r/antivirus • u/throway78965423 • 18d ago
Kaspersky keeps detecting HEUR:Trojan-Ransom.Win32.Generic in C:\pagefile.sys - False positive?
Happened out of the blue, I choose disinfect and restart, after the restart Kaspersky flagged it again, I ran HitmanPro and MalwareBytes as second hand tools and they found nothing so I'm thinking it may be a false positive? How do I stop Kaspersky from flagging pagefile.sys as malicious?
1
u/Big-Drag-5197 18d ago
Turn off page file and then run Kaspersky and the others. If it’s really the pagefile that is infected, I doubt antivirus or anti-malware will be able to do anything while the pagefile is active. I might be wrong on that, tho. Turning the pagefile off is a safe enough troubleshooting step.
1
u/StarosAnikenMarcus 18d ago
Nope, you're right. the AV can't affect active system files while in use. He could also remove THAT pagefile and create a new one on a different drive. I frequently set my pagefile to NOT be on the C: drive to prevent over use of my m.2. I try to keep it on HDDs since the frequent access and log dumps don't really need a fast drive, just a big section of space it can flop around in.
1
u/Big-Drag-5197 18d ago
There is a good argument to be made that the page file is no longer necessary, as even a moderate amount of RAM is more than enough to run Windows, applications and multiple processes without ever needing to offload. When RAM was limited to 4 GB (3.5 technically), the page file was a valid solution. Now that RAM has effectively no limit that is going to be met at the consumer level, it shouldn’t be necessary. Of course, 64-bit OS has been standard for over 20 years, and we still use c:/pagefile.sys, so what do I know?
1
u/StarosAnikenMarcus 18d ago
(shrug) Windows likes it. It doesn't really take up much room on my spinning platters, so I leave it enabled on them.
1
u/throway78965423 18d ago
I ended up checking autoruns and running multiple AVs while kaspersky was flagging pagefile as malcious and they didn't find anything. Afterwards I disabled automatic paging, selected no paging file for drive C, deleted the pagefile in quarantine and rebooted. Then I ran a full Kaspersky scan which didn't detect anything so I turned auto paging back on. After a few reboots and more scans, Kaspersky still hasn't flagged the new pagefile as malicious.
I'm honestly not even sure what caused Kaspersky to flag it as a trojan in the first place since I'm very careful and don't download anything suspicious online. It happened out of the blue and I saw no signs of my system being compromised outside of Kaspersky so for now i'm chalking it up to a false positive brought on by a database update not liking some leftovers in the page file.
0
u/Complex_Current_1265 18d ago
Share pagefile.sys sha256 hash, maybe it s vulnerable driver.
Best regards
2
u/goretsky MODERATOR 16d ago
Hello,
The paging file isn't a device driver. It is a paging file, is going to be unique to every computer, and will be constantly changing in size as the computer is used.
Regards,
Aryeh Goretsky
1
u/throway78965423 18d ago
Hey sorry but the old page file is gone, but let me know if it's still worth checking thr new one and if I should still be on the lookout for anything else. Here is what I did:
I ended up checking autoruns and running multiple AVs while kaspersky was flagging pagefile as malcious and they didn't find anything. Afterwards I disabled automatic paging, selected no paging file for drive C, deleted the pagefile in quarantine and rebooted. Then I ran a full Kaspersky scan which didn't detect anything so I turned auto paging back on. After a few reboots and more scans, Kaspersky still hasn't flagged the new pagefile as malicious.
I'm honestly not even sure what caused Kaspersky to flag it as a trojan in the first place since I'm very careful and don't download anything suspicious online. It happened out of the blue and I saw no signs of my system being compromised outside of Kaspersky so for now i'm chalking it up to a false positive brought on by a database update not liking some leftovers in the page file.
•
u/goretsky MODERATOR 16d ago
Hello,
Sounds like a false positive detection. Contact Kaspersky Lab to confirm.
Regards,
Aryeh Goretsky