Avast Found Rootkit - TrustedInstaller.exe

Page 1 of 3 123 LastLast

  1. Posts : 101
    Win7
       #1

    Avast Found Rootkit - TrustedInstaller.exe


    I have a 2 day old install has had limited Internet contact to only install updates and AV/Firewall/Malware software. Avast prompted me with a Rootkit Found message pointing to C:\Windows\servicing\TrustedInstaller.exe. I ran Avast and Emsisoft Anti-Malware on the file in that location showing it is clean. My guess is that this is a false positive. Is anyone else aware of this notification? My work PC with Win 7 has this file as well, but I am running MSE on that machine.

    Thanks!
      My Computer


  2. Posts : 5,642
    Windows 10 Pro (x64)
       #2

    There is suppose to be said file on Windows. Maybe take a copy of the file and send it up to VirusTotal.com and have it checked.
      My Computer


  3. Posts : 101
    Win7
    Thread Starter
       #3

    Thanks for the link! I got the following results:

    File has already been analysed:


    MD5: 840f7fb849f5887a49ba18c13b2da920 First received: 2009.08.26 17:49:21 UTC Date: 2010.05.27 20:16:22 UTC [<1D] Results: 0/41
    I assume that this means that 0 out of the 41 AV engines found this to be a dangerous file? Not sure if it was also able to use the MD5 to compare with MS.

    Thanks,
      My Computer


  4. Posts : 5,642
    Windows 10 Pro (x64)
       #4

    0/41 means 0 of the 41 AVs flagged this file as dangerous....meaning it is safe.
      My Computer


  5. Posts : 1
    Windows 7 Ultimate
       #5

    Tell Avast to ignore that warning, or you won't be able to install any updates at all.

    Avast seems to consider the TrustedInstaller (which is actually a hidden user account installed by windows update the first time you use it) as a rootkit since it tempers with critical system components and change the behavior of your windows OS. We can't assume it as a false positive, in fact the TrustedInstaller IS a rootkit, but not in the sense of a malicious one. It should be ignored and placed in the list of trusted software in most anti-virus software.

    One of the drawbacks of that kind of detection, you never know if it is the real TrustedInstaller or a malicious one. If you receive the message only when you try to install software and especially updates, it should be safe to ignore the message. Otherwise, make sure that the message is not related to some malicious software that would make itself look as if it was the real TrustedInstaller. You should pay more attention especially when installing third party software that no one knows about, that could temper with critical system files. It could potentially hide malicious software that could compromise your Windows 7 installation.
      My Computer


  6. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #6

    Good post, Warhammer.
      My Computer


  7. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #7

    CarlTR6 said:
    Good post, Warhammer.
    Agreed!
      My Computer


  8. Posts : 39
    Windows 7 Home Premium 64-bit
       #8

    I deleted mine... could someone please upload a copy of trustedinstaller.exe for Windows 7 Home Premium 64-bit?
      My Computer


  9. Posts : 18,404
    Windows 7 Ultimate x64 SP1
       #9

    Why did you delete it? It's an important system component.

    Run sfc/scannow with an elevated cmd prompt.
      My Computer


  10. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #10

    RockStar21 said:
    I deleted mine... could someone please upload a copy of trustedinstaller.exe for Windows 7 Home Premium 64-bit?
    Welcome to the forum, RockStar. A word of advice - don't mess with Windows system files.
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:46.
Find Us