{"id":88,"date":"2008-01-29T09:23:56","date_gmt":"2008-01-29T16:23:56","guid":{"rendered":"https:\/\/www.tungsai.com\/blog\/?p=88"},"modified":"2008-01-29T09:23:56","modified_gmt":"2008-01-29T16:23:56","slug":"possible-malicious-infection-day-3","status":"publish","type":"post","link":"https:\/\/www.tungsai.com\/blog\/?p=88","title":{"rendered":"Possible Malicious Infection &#8211; Day 3"},"content":{"rendered":"<p>So, I log on, boot up, and two pop-ups appear on my desktop. The first one is UltraMon.exe crashing. Probably \/ Maybe legitimate; Ultramon is the program I use to control my Awesome Triple Monitor setup. But the Other, Oh, the OTHER message&#8230;. Well, have a look:<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/sysfader-error.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"149\" alt=\"sysfader_error\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/sysfader-error-thumb.jpg\" width=\"727\" border=\"0\"><\/a> <\/p>\n<p>&nbsp;<\/p>\n<p>SysFader: IE7XPLORER.EXE &#8211; Application Fatal Error<\/p>\n<p>The instruction at 0x0f634739 referenced memory at 0x03ac4e50. The memory could not be read. Click on OK to terminate<\/p>\n<p>[&nbsp; OK&nbsp; ]<\/p>\n<p>&nbsp;<\/p>\n<p>Now, although SysFader is a legitimate thing that I&#8217;ve heard of (It&#8217;s what windows uses to make your background fade to dark greyscale when logging out, etc.), The executable &#8220;IE7XPLORER.EXE&#8221; does *not* exist. And even if it were a legitimate IE7, I DID NOT LAUNCH it. Nor was it in my startup. So, why would sysfader \/ IE7 get an &#8220;Application Fatal Error&#8221;? Answer: IT WON&#8217;T.<\/p>\n<p>Note: This message ALSO appeared as a little warning bubble in the SysTray, you know, those <\/p>\n<p>For laughs, I googled &#8220;IE7XPLORER.EXE&#8221;&#8230;<\/p>\n<p><a href=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/ie7xplorer.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px\" height=\"208\" alt=\"ie7xplorer\" src=\"https:\/\/www.tungsai.com\/blog\/wp-content\/uploads\/2008\/01\/ie7xplorer-thumb.jpg\" width=\"361\" border=\"0\"><\/a> <\/p>\n<p>DUH! Big surprise there. Still&#8230; it&#8217;s amazing that NO HITS occurred. (By the time you read this, Google will have already picked up my Blog.)<\/p>\n<p>Also interesting of note is that no other antivirus companies other than the one mentioned yesterday (SaliarAR) have identified it. It reminds me of the ages old theory about how Antivirus companies would create the viruses, release them into the wild, and then, Voila! Here&#8217;s a cure&#8230; for $60! Not that I&#8217;m accusing this SaliarAR of doing such things&#8230; but it just reminds me of that old joke \/ conspiracy theory.<\/p>\n<p>Since this occurred at boot-up, Noel suggested I try this program called RunAnalyzer, available from the folks who do Spybot Search &amp; Destroy. I downloaded it, installed it, and it appears to be taking a while. I&#8217;ll take this opportunity to post this page, for the benefit of White Hatted Admins.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So, I log on, boot up, and two pop-ups appear on my desktop. The first one is UltraMon.exe crashing. Probably \/ Maybe legitimate; Ultramon is the program I use to control my Awesome Triple Monitor setup. But the Other, Oh, the OTHER message&#8230;. Well, have a look: &nbsp; SysFader: IE7XPLORER.EXE &#8211; Application Fatal Error The&hellip; <a class=\"more-link\" href=\"https:\/\/www.tungsai.com\/blog\/?p=88\">Continue reading <span class=\"screen-reader-text\">Possible Malicious Infection &#8211; Day 3<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-88","post","type-post","status-publish","format-standard","hentry","category-windows","entry"],"_links":{"self":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/88","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=88"}],"version-history":[{"count":0,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/88\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=88"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=88"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tungsai.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=88"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}