1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Very odd - userinit.exe suddenly a start up program? What's going on?

Discussion in 'Virus & Other Malware Removal' started by rabidbob, Apr 4, 2010.

Thread Status:
Not open for further replies.
  1. rabidbob

    rabidbob Thread Starter

    Joined:
    Apr 4, 2010
    Messages:
    2
    Hello everyone,

    I've been a bit foolish and impatient recently and I ran something (self extracting zip) from the internet I probably shouldn't have; while it was extracting WinPatrol popped up with a new program alert "WinLogon:UserInit" from the system32 directory (userinit.exe). I said to myself "Self, that's very odd, why would it suddenly want to run that executable at start up a month after installing windows?" So I downloaded Hijack this and ran it, but there's nothing that leaps out at me as suspicious - but I've not accepted (or denied) userinit.exe as a start up program and I've not rebooted either (in fact the winpatrol alert is still open!). I have scanned the file with Malware Bytes and AVG and it comes up clean in both of them, but I'm not sure if they'd pick up anything if there was a call from the exe to another file which did have malicious code in it. I'm mostly tempted to deny it running as a start up program and do a full scan with AVG and Malware Bytes, but I wanted an expert to cast their eye over the HiJack This log first if that's ok?

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 13:38:09, on 04/04/2010
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Steam\Steam.exe
    C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files (x86)\n52te\razerhid.exe
    C:\Program Files (x86)\AVG\AVG9\avgtray.exe
    C:\Program Files (x86)\n52te\razertra.exe
    C:\Program Files (x86)\TextPad 5\TextPad.exe
    C:\Windows\SysWOW64\NOTEPAD.EXE
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mitch\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\TrendMicro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKLM\..\Run: [Jomantha] C:\Program Files (x86)\n52te\razerhid.exe
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O13 - Gopher Prefix:
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{11FB60B8-E21A-4A9F-8F65-3690205F0BB5}: NameServer = 192.168.1.254
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 8269 bytes
     
  2. rabidbob

    rabidbob Thread Starter

    Joined:
    Apr 4, 2010
    Messages:
    2
    I looked at the registry entry for userinit.exe and there's nothing malicious tagged on to the end of the reg entry. Then I found a SHA-1 checksum for userinit.exe (from: https://www.faultwire.com/file_detail/userinit.exe*28342.html ) and checked against that - checksums match so it can't have been altered, and I've allowed it. I'm not sure what's going on still with WinPatrol alerting because of it and I'm still suspicious, so if there's anything untoward in my hijack this log please let me know! I'm unsure how to 100% check my PC is clean ... I'm guessing if I reboot in safe mode, something like a root kit will still execute?
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/914638

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice