How can I securely delete pagefile.sys and hiberfil.sys?

problemo

New member
Local time
7:14 PM
Messages
22
I run Windows 7-64 bit Home Premium and work on encrypted containers with TrueCrypt. I'm afraid that such sensitive information (including passwords) may be unencrypted on pagefile.sys or hiberfile.sys. How can I securely delete both of these files? I know there's a method in Windows 7 to delete pagefile.sys at shutdown but I heard from different sources on the net, this is unreliable and does not in fact SECURELY delete the content inside pagefile.sys. Any suggestions?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bitIntel Core2 Quad 8300 @ 2.5GHz8GBATI Radeon 4800 Series
Computer Manufacturer/Model Number
HP Elite PC
OS
Windows 7 Home Premium 64-bit
CPU
Intel Core2 Quad 8300 @ 2.5GHz
Memory
8GB
Graphics Card(s)
ATI Radeon 4800 Series
Monitor(s) Displays
Dell 23" Widescreen
Screen Resolution
1920x1080
Hard Drives
685GB SATA3G
Case
HP Elite
Keyboard
HP Keyboard
Mouse
Microsoft optical mouse
Internet Speed
1MBps download / 60kbps upload
Just disable them and wipe the free space with 0's after that?
 

My Computer My Computer

At a glance

Microsoft Windows 10 Professional / Windows 7...Intel i5-357016GB DDR3AMD Radeon HD 7850 2GB
Computer type
PC/Desktop
OS
Microsoft Windows 10 Professional / Windows 7 Professional
CPU
Intel i5-3570
Motherboard
Lenovo Mahobay
Memory
16GB DDR3
Graphics Card(s)
AMD Radeon HD 7850 2GB
Sound Card
(1) Realtek HD Audio (2) AMD HD Audio
Monitor(s) Displays
LG LS192WS
Screen Resolution
1440 x 900 @ 32bit color
Hard Drives
(1) SUV300S37A/120G (2) ST3500413AS SATA Disk Device AHCI mode enabled.
PSU
Corsair HX620
Case
Thermaltake V4 Black Edition
Cooling
Cooler Master Hyper 212 + Artic Silver 5 on CPU/GPU
Keyboard
Dell SK-8115
Mouse
Razer Copperhead with MAPED mat (awesome!)
Internet Speed
100 Mbps up/down
Browser
Chrome

My Computer My Computer

At a glance

Windows7 Pro 64bit SP-1; Windows XP Pro 32bitIntel Core i7-870 Lynnfield 2.93GHz LGA 1156 ...8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GBASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit G...
Computer Manufacturer/Model Number
Hopalong/ Godzilla
OS
Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
CPU
Intel Core i7-870 Lynnfield 2.93GHz LGA 1156 95W Quad-Core
Motherboard
ASUS P7P55D-E PRO
Memory
8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GB
Graphics Card(s)
ASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit GDDR5
Sound Card
VIA Onboard
Monitor(s) Displays
Asus VS248H-P 24"; Samsung SyncMaster 941BW 19"ws
Screen Resolution
1920x1080; 1440x900
Hard Drives
Samsung 830 120GB SSD
Intel 320 120GB SSD
Western Digital Caviar Black WD7501AALS 750GB 7200 RPM SATA 3.0Gb/s
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA 3.0Gb/s
PSU
COOLER MASTER Silent Pro RS850-AMBAJ3-US 850W Modular
Case
COOLER MASTER HAF 932 RC-932-KKN5-GP Black
Cooling
Scythe "Mugen-2 Rev.B" (2 ScytheKaze-Jyuni PWM fans)
Keyboard
Logitech K-320
Mouse
Kensington
Antivirus
Avast Inernet Suite
Browser
IE 9 ; Chrome
Hi Problemo,

You might want to try Mark Russinovich's SDELETE, from here

SDelete

It runs from the CMD command line. SDELETE is DoD 5220.22-M compliant. A single pass should be sufficient for your needs.

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.

My Computer My Computer

At a glance

Windows7 Pro 64bit SP-1; Windows XP Pro 32bitIntel Core i7-870 Lynnfield 2.93GHz LGA 1156 ...8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GBASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit G...
Computer Manufacturer/Model Number
Hopalong/ Godzilla
OS
Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
CPU
Intel Core i7-870 Lynnfield 2.93GHz LGA 1156 95W Quad-Core
Motherboard
ASUS P7P55D-E PRO
Memory
8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GB
Graphics Card(s)
ASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit GDDR5
Sound Card
VIA Onboard
Monitor(s) Displays
Asus VS248H-P 24"; Samsung SyncMaster 941BW 19"ws
Screen Resolution
1920x1080; 1440x900
Hard Drives
Samsung 830 120GB SSD
Intel 320 120GB SSD
Western Digital Caviar Black WD7501AALS 750GB 7200 RPM SATA 3.0Gb/s
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA 3.0Gb/s
PSU
COOLER MASTER Silent Pro RS850-AMBAJ3-US 850W Modular
Case
COOLER MASTER HAF 932 RC-932-KKN5-GP Black
Cooling
Scythe "Mugen-2 Rev.B" (2 ScytheKaze-Jyuni PWM fans)
Keyboard
Logitech K-320
Mouse
Kensington
Antivirus
Avast Inernet Suite
Browser
IE 9 ; Chrome
sdelete and truecrypt

From a forensic standpoint your data is always on your hard drive the only way to securely get rid of it is to write zeros over that data numerous times. However you DO NOT want to delete or overwrite the pagefile.sys as its a critical system file and Windows caches much of its data on to it. For non system critical files you may want to use sdelete by sysinternals the command is sdelete -p <Times to write over> <File or Directory Path>. E.g. sdelete -p 15 "c:\textfile".

Someone mentioned Truecrypt, it is very stable and very secure. You should use AES 256-bit encryption which has not been cracked.
 

My Computer My Computer

At a glance

Windows XP and Windows 7
OS
Windows XP and Windows 7
pagefile.sys is not a cache for anything stored on the disk, it just stores data paged out of system RAM. It's virtual memory. Of course that doesn't mean it's any less likely to contain unencrypted data that was worked with at any point in time.

The only 100% reliable solution against leaving any unencrypted remnants behind is to encrypt the Windows system partition itself, including the pagefile.sys stored within it as well as any and all cache and temporary files created or modified during a Windows session.

(However, it depends on what's on those Truecrypt-encrypted volumes and how the OP is working with their contents in the first place.)

Another effective, though uncommon, method is to use software to automatically create and format a fixed-size RAM disk at boot time and allocate it with a pagefile.sys, enabling you to keep the pagefile out of any disk-based volumes without having to disable it altogether. Of course using a RAM disk to store a file that's used as virtual memory is a bit...backward. ;)

(I do this on my laptop though, since it has a full 1GB of RAM that my 32-bit Windows can't see but my RAM disk software is able to use separately.)

Clearing the pagefile.sys file at every Windows shutdown is an obvious and simple method requiring a single registry key change which is pretty trivial, but it'll delay the shutdown a lot, and this doesn't address the remaining issue of various cache and temp files left behind on the system volume.

For the record: Clear the page file at shutdown
 

My Computer My Computer

At a glance

Windows 7 Professional SP1 32-bitIntel Core 2 Duo E6600 2.4GHz4GB DDR2-667 (4x1GB in dual-channel config)nVidia GeForce 9800 GT
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom-built
OS
Windows 7 Professional SP1 32-bit
CPU
Intel Core 2 Duo E6600 2.4GHz
Motherboard
Asus PL5D2
Memory
4GB DDR2-667 (4x1GB in dual-channel config)
Graphics Card(s)
nVidia GeForce 9800 GT
Sound Card
Creative X-Fi XtremeMusic
Monitor(s) Displays
Acer P236H
Screen Resolution
1920x1200 (DVI)
Hard Drives
OCZ SSD Vertex Plus 60GB SATA (Firmware 3.55), 64MB cache
Hitachi HD321KJ SATA, 320GB, 7200rpm, 16MB cache
PSU
Antec TruePower 2.0
Case
Cooler Master Centurion
Cooling
Too many fans
Keyboard
Standard
Mouse
Microsoft wireless optical mouse
Internet Speed
AT&T U-verse (18mbit/sec)
Antivirus
Microsoft Security Essentials
Browser
Firefox
Other Info
Other devices:
Compaq CQ-60 laptop
Google Nexus 7 (2012) tablet
Nvidia SHIELD tablet (US/LTE)
Hardkernel ODROID-XU single-board computer (Samsung Exynos 5420)
Back
Top