Author Topic: help for suela-1042  (Read 7909 times)

0 Members and 1 Guest are viewing this topic.

FuReX

  • Guest
help for suela-1042
« on: March 17, 2004, 10:11:16 PM »
hi
avast find this virus(?) in the file C:\pagefile.sys
if i delete it and restart pc, the file is here yet and it's infected!
i hope you understand! i'm italian!
ciao!

Summoner Yuna

  • Guest
Re:help for suela-1042
« Reply #1 on: March 17, 2004, 10:59:54 PM »
in the pagefile??? I have never heard of a virus in there. run a scan with a scanner to make sure its not fale positive http://housecall.trendmicro.com

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:help for suela-1042
« Reply #2 on: March 17, 2004, 11:05:57 PM »
Yuna. the pagefile in windows is very similar to the virtual memory in the Mac OS. and the Mac Autostart worm did "hide" in virtual memory so i would guess its not impossible on a PC
"People who are really serious about software should make their own hardware." - Alan Kay

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:help for suela-1042
« Reply #3 on: March 18, 2004, 09:57:42 AM »
It's probably just a false alarm...
In any case, the pagefile cannot be "infected"... so if this is the only file the "virus" is found in, you don't have to worry.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:help for suela-1042
« Reply #4 on: March 19, 2004, 04:41:33 PM »
igor, is it impossible? I think the pagefile is like a set part of the HDD that acts like RAM i think so could a virus not hide there just like in RAM.
mac Virtual memory is subject to this.
"People who are really serious about software should make their own hardware." - Alan Kay

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:help for suela-1042
« Reply #5 on: March 22, 2004, 11:10:52 AM »
Well, the pagefile is an extension of the system RAM - so, in fact you can say it's "RAM". If a virus is found inside the file, it means it is in memory (though as I said, it's probably a false alarm in this case). Only the operating system controls this file - a virus cannot "hide" there, it's up to the system what parts of the memory it will swap to the pagefile.

However, you cannot access (e.g. scan) the pagefile when the operating system is running. So, I believe the original poster scanned a pagefile of a system that was not running (either it was done using a boot-time scanner, or it's a multi-OS system). The content of the pagefile is not reused when the system is started - so the data inside the file can simply be ignored - they will be "forgotten" and overwritten by other data.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:help for suela-1042
« Reply #6 on: March 22, 2004, 04:19:00 PM »
thanks igor. i was just curious  :)
"People who are really serious about software should make their own hardware." - Alan Kay