Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 12th, 2004, 10:31 AM
tempnexus's Avatar
tempnexus tempnexus is offline
Frequent Poster
 
Join Date: Apr 2003
Posts: 251
Default What the hell is Sysfader.exe ?

Ok I get a crash once in a while and many times is just a window that takes a second but right now I actually did a window capture and got this.

Sysfader:Explorer.exe
Instruction at 0x77f57e4f reference memory at 0x00000067 the memory was unable to be written.

I've ran SpySweeper, AdAware, TD-3, BoClean, Nod32 and Bitdefender. IT comes up with nothing...but the pc is sometimes unstable...so what the hell is sysfader?

Thanks so much
__________________
I have a computer and my browser tries to make me fat by feeding me cookies.
"You need to delete your video card and format your modem, and install AOL on your motherboard"
  #2  
Old March 12th, 2004, 10:39 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,398
Default Re:What the hell is Sysfader.exe ?

Hi tempnexus,

Have you checked your computer for spyware?
Stupid question. I now see you ran SpySweeper.
Try this anyway http://www.wilderssecurity.com/showthread.php?t=15913

I found this:
http://www.hardwareanalysis.com/content/topic/15565/

Regards,

Pieter
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #3  
Old March 12th, 2004, 10:40 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re:What the hell is Sysfader.exe ?

Hi Tempnexus, I can only find one possible useful link:
http://www.opentechsupport.net/forum...c/19441-1.html

Hope it helps Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #4  
Old March 12th, 2004, 10:48 AM
tempnexus's Avatar
tempnexus tempnexus is offline
Frequent Poster
 
Join Date: Apr 2003
Posts: 251
Default Re:What the hell is Sysfader.exe ?

This is weird no one knows for sure some say it's a file that places win into hybernation mode others say: "sysfader is used to effect fade in/out of menus and tooltip balloons. If it's persistently hanging-up, it can be disabled in Display Properties -> Effects -> uncheck "Use Transition Effects for menus and tooltips" (note: this is how it's disabled in Win2K; it might be done differently in XP)."
__________________
I have a computer and my browser tries to make me fat by feeding me cookies.
"You need to delete your video card and format your modem, and install AOL on your motherboard"
  #5  
Old March 25th, 2004, 09:18 AM
finewings
 
Posts: n/a
Default Re:What the hell is Sysfader.exe ?

I don't kown what it is either. BUT i solove it just now. Try to boot in the safe mode. Run msconfig in start->run. There seems to be some doubtable services there, stop them. Restart the computer... Good luck!
  #6  
Old July 4th, 2004, 12:52 PM
Sgt Bilko
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

I have exactly the same problem. Unfortunatly I can't offer any help as to what it is
  #7  
Old July 4th, 2004, 01:03 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: What the hell is Sysfader.exe ?

Could you check with SFC (?) if the explorer.exe is still ok?
__________________
Jooske
"o_o"
  #8  
Old July 10th, 2004, 07:01 AM
freedom1
 
Posts: n/a
Unhappy Re: What the hell is Sysfader.exe ?

I am having a similar problem with SysFader

I have run Ad Aware, Spy Bot and Notons and cant find anything

Everytime I go to a ftp site my browser hangs. When I go to my task manager I always has SysFader as not responding. Normal surfing seems OK its only when I go to a ftp site

Any advice would be appreciated, Thanks in advance!
  #9  
Old July 10th, 2004, 07:11 AM
freedom1
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

I thought that I would also post my HJT log as it may help in working out what the problem is

Logfile of HijackThis v1.97.7
Scan saved at 5:59:54 PM, on 10/07/2004
Platform: Windows XP SP1
MSIE: Internet Explorer v6.00

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\soundman.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\BIPAC-7000 ADSL USB Modem\CnxDslTb.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\My Documents\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page
O2 - BHO: (no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Toolbar - C:\Program Files\MSN Toolbar\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .png: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..
  #10  
Old July 10th, 2004, 07:14 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: What the hell is Sysfader.exe ?

Found a dutch page in the MS knowledge base telling the problem is known in Internet Explorer 6.0 and in a later hotfix it would have been fixed.

Somewhere i saw this description:
Based on Google it seems to be part of the Windows system and is used when you enable the "Fade effect" in Windows Display properties (Display properties -> Appearance -> Effects).

So not sure if the one combines the other?
__________________
Jooske
"o_o"
  #11  
Old July 12th, 2004, 10:09 AM
Taze
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

Found in another thread... Hope it helps!
_________________________________
Well ultimately I've found the answer, and lo and behold it was a virus. It didn't have anything to do with the installation I did, however - it had seemingly been on my PC for almost a month without doing anything.

The virus is a Trojan called 'Winshow'.

