Avast Found Rootkit - TrustedInstaller.exe

Thanks guys for the suggestions. Copied the trustedinstaller.exe profdlp uploaded to the servicing folder and everything seems to be working fine. Ran sfc and did not find any integrity violations. So big thanks to profdlp for the upload and everyone else for their input!!

Best Regards,
RS21

That is good news! Glad you solved the problem. Thanks for reporting back.
 

My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
I have the same problem, by proxy. I'm helping a friend try to restore TustedInstaller to their new Windows 7 Home Premium 64Bit machine after they deleted it using Avast. I found the same solution as is posted here, for Vista machines, and tried it. However the step of just copying it into the servicing folder failed miserably for me. I'm not a Windows 7 expert, or even that familiar, but I consider myself to be competent for a non-IT user.

I had no luck accessing the servicing folder. No matter what approach I took, access was denied. I could not copy and paste the copy of TrustedInstaller into the folder. The root admin account was similarly locked out which I found surprising. I suspect there is a simple step I didn't try (eg. turning off read only, or changing permissions for the folder, both of which I tried). It would be very helpfull if Rockstar posted how this is accomplished, or if someone else could.

Fortunately, we're prepared for a full restore approach, so we should be fine. However it would be great for future Avast users on Win7 if we could get all of the instructions in one thread. My experience of finding half finshed threads and solutions was very frustrating.
 

My Computer

OS
Windows 7 Home Premium 64 bit
I deleted mine... could someone please upload a copy of trustedinstaller.exe for Windows 7 Home Premium 64-bit?
This is a good example of why I reccomend creating a restore point before you make any changes to your system be it installing a new program or whatever.
It just makes it so much easier to get your system back to where it was before.
I do it before I download a new program, then I scan the program with MSE or Avast or both then I install it. if I decide I no longer want it i can uninstall it then restore my system back to where it was.
I know this doesn't help you now but might want to try it in the future.
I'm not sure it would restore deleted system files. Hope you can get it sorted out without to much trouble but their is a lesson to be learned here, some are harder than others, but learned none the less. Fabe
 

My Computer

Computer Manufacturer/Model Number
Self Built
OS
Windows 7 ultimate 64 bit / XP Home sp3
CPU
intel Core 2 Duo E8400 3.0ghz
Motherboard
Asus P5ND bios 1401
Memory
8 gigs 1066 OCZ Fata1ty
Graphics Card(s)
EVGA GTX 580 Call of Duty Black Ops Edition
Sound Card
Creative Soundblaster Audigy 2zs
Monitor(s) Displays
Asus 24in LCD's 2MS X2
Screen Resolution
1920x1080p @60Hz
Hard Drives
WD Caviar 500 Black/ WD Caviar 200 Blue
PSU
OCZ 700W GameXtreme
Case
NZXT Apollo
Cooling
Corsair H50 CPU/120mm x3 /60mm x2 /Corsair Dominator Ram
Keyboard
Logitech Bluetooth Wireless MX5000
Mouse
Logitech Bluetooth Wireless MX1000
Internet Speed
Download 19.83 Upload 0.97
Other Info
Logitech Z2300 Speakers/ Bose Noise Cancelling Headphones/Avermedia PCI-e Hybrid TV Bravo/Epson NX415 all in one/ 4 Port Powered USB Hub/ LG 10x Bluray Burner /TSST Corp DVDRW External
...I suspect there is a simple step I didn't try (eg. turning off read only, or changing permissions for the folder, both of which I tried)...
You can try using TakeOwn, unless that's one of the things that didn't work, of course. I'd just use it on the servicing folder located in C:\Windows\servicing.

Run the program and it will give you a new option to take ownership when you right-click a file or folder.

Don't go wild with it and try to take ownership of an entire drive or your whole Windows folder or something. I made that mistake during the Win7 beta period and regretted it. :o
 

Attachments

My Computer

Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
There is no need to go though that. Every single file the system needs is already extracted to C:\Windows\Winsxs
:doh: That's true. Didn't have my thinking head on!
Mine is in C:\Windows\winsxs\amd64_microsoft-windows-trustedinstaller_31bf3856ad364e35_6.1.7600.16385_none_ed02252b66d7bca2
 
Last edited:

My Computer

OS
Windows 7 x64
A while back Avast! gave me the same report. After the next definition update it was fine. Guess they tweaked the definitions and it was causing a false positive.

Jim :geek:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
Back
Top