Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I have a firewall and it says that my wininit.exe keeps trying to access the internet... is it suppose to do that?
My computer is acting all weird..
Kernel is using 100% cpu all the time...
My norton anti-virus can't read the boot record...(it reads the master but not the others) So it freezes everytime i run norton's anti-virus...
Oh and I have like 10 IPX sockets open all the time...so my system monitor says..
AAAAAAHHHHHHHH!!!!!
Somebody help me!!!!!!!!!

I have too much stuff...
Can't find time to back up all my stuff...
Gotta find a way...
AAAAHHHHHH!!!!!!

Sort of sounds like the W32.HLLW.Bymer virus/worm. See the link above.
There is a legit wininit.exe in \windows but if you find one in \windows\system then it sounds like this one.

Heh. this sounds familiar...I am currently resurrecting my family's computer from *exactly* the same problem. what timing! =)

The wininit.exe that resides in windows\system _is_ a backdoor virus. Its
also just that, a lame backdoor. The
wininit.ini that rides with it will shutdown
your PC during bootup. Cure;
(1) boot from floppy,
(2) delete c:windows\windows\system\wininit.*

the virus your having problems with is the w32/kriz.40.50 it delivers a payload that whips out your pc on december 25 it all so sends its self out by emailing other pc's along with delivering other types of worms the best thing i can say is get mcafee and it will get rid of that little butthole

I just installed a firewall in my computer. I have 3 computers here on a network. all 3 have that wininit.exe file in the windows directory. are yous really sure that is a backdoor and not a windows program? because I took it out of the registry.

there are 2 wininit.exe files. one under c:\windows\ and one under c:\windows\system\. the one under system is the backdoor.
I don't know if this will work or not, but I'm just going to take it out of my registory, and delete it.
good luck everyone :-)

The virus in wininit.exe attempts to use cycles of your processor when you aren't. It is part of a "distributed net" contest. The winner has control of the most cpu's. Delete wininit.exe and re-install a clean copy. Rename vnbt.386 to disable a hidden printer share created by W9x when printers are shared on a W98 LAN.

I talked to microsoft and they said to rename the file from wininit.exe to wininit.xxx. This doesn't delete the file, but it renders it ineffective. If you can't change the file in windows, go to Dos and type ren wininit.exe wininit.xxx in the C:\WINDOWS\SYSTEM directory.

I just posted a url on this site at another thread...
http://www.zdnet.com/filters/printerfriendly/0,6061,2662809-77,00.html
thats a thourough method....don't delete the wininit.exe in C:\Windows...only the one in c:Windows\System!!!!!

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |