Author Topic: Pagefile infected by win32:notre  (Read 5877 times)

0 Members and 1 Guest are viewing this topic.

insider

  • Guest
Pagefile infected by win32:notre
« on: December 03, 2007, 11:42:42 AM »
VLK as you suggested : I got a warning that on the HD, which is not in use, the pagefile is infected .... what to do to get rid of this pest ??? It seems that I'm not the only one who got this warning when using Avast! http://help.com/post/12362-pagefilesys-has-been-infected-with

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Pagefile infected by win32:notre
« Reply #1 on: December 03, 2007, 03:56:32 PM »
For this particular false positive (pagefile), as a workaround, you can add the file to the Standard Shield provider (on-access scanning) exclusion list (if it is not still there by default).
Left click the 'a' blue icon, click on the provider icon at left and then Customize. Go to Advanced tab and click on Add button...
The best things in life are free.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Pagefile infected by win32:notre
« Reply #2 on: December 03, 2007, 10:26:42 PM »
scanning of pagefile.sys is excluded by default afaik...

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Pagefile infected by win32:notre
« Reply #3 on: December 03, 2007, 10:31:31 PM »
Thats correct. With mask:

?:\PAGEFILE.SYS

This will apply the exclusion rule to any drive...
Visit my webpage Angry Sheep Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Pagefile infected by win32:notre
« Reply #4 on: December 04, 2007, 01:21:05 AM »
if it is not still there by default
It should...
The best things in life are free.

insider

  • Guest
Re: Pagefile infected by win32:notre
« Reply #5 on: December 04, 2007, 09:54:21 AM »
strange but yesterday evening I rescanned my 2 HD's and the result was : nada, nothing found !! So maybe it was a "mistake" made by the prog or by the pc or ...by me .... ::)

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Pagefile infected by win32:notre
« Reply #6 on: December 04, 2007, 10:55:16 AM »
nope.. it's only a randomness of "dumping" to swapfile.. pagefile contains many footprints of swapped processes and it's quite possible, that some part of many times rewritten area looks "viral" ;).. that's the reason why pagefile.sys is excluded by default...

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89116
  • No support PMs thanks
Re: Pagefile infected by win32:notre
« Reply #7 on: December 04, 2007, 03:35:18 PM »
How then is the pagefile.sys being scanned if it is excluded by default, my only though is that the exclusions don't have it. This was detected by an on-demand scan by insider.

On my system it is in the standard shield exclusions but not in the Program Settings, Exclusions, so it would be scanned by the on-demand scan and ashquick.exe if used.

So if it is in the Standard Shield exclusions by default, why not the the Program Settings, Exclusions ?
« Last Edit: December 04, 2007, 03:42:41 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security