Wat The Hell Is This??????

Discussion in 'Windows Desktop Systems' started by alloy25, Mar 6, 2003.

    Can someone please tell me wat this is?????

    NAV found a W32.KWbot.D.Worm on my comp and backed it up then deleted it ??????

    Now on logon I get this ???

    PLZ HELP !!!

    Assuming the missing file isn't part of the OS, remove its instance from the registry (I havn't checked to see what that file is). If it's a corrupted or required MS file, run a repair from the XP CD.

    Betcha $50 you pulled that worm in through KaZaA.:p
    If you do a search on Google for winsys.exe, it brings up several pages saying that it often comes with a "Tanked" virus that is sent via Kazaa. It sounds like your antivirus was removed the infected files but didn't fix any registry settings. Looking at the website that JJH35 gave you, there are probably some registry entries that are trying to make winsys.exe startup every time. Run regedit and kill winsys.exe in the following places.
    HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
    HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ RunServices
    HKEY_CURRENT_USER\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ RunOnce
    This should hopefully solve your problem.
    You betta come get your $ 50 then cause your absolutley right!!!!ttaaddaarrr !!!!!! Welcome to the wonderful world of kazaa...lol....

    JJH35: I'll give it ago and let you know.....

    here is the fix

    i fixed that annoying problem at startup.here it is.goto,regedit,

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\shell ,double click on the shell value and replace the text with "Explorer.exe" (without brackets).basically what you are doing is deleting the "C:\WINDOWS\System32\winsys.exe" entry from that part of the key

    Ok i gave it a go but havent logged off then back on so i'll see later ...thanks to everyone for there help


    Why do you have to backup for if you remember where the thing you changed is????????