{"id":82,"date":"2008-01-28T07:06:41","date_gmt":"2008-01-28T14:06:41","guid":{"rendered":"https:\/\/www.tungsai.com\/blog\/?p=82"},"modified":"2008-01-28T07:06:41","modified_gmt":"2008-01-28T14:06:41","slug":"the-plot-thickens-winsysldrexe-and-critical-error-occured","status":"publish","type":"post","link":"https:\/\/www.tungsai.com\/blog\/?p=82","title":{"rendered":"The Plot Thickens&#8230; WINSYSLDR.EXE and &quot;Critical Error Occured&quot;"},"content":{"rendered":"<p>I am convinced that some viral \/ spyware is knocking on my door. This morning, Monday, January 28th, 2008, I came in to my office and my machine had been logged in all weekend (Locked, of course). Well, well, well, what did we have here: TWO instances of &#8220;WINSYSLDR.EXE&#8221; on my desktop.<\/p>\n<p>Sigh. Well, at least I&#8217;m able to gather additional information about this very possible threat. First, I noticed that the icon for it in the taskbar are the icon for Folders, as shown in this image:<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/winsysldr-error-2x.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"164\" alt=\"winsysldr_error_2x\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/winsysldr-error-2x-thumb.jpg\" width=\"523\" border=\"0\"><\/a> <\/p>\n<p>&nbsp;<\/p>\n<p>Second, in the Windows Task Manager, under the &#8220;Applications&#8221; tag, are two ACTUAL EXECUTABLE APPS, blatantly shown on the task manager. Note, people: <strong>A legitimate error message popped up by a legitimate application will NOT show up as a unique APPLICATION.<\/strong><\/p>\n<p><strong><\/strong>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/image.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"459\" alt=\"image\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/image-thumb.png\" width=\"409\" border=\"0\"><\/a> <\/p>\n<p><strong><\/strong>&nbsp;<\/p>\n<p>Thirdly: Under &#8220;Processes&#8221;, I now see a Process called &#8220;System&#8221;, <\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/system-task-mgr-winsysldr.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"459\" alt=\"system_task_mgr_winsysldr\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/system-task-mgr-winsysldr-thumb.jpg\" width=\"409\" border=\"0\"><\/a> <\/p>\n<p>&nbsp;<\/p>\n<p><strong>PEOPLE, THERE IS NO LEGITIMATE PROCESS CALLED &#8220;SYSTEM&#8221;.<\/strong><\/p>\n<p>No doubt my system is infected, after googling &#8220;winsysldr.exe&#8221;. as of last week, this very blog is the #1 hit; but many more hits have been added under some lesser-known virus pages; something called &#8220;SaliarAR&#8221;. I&#8217;ve never heard of it. <\/p>\n<p><a href=\"http:\/\/www.downloads-portal.com\/security-and-privacy\/anti-virus-tools\/saliarar_application-59071.html\" target=\"_blank\">http:\/\/www.downloads-portal.com\/security-and-privacy\/anti-virus-tools\/saliarar_application-59071.html<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>I don&#8217;t even trust THOSE sites, though. I must get to the BOTTOM of which EXECUTABLE this shit is running under!! How can I possibly do this? While searching for the answer, Noel suggested that I head over to Spybot Search &amp; Destroy, install it, run it, love it. Well&#8230; I didn&#8217;t wanna admit defeat, but as I scanned the impossibly long list of services running on my machine, trying to locate WHAT EXE was actually SPAWNING these dialogues, <\/p>\n<p>&nbsp;<\/p>\n<p>A NEW MESSAGE APPEARED RIGHT BEFORE MY EYES.<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/critical-error-occurred.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"139\" alt=\"critical_error_occurred\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/critical-error-occurred-thumb.jpg\" width=\"382\" border=\"0\"><\/a> <\/p>\n<p>&nbsp;<\/p>\n<p>And sure enough, showed up as &#8220;Critical error occured&#8221;. SPELLING ERROR! BLATANT SIGN OF ADWARE\/SPYWARE! Some foreigner obviously cooked up this malicious bullshit. (Can you tell i&#8217;m getting impatient?) Yeah, yeah&#8230; I could reinstall everything and be done with it, but that wouldn&#8217;t be very fun, now, would it?<\/p>\n<p>I wonder if they have a keylogger installed and are, at this very moment, watching me type in this Blog update.<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/critical-error-taskmgr.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"409\" alt=\"critical_error_taskmgr\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/critical-error-taskmgr-thumb.jpg\" width=\"364\" border=\"0\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&#8220;Critical error occured.exe&#8221;? RIIIIiiight. Downloaded &amp; installed SBS&amp;D immediately. It&#8217;s running a scan now&#8230; it&#8217;s gonna take a while, so I&#8217;ll post this up on teh innernets for immediate consumption.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I am convinced that some viral \/ spyware is knocking on my door. This morning, Monday, January 28th, 2008, I came in to my office and my machine had been logged in all weekend (Locked, of course). Well, well, well, what did we have here: TWO instances of &#8220;WINSYSLDR.EXE&#8221; on my desktop. Sigh. Well, at&hellip; <a class=\"more-link\" href=\"https:\/\/www.tungsai.com\/blog\/?p=82\">Continue reading <span class=\"screen-reader-text\">The Plot Thickens&#8230; WINSYSLDR.EXE and &quot;Critical Error Occured&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-82","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/82","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=82"}],"version-history":[{"count":0,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/82\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=82"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=82"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=82"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}