux), I’m looking forward to seeing the day Windows will be able to “live” without it, ie use more RAM instead, or at least a better RAM management (although things have improved in Vista and Seven when compared to XP). As to multiple page files on multiple HDD I know, I mentioned it here btw, so if you found it brought more performance on your system (ie less page file fragmentation) then fine, but I doubt this would change anything on most recent hardware.