I recently got spyware called "Antivirus Soft". After getting rid of it as far as I'm aware of, I've been getting a constant registry change for my winlogon. The entry is UserInit, old data userinit.exe and new data is C:\Windows\SysWOW64\Userinit.exe. I've been reading forums and I understand this is a normal process, but after getting this spyware I turned on paranoid mode so I have no previous knowledge of this registry change. I deny just cause I don't want it to end up being the spyware trying to get going again. I've read that this can be spyware, since this process doesn't happen except at logon, and its trying to replace the data. If any of this is confusing or you need more information I'll be glad to answer, until then I'll keep denying this change. One other thing is when I deny the change another one pops up saying its value was deleted and the entry is shell with old data being explorer.exe and no new data.