Very odd - userinit.exe suddenly a start up program? What's going on?

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

rabidbob

Thread Starter
Joined
Apr 4, 2010
Messages
2
Hello everyone,

I've been a bit foolish and impatient recently and I ran something (self extracting zip) from the internet I probably shouldn't have; while it was extracting WinPatrol popped up with a new program alert "WinLogon:UserInit" from the system32 directory (userinit.exe). I said to myself "Self, that's very odd, why would it suddenly want to run that executable at start up a month after installing windows?" So I downloaded Hijack this and ran it, but there's nothing that leaps out at me as suspicious - but I've not accepted (or denied) userinit.exe as a start up program and I've not rebooted either (in fact the winpatrol alert is still open!). I have scanned the file with Malware Bytes and AVG and it comes up clean in both of them, but I'm not sure if they'd pick up anything if there was a call from the exe to another file which did have malicious code in it. I'm mostly tempted to deny it running as a start up program and do a full scan with AVG and Malware Bytes, but I wanted an expert to cast their eye over the HiJack This log first if that's ok?

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 13:38:09, on 04/04/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files (x86)\n52te\razerhid.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\n52te\razertra.exe
C:\Program Files (x86)\TextPad 5\TextPad.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Jomantha] C:\Program Files (x86)\n52te\razerhid.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11FB60B8-E21A-4A9F-8F65-3690205F0BB5}: NameServer = 192.168.1.254
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8269 bytes
 

rabidbob

Thread Starter
Joined
Apr 4, 2010
Messages
2
I looked at the registry entry for userinit.exe and there's nothing malicious tagged on to the end of the reg entry. Then I found a SHA-1 checksum for userinit.exe (from: https://www.faultwire.com/file_detail/userinit.exe*28342.html ) and checked against that - checksums match so it can't have been altered, and I've allowed it. I'm not sure what's going on still with WinPatrol alerting because of it and I'm still suspicious, so if there's anything untoward in my hijack this log please let me know! I'm unsure how to 100% check my PC is clean ... I'm guessing if I reboot in safe mode, something like a root kit will still execute?
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top