PC Pitstop is the undisputed leader in PC diagnostics. Our running process library is culled from our database of over 100 million PC diagnostics and scans.

Tip from the PitCrew

Every process running on your computer takes up CPU cycles and valuable memory. For optimal PC performance and resource utilization, you should be aware of every process on your computer. PC Pitstop designed this process library to help you know which processes are worthwhile and others that slow system performance.

Furthermore, perhaps the quickest and most straight forward method to detect malware is through a running process analysis.

Process Library

  

More than one possible match was found; all matches are listed below in order of their prevalence. This only tells you what the file and the correct action might be.

To understand which possibility is actually running on your own system, perform an Overdrive test and then look at the Software|Processes tab.


Match #1

userinit.exe (userinit.exe)

Percentage of recently scanned PC's with this process running: 0.00%
Average CPU use for this program: 0%
Average RAM for this program: 4 MB


PC Pitstop Analysis

userinit.exe - This is a key process to the Windows operating system. It manages the different start up sequences on boot-up. It establishes network connections and the Windows shell. Userinit.exe is important to the stable and secure operation of your computer and should not be terminated. The correct filepath is C:\Windows\System32\Userinit.exe,. Note the comma at the end of the file path is required. Please note that userinit.exe is also listed as a trojan. This threat can go under as many as 10 different file names. It has been classified as Haxdoor.Fam, Win32.Bagle.M@mm, and Worm.Win32.Feebs.df


Recommendation

Win Patrol

userinit.exe is an essential part of Windows and required for Windows to work properly. It should never be disabled.

PC Pitstop recommends WinPatrol Plus for monitoring all of the background activity on your PC. WinPatrol Plus provides a easy to understand descriptions of over 15,000 processes and programs.



Identification

In addition to the file name, userinit.exe, the following version information is used to identify the file. If the file does not match this information, it may be a different file. To ensure the file is absolutely correct, run a free and comprehensive scan.

Vendor contains:Microsoft
Product contains:Microsoft

To view version information with Windows Explorer, right-click the file and click Properties, Version.


MD5 Hashes

MD5 hashes is the way that computers can define the uniqueness of a file. Anti malware vendors frequently use this technique to detect and clean malware. It is common for a program to have multiple MD5 hashes as the developers create newer versions of the program. For the program called userinit.exe, we have detected more than 20 different MD5 hashes. Click on a hash to research the hash in Google.
MD5 Report Summary
Program NameMD5 Count
userinit.exe> 20
#MD5Size
10xd6fc61a4f0e2c0a79ac0f46b9d205fe114542 bytes
20xe2f70e6b3700201b59c0cb176de275f524576 bytes
30xe931e0a2b8bf0019db902e98d03662cb22016 bytes
40x39b1ffb03c2296323832acbae50d2aff24576 bytes
50xde7a0ee4a6a28e6dfe3118eb22468da624576 bytes
60xe7fa45622ea5f16c9bc7379591262b2526112 bytes
70x4f4d622074ce2545ca44405be7cbf4ca68856 bytes
80xcaed6da103f0d57d87c627bb18bca4fe70144 bytes
90x76c24631dce6a6b4f13e82246394445c72704 bytes
100x78a5351f732f7d019ac982ecb97897fc71680 bytes
110x29a1877f2d0eacff20b6507a3c00f31b26112 bytes
120x01aa3c7eaf00d2937df72e9613bfa57a400896 bytes
130x908d00140127d0bfe8120c34f0f40ca224576 bytes
140x813b2e9c4caea05fba51a442fab7a95d26112 bytes
150x5f788cd477c0f61f1d52503b7b3793aa71680 bytes
160x783ef47b794fb521c18668e8c7d7ff0c72704 bytes
170x836f7960362ff95c5d49e40b891f2cfc24576 bytes
180x0e135526e9785d085bcd9aede6fbcbf925088 bytes
190xa93aee1928a9d7ce3e16d24ec7380f8926112 bytes
200x585398603f570f9705774d65d292e5d121504 bytes

PC Pitstop Database Comparisons

Every week, we update our information about the running programs identified during the previous week's testing. userinit.exe (userinit.exe) has been seen on 0.00% of systems tested at PC Pitstop. As a point of comparison, it is rare for a particular malicious program (virus or spyware) to be seen on more than one or two percent of all systems tested. The average RAM memory usage for this process was 4 MB. The average CPU load for this program was 0%.


Detailed Description and/or Removal Instructions

http://support.microsoft.com/kb/892893


Match #2

userinit.exe (Win32/Satiloler.A)

This program has not been seen on any systems tested at PC Pitstop in the past week.


PC Pitstop Analysis

userinit.exe - According to CA:

Win32/Satiloler.A is a backdoor trojan that allows an attacker to collect information from a user's system.


Recommendation

CA AntiVirus

userinit.exe is a VIRUS. Stop all work until the virus is removed or you run the risk of spreading the virus to other people. Worse yet, the virus may be doing harm to your computer and your information.

userinit.exe is a virus and should be removed immediately to avoid doing further harm. PC Pitstop recommends CA Antivirus in these types of situations.



Identification

The file name alone identifies this program.


MD5 Hashes

MD5 hashes is the way that computers can define the uniqueness of a file. Anti malware vendors frequently use this technique to detect and clean malware. It is common for a program to have multiple MD5 hashes as the developers create newer versions of the program. For the program called userinit.exe, we have detected more than 20 different MD5 hashes. Click on a hash to research the hash in Google.
MD5 Report Summary
Program NameMD5 Count
userinit.exe> 20
#MD5Size
10x9a7f725a8961ea7a16a597a7ca126121112128 bytes
20xba17d26745f617d02ad49f48004395f4121856 bytes
30x393ea54e69df326ac1e25e4e976a92df33056 bytes
40x213eb9e102049cd43db47de02c1e3aa582432 bytes
50x78773f3ee7fcf1690d2f9ff6180a26b132120 bytes
60x81c199973a5576af6afda78012e53af382432 bytes
70x7d30c0f3dfa91420d4d8ad46aa8ef78382432 bytes
80x5a1a0fc00c570e1b87e84df80ea5d43a82432 bytes
90xfc3e63758ce17f865983a9cbf49d70ac82432 bytes
100xb5bfcf3c4dfe120d2bb0f9736a17c06557344 bytes
110x809c3456b9a920fc829a2de5929508cf82944 bytes
120x6771911db01de15fc3e13b5d5be5018682944 bytes
130x3fc661b30c43ac93f471cc4d39cf64d534816 bytes
140xb2ff7ac76062c5379fddc52c1690ea8c112128 bytes
150x9ecbf66ccb8abfa8626bbe977c8bfad982944 bytes
160x6650127763064bc3a33de95da25cb5fc41984 bytes
170x5e136b0441e38b1d50839c1ee670521583968 bytes
180x0e73fa40abe58227f047d9a113ddc483120832 bytes
190xa94b21519626833b8fff023aa4011d4082944 bytes
200x79e1042564f9344e8f494aac5fcbf595114688 bytes

PC Pitstop Database Comparisons

Every week, we update our information about the running programs identified during the previous week's testing. This program has not been seen on any systems tested at PC Pitstop in the past week.


Vendor or Distributor's Web Site

http://search.ca.com/search/ca?style=en&search_button=Search&qt=userinit.exe&col=

Detailed Description and/or Removal Instructions

http://www.ca.com/securityadvisor/virusinfo/virus.aspx?id=58501

Important note: A file name alone may not be enough for positive identification. PC Pitstop's Overdrive tests and spyware scan use information such as the company name, product name, or install directory. If you are unable to identify a file, ask about it in our forums after running our full tests.