Here is the fix...
This problem is created by a trojan (VBS_Winshow.A, as Trend Micro refers to it as)
http://www.trendmicro.com/vinfo/viru...SHOW.A&VSect=T

or adware as Symantec refers to it as.

http://securityresponse.symantec.com...e.winshow.html

This past weekend happens to be about the one month anniversary of its initial appearance; perhaps this is the reason why it the 'copy' error started showing up. On my machine, it looks like it first deposited itself on 10/30/03. Its main impact for me was it would not allow multiple launches of IE from the desktop icon, and it became impossible over the weekend to synch my pda, HD MP3 player or use my multi-card reader, and impacted anything else that was hooked up through my USB 2.0 card. IE session since the beginning of November have seemed somewhat buggy; anything depending upon a plug-in applet (like Java) took FOREVER to load. The 'copy' boot error does not show up with every bootup or login, making it seem like the problem goes away.

In 2000/XP, you need to search for the folders Winshow and Winlink, usually deposited in C:\ Documents and Settings \ (user) \ Local Settings \ Application Data, where (user) is whatever name you log into or use XP/2000 with. If you have them, you will need to delete eventually, but you'll first have to delete the registry entries (if you don't, the trojan will simply recreate the folders with the next bootup). There probably is the file 'msupdater.exe' on your machine as well, this and the two folders have been associated as a IE hijacker routine a number of people have reported on the internet.

Norton's WinDoctor can delete some of the registry entries (it did for me, but it didn't get everything), but you really need to use it or better yet, use Hijack This, booted into Safe Mode (where the trojan isn't allowed to start before attempting to delete its components).

For those who don't know, Hijack This is an anti-hijacking app is easy to find (and best of all, is free). You can find it on CNET and other places to download. In my case, it came in a .zip file; within it was a .exe file that launches Hijack This when clicked. It doesn't appear to install itself to Windows. Upon starting in Safe Mode, you should get a window; select Scan, and in a second or two you will get a listing of the processes that launch on startup with your specific computer. Look for the Winlink and Winshow entries (under BHO on my computer), click the tick boxes, and click Fix Check.

Once done, you can reboot normally, go and find the the msupdater.exe file, Winshow and Winlink folders and delete w/o them showing up again.

To further clean up, you can go into the registry (with regedit, but only if you know what you're doing in there), and search for both winlink and winshow; there may be remnants still lurking as there were on my computer. If you find them, delete them; the trojan shouldn't be active at this point so it shouldn't recreate them. NOTE: if you have multiple login user identities on your machine, you may have to do this exercise for EACH one. If you're knowledgeable and brave enough, you can delete the registry entries in Safe Mode also, without using Hijack This or any other app.
  #12  
Old July 12th, 2004, 03:26 PM
Rockersuke
 
Posts: n/a
Unhappy Looks like it's not Winshow

Nops, I have also the same "Sysfader" symptoms but none of the Winshow files/keys. I think "Winshow" is not related to this.

Damn! ^_^''
  #13  
Old July 12th, 2004, 04:15 PM
Whynot's Avatar
Whynot Whynot is offline
Regular Poster
 
Join Date: Feb 2004
Posts: 50
Default Re: What the hell is Sysfader.exe ?

Have a read of this - it may throw some light on the subject
http://support.microsoft.com/default...b;en-us;828133
HTH
__________________
AMD64 x2 4299 , 2 Gig RAM, RAID 0, 7800GT, X-Fi Fati1ty, XP Pro (SP2) and .net/XP 64bit. NVidia Firewall , Windows Defender, Process Guard 3.4, Avast, SpyBot, Ad-Aware SE, SpywareBlaster, SpywareGuard, Firefox 1.5
  #14  
Old July 12th, 2004, 05:39 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: What the hell is Sysfader.exe ?

I wonder if people who updated IE 6.0 with all patches still have the problem?
__________________
Jooske
"o_o"
  #15  
Old July 12th, 2004, 06:58 PM
granduke's Avatar
granduke granduke is offline
Infrequent Poster
 
Join Date: Jul 2004
Location: Germany,EU near Jooske
Posts: 4
Default Re: What the hell is Sysfader.exe ?

I have win XP and update my IE 6.0 almost like everyday (although there's none atm).

And guess what,i dont even have sysfader.exe in my comp.I've searched and couldn't find one.
  #16  
Old July 13th, 2004, 01:48 PM
ipje ipje is offline
Infrequent Poster
 
Join Date: Mar 2002
Location: the netherlands
Posts: 46
Default Re: What the hell is Sysfader.exe ?

