Avast Found Rootkit - TrustedInstaller.exe

seag33k

New member
Member
VIP
Local time
4:23 PM
Messages
101
I have a 2 day old install has had limited Internet contact to only install updates and AV/Firewall/Malware software. Avast prompted me with a Rootkit Found message pointing to C:\Windows\servicing\TrustedInstaller.exe. I ran Avast and Emsisoft Anti-Malware on the file in that location showing it is clean. My guess is that this is a false positive. Is anyone else aware of this notification? My work PC with Win 7 has this file as well, but I am running MSE on that machine.

Thanks!
 

My Computer

Computer Manufacturer/Model Number
ASUS N61JQ-A1
OS
Win7
CPU
Intel Core i7
Memory
4 GB
Graphics Card(s)
ATI 5730
Internet Speed
http://www.speedtest.net/result/823059694.png
There is suppose to be said file on Windows. Maybe take a copy of the file and send it up to VirusTotal.com and have it checked.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Thanks for the link! I got the following results:

File has already been analysed:


MD5: 840f7fb849f5887a49ba18c13b2da920 First received: 2009.08.26 17:49:21 UTC Date: 2010.05.27 20:16:22 UTC [<1D] Results: 0/41
I assume that this means that 0 out of the 41 AV engines found this to be a dangerous file? Not sure if it was also able to use the MD5 to compare with MS.

Thanks,
 

My Computer

Computer Manufacturer/Model Number
ASUS N61JQ-A1
OS
Win7
CPU
Intel Core i7
Memory
4 GB
Graphics Card(s)
ATI 5730
Internet Speed
http://www.speedtest.net/result/823059694.png
0/41 means 0 of the 41 AVs flagged this file as dangerous....meaning it is safe.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Tell Avast to ignore that warning, or you won't be able to install any updates at all.

Avast seems to consider the TrustedInstaller (which is actually a hidden user account installed by windows update the first time you use it) as a rootkit since it tempers with critical system components and change the behavior of your windows OS. We can't assume it as a false positive, in fact the TrustedInstaller IS a rootkit, but not in the sense of a malicious one. It should be ignored and placed in the list of trusted software in most anti-virus software.

One of the drawbacks of that kind of detection, you never know if it is the real TrustedInstaller or a malicious one. If you receive the message only when you try to install software and especially updates, it should be safe to ignore the message. Otherwise, make sure that the message is not related to some malicious software that would make itself look as if it was the real TrustedInstaller. You should pay more attention especially when installing third party software that no one knows about, that could temper with critical system files. It could potentially hide malicious software that could compromise your Windows 7 installation.
 

My Computer

OS
Windows 7 Ultimate
CPU
Phenom II 965 BE C2 Stepping AMD CPU
Motherboard
Asus M4A79XTD EVO AMD mobo
Memory
2x2GB KVR CL9 memory
Graphics Card(s)
EVGA GeForce 9800 GTX+
Monitor(s) Displays
ViewSonