Re: PSA: Somehow, without action from me, hyberfile.sys got turned on
Maria Sophia <[email protected]> Wed, 1 Apr 2026 04:24:37 -0400
| Newsgroups | alt.comp.os.windows-10,alt.comp.microsoft.windows |
|---|---|
| Organization | BWH Usenet Archive (https://usenet.blueworldhosting.com) |
| Message-ID | <[email protected]> |
Maria Sophia wrote: > Apparently, it "can" happen. > Apparently it "did" happen. How the heck did this happen that hibernation was turned on but not by me? Based on Winston's kind and helpful comment that it can't happen, I'm faithfully digging into if/how an unsupported Win10 box can change the power configuration without the user's consent, as it surprised me too. Especially as I'm testing what happens on an unsupported Win10 box. (I never signed up for the MSA so I can't get the free ESU updates.) Certainly I received Windows Defender updates as shown below: Security Intelligence Update for Microsoft Defender Antivirus KB2267602 (Version 1.447.105.0) - Current Channel (Broad) Successfully installed on 3/31/2026 Security Intelligence Update for Microsoft Defender Antivirus KB2267602 (Version 1.447.96.0) - Current Channel (Broad) Successfully installed on 3/30/2026 Apparently Windows defender updates use the Windows servicing stack. Which is apparently the same infrastructure used for Windows Update. Apparently the servicing stack periodically validates system configuration. Apparently if a power policy has issues, Windows restores defaults. Where the default for Windows 10 is: a. Hibernation ON b. HibernateEnabled = 1 c. hiberfil.sys created As shown by: C:\> reg query HKLM\SYSTEM\CurrentControlSet\Control\Power /v HibernateEnabled My theory? A Windows servicing stack power-policy reset triggered during a Defender update cycle. Can I prove that? Nope. But since it happened, there must be a mechanism for it to happen. It's all I can think of that might do it without the users' knowledge. There is a way to stop this, but it's nuclear. C:\> powercfg /h off C:\> cd C:\ C:\> echo. > hiberfil.sys C:\> attrib +r +s +h hiberfil.sys C:\> reg add HKLM\SYSTEM\CurrentControlSet\Control\Power /v HibernateEnabled /t REG_DWORD /d 0 /f That supposedly will permanently disable hibernation by turning it off, and then blocking Windows from recreating the hibernation file, and then forcing the system to keep hibernation disabled at the registry level. I just did those commands. I'll let you know if hiberfile.sys ever comes back alive again.