An Antivirus site I can trust - Winchook.dll and Winsys2.exe

Page 1 of 1 [ 7 posts ] 

pakled
Veteran
Veteran

User avatar

Joined: 12 Nov 2007
Age: 67
Gender: Male
Posts: 7,015

03 Dec 2009, 5:51 pm

I'm getting an error message that says winsys2.exe can't find winchook.dll. I'm also getting a note from Avast saying I have a trojan.

Now, back in the day, I would just go to a trusted site, but apparently, they've all gone out of business. Some sites say 'it's not a problem', some sites say 'it's a potential trojan with the same name as an MS file' . One site said 'are you sure you want to leave this site?' That message always gets a rousing '@#$% yeah'.

So the real problem is what help can I trust? Do you guys know of any web sites that can explain what it is (I'm figuring it probably is a trojan), and most importantly, how to get rid of it?

Thanks.

(Ps - I wouldn't be a bit surprised if this has something to do with my 'static for sound' problem)


_________________
anahl nathrak, uth vas bethude, doth yel dyenvey...


cyberscan
Veteran
Veteran

User avatar

Joined: 16 Apr 2008
Age: 56
Gender: Male
Posts: 1,296
Location: Near Panama, City Florida

03 Dec 2009, 6:08 pm

One thing you can do is see if these files (winsys2.exe and winchook.dll) are required by Windows. Do this by searching for the files on another computer running the same version of Windows you have. If not found on the other computer, try renaming winsys2.exe to winsys2.bak. Reboot and run the Avast. If your system crashes, try restoring the file back to its original name.


_________________
I am AUTISTIC - Always Unique, Totally Interesting, Straight Talking, Intelligently Conversational.
I am also the author of "Tech Tactics Money Saving Secrets" and "Tech Tactics Publishing and Production Secrets."


Tach
Pileated woodpecker
Pileated woodpecker

User avatar

Joined: 30 Oct 2009
Age: 34
Gender: Male
Posts: 191
Location: Sol System

03 Dec 2009, 11:24 pm

The latest AVAST update started giving a LOT of false positives.
On mine it detected Spybot S&D and a visual studio addon as a trojan.


_________________
I got a C++ in programming...


pakled
Veteran
Veteran

User avatar

Joined: 12 Nov 2007
Age: 67
Gender: Male
Posts: 7,015

03 Dec 2009, 11:41 pm

hmm...yeah, Avast did just update...somebody get the bacon, I've got egg on my face...;)


_________________
anahl nathrak, uth vas bethude, doth yel dyenvey...


Friskeygirl
Veteran
Veteran

User avatar

Joined: 25 Jun 2009
Age: 40
Gender: Female
Posts: 1,865

04 Dec 2009, 2:44 pm

I will skip that update, it has been popping up since yesterday, so far Avast
has been trouble free for me, which windows version are you using pakled.



pakled
Veteran
Veteran

User avatar

Joined: 12 Nov 2007
Age: 67
Gender: Male
Posts: 7,015

05 Dec 2009, 12:18 am

Windows XP , SP (whatever the last one was...;)AMD dual-core, 4g mem, Asus System board

I have XP at work, and don't find either file on the machine there.
I've been going through the various web sites, forums, etc., and it's evenly divided between
'this is harmless'
'this is Nvidia's fault (I have an nvidia card)
This is a dangerous Trojan that does high-cost calling when needed.(but not by me)
microsoft (why am I not surprised?) doesn't seem to have anything at all on either file.
From one of the reports, it's automatically loaded on startup. and part of my installed programs.
Actually, now that I think of it, I'm going to make sure by calling my ISP. I'll check some more.
I wish Computer Cops was still around, at least I could trust 'em.


_________________
anahl nathrak, uth vas bethude, doth yel dyenvey...


pakled
Veteran
Veteran

User avatar

Joined: 12 Nov 2007
Age: 67
Gender: Male
Posts: 7,015

05 Dec 2009, 1:03 am

Ok, Hijack This! didn't have any help per se, but at least it gave me some semi-trustworthy sites.

Evidently, both files are semi-legit; they're used in both real programs and malware..
They've been deleted, time for a reboot. If you don't see me for a couple of days, it's more essential than I thought...;)


_________________
anahl nathrak, uth vas bethude, doth yel dyenvey...