Associated Malware Groups
The filename is associated with the malware group:
File Behavior
USERINI .EXE has been seen to perform the following behavior:
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Modifies System Runtime Policies to limit system usability
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Can communicate with other computer systems using HTTP protocols
- Sends email using SMTP protocols
- Executes a Process
- Creates or uses a background service to access the Internet using HTTP protocols
- Injects code into other processes
- Found on infected systems and resists interrogation by security products
USERINI .EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
- Terminated as a Process
Country Of Origin
The filename USERINI .EXE was first seen on Nov 5 2009 in the following geographical regions of the Prevx community:
- Europe on Nov 5 2009
- Thailand on Nov 5 2009
- Netherlands on Mar 7 2010
- Hungary on Mar 7 2010
- Vietnam on Mar 21 2010
- The United Kingdom on Mar 21 2010
File Name Aliases
USERINI .EXE can also use the following file names:
- EXPLORER.EXE:USERINI.EXE
- UPDATE870578.EXE
- USERINI.EXE
- UPDATE1904348.EXE
- UPDATE44790609.EXE
- UPDATE12296625.EXE
- UPDATE8283750.EXE
- UPDATE8354218.EXE
- UPDATE231396609.EXE
- USERINI.EXE.BAK
- UPDATE3509109.EXE
- ILMVM.EXE
- HLTT.EXE
- SAECST.EXE
- INUOO.EXE
Filesizes
The following file size has been seen:
- 43,008 bytes
- 21,504 bytes
- 22,528 bytes
File Type
The filename USERINI .EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.