userinit.exe

honey

The executable userinit.exe has been detected as malware by 4 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘userinit’.
Product:
honey

Version:
1.00

MD5:
1ad4b03f553c761a08ff1ddf88b72b9b

SHA-1:
61931ccab9dfc83e6f01a93f30e9f5210c101ac4

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/1/2025 8:23:56 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Legacy.Trojan.Agent-1388588
0.98/23209

Dr.Web
Win32.HLLW.Autoruner1.33621
9.0.1.05190

F-Secure
Trojan.Heur.Qy0frz9ZTamib
5.16.24

Kaspersky
Worm.Win32.AutoRun
15.0.2.529

File size:
686.8 KB (703,232 bytes)

Product version:
1.00

Original file name:
honey.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\userinit.exe

File PE Metadata
Compilation timestamp:
5/1/1998 8:15:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2AA8

Entry point:
B8, D4, 1F, 44, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 8F, 72, 12, BB, 5B, 9D, 2B, 0E, 1F, C0, E7, 62, 55, 1A, E6, 2E, CA, CA, 24, C5, 45, AB, D8, 25, B8, A7, E8, C8, F8, 86, 77, 8F, 1A, 84, 8A, 3C, 6A, D0, C4, 15, 6D, 6D, F0, 77, 42, 04, B7, 13, A8, 9E, 0A, 50, D2, C6, BD, 58, A3, FF, D3, 58, 66, DF, 91, 1C, 0A, EC, 09, F9, 76, A4, BA, 18, 8F, 07, 43, DF, EE, 7C, F1, 45, 98, 22, C8, AA, D6, 12, 76, 6D, 1C, 3B, F5, AE, 72...
 
[+]

Entropy:
3.1099

Packer / compiler:
PECompact v2

Code size:
172 KB (176,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
userinit

Command:
C:\windows\userinit.exe


Remove userinit.exe - Powered by Reason Core Security