After scanning my computer with Malwarebytes, I got the following report: Elementi dato del registro infetti: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. If I scan the system again I find no further problems. After re-booting the system, I get again the same report. Elementi dato del registro infetti: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. Is it a false positive of the program or the program is not scanning the author of the modifications of the register? I've tryed also Kasper with the following results: C:\WINDOWS\system32\userinit.exe Infected: Exploit.Win32.IMG-WMF.hu 1 Thank you for your support!