You have spysweeper on you're computer if this is version 3.0 then this could be you're problem. The last month I had problems with the "right click" of my mouse and crash of explorer.exe. But things were getting worse today I was not able to access files/maps with rightclick/using keyboard. In a dutch forum I read the same problems for other OS and spysweeper 3.0 (I use XP). Give it a try when you have version 3.0, uninstall it and see if you're problem is solved.
__________________
my photoalbums
  #17  
Old July 13th, 2004, 04:39 PM
Rockersuke
 
Posts: n/a
Unhappy Re: What the hell is Sysfader.exe ?

I've never installed Spysweeper and I always install Micorosoft updates, including the ones that they have released right today om my WinXP SP1 system...

...but the ###### explorer chrash with sysfader message is still there! Sometimes when I rightclick something, sometimes when I try to open anything... as random as usual...

sigh!
  #18  
Old July 23rd, 2004, 04:42 AM
Squib
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

I experienced it for the first time today - it froze the taskbar, but after several minutes (and pressing Alt-Ctrl-Del) the taskmanager came up and I could exit the hung "Sysfader.exe"

Everything returned to normal. No restart needed.

I have no idea what it is, but I was trying to open the start menu at the time it struck... background task was initialising a really old HDD from a 386.

Recent changes to my system: Disabled hardware acceleration because alpha blending caused display drivers (3dfx) to crash when I was in the middle of writing an application

Maybe having little or no hardware acceleration increases the chances of suffering the dreaded sysfader attack?
  #19  
Old July 25th, 2004, 08:27 AM
Jamesyb
 
Posts: n/a
Unhappy Re: What the hell is Sysfader.exe ?

Can anyone give more help to this issue?

What services did you delete/stop?

How do I get to display settings in XP
  #20  
Old July 25th, 2004, 08:39 AM
ronny ronny is offline
Frequent Poster
 
Join Date: Feb 2004
Location: Belgium
Posts: 231
Default Re: What the hell is Sysfader.exe ?

When you talk about the devil...
Today i was watching filmtrailers using IE & Quicktime6.5.1 , when suddenly i got also & for the first time(! ) this Sysfader error:
"Instruction at 0x10023b12 reference memory at 0x000000b8 the memory was unable to be written"
When i used Mozilla1.7 & QuickTime i don't have the error.

I think it is not a virus because i checked my pc with Kaspersky, Norton online, Housecall, e-Trust and they didn't found anything.
I also scanned using Adaware, Spybot S&D, Spysweeper, Bazooka, a² and Pestpatrol.
Only Pestpatrol found 593 pests. But they were almost all from GameSpyArcade and the other 4 must be false positives, because they were Microsoft dll's.

And yes my IE & XP is updated with the last patches.

edit: problem seems to have dissapeared, everything works fine now. And strangely, i can't find any sysfaderfile on my computer. So i am sorry, my post doesn't seem to be very usefull anymore. But i leave it here cause I did had the same mistake at one point.

Last edited by ronny : July 25th, 2004 at 10:12 AM.
  #21  
Old July 29th, 2004, 05:13 PM
Qwack
 
Posts: n/a
Unhappy Re: What the hell is Sysfader.exe ?

You aren't nuts.

I have the same problem.

Sysfader not responding and can't be stopped with Windows Task Manager.
Have to shut down thr Sytem with the Power Button.

Looked for Sysfader. Couldn't find it.

I also have another symptom. When I shut down Zone Alarm it comes back
with a message about "True Vector Internet Monitor not responding".

I'm looking for a way to solve the problem.....
  #22  
Old August 6th, 2004, 05:23 PM
Griffman1
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

Hi, I've been having a problem with my computer for about a week now and today when I was playing around with it trying to fix it sysfader.exe popped up in the task manager. It was only for about a half second and I'm not exactly sure that it was spelled correctly..when I saw it though I typed it in google and it brought me here.

The problem I've been having with my computer is whenever I load it up the icons on the desktop and the start menu all disappear..I went into the task manager at first when it happened and there was no explorer.exe so I ran a new task through the manager "explorer.exe". The icons came back and so did the start menu..but it was for about 2 seconds and then reclosed. I don't know if this is tied in with the sysfader.exe thing but if anyone could help me it would be greatly appreciated.
  #23  
Old August 6th, 2004, 05:24 PM
Griffman1
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

me again..I don't know what you might need to know but I'm running windows XP
  #24  
Old August 8th, 2004, 06:43 AM
hmmm
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

hi there i was just having the same error sysfader blah and i know where it comes from at least in my case....


its the machine debug manager servive which gets installed with visual studio.net and similar such as .net framework etc just check it and disable it in services ....but u need to enable it if u r programming wih studio again


test it for meit helped
  #25  
Old August 8th, 2004, 06:43 AM
hmmmm
 
Posts: n/a
Default Re: What the hell is Sysfader.exe ?

and i forgot its mdm.exe
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:31 PM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums