This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Pagefile.sys virus - False positive?

Hey,

I have a Sophos client reporting the following as multiple different viruses:

Virus/spyware Not cleanable Mal/Iframe-F \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy13\pagefile.sys
Virus/spyware Not cleanable Mal/Badsrc-C \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy13\pagefile.sys
Virus/spyware Not cleanable Troj/Fujif-Gen \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy13\pagefile.sys
Virus/spyware Not cleanable Troj/Iframe-CG \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy13\pagefile.sys
Virus/spyware Cleanup failed Troj/Badsrc-M \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy13\pagefile.sys


This showed up the same day as the now infamous Shh/Updater-B False positives

At first I ignored it because I figured it would start to show on multiple computers, but it didn't.

It only showed on a single computer so now I am not sure if this is a false positive or not. Can the pagefile.sys get infected by a virus?

Has anyone seen the behavirous before? And if so, should I take action to clean it? Or can it be ignored as a false positive?

Thank you.

:33137


This thread was automatically locked due to age.
Parents
  • Hey QC,

    No confusion.. I don't think.

    Thank you for clarifying.

    I just wanted to add on to this thread since I am still dealing with this same notification.

    Out of curiosity, do these items show on the Sophos client? (if you have been able to check?)

    In my situation, there is no notification on the Sophos client. The SEC is the only indication that there is

    anything wrong.

    And yes, I have tried acknowledging the notifcation only to have it reappear after a full system scan.

    cheers

    :34835
Reply
  • Hey QC,

    No confusion.. I don't think.

    Thank you for clarifying.

    I just wanted to add on to this thread since I am still dealing with this same notification.

    Out of curiosity, do these items show on the Sophos client? (if you have been able to check?)

    In my situation, there is no notification on the Sophos client. The SEC is the only indication that there is

    anything wrong.

    And yes, I have tried acknowledging the notifcation only to have it reappear after a full system scan.

    cheers

    :34835
Children
No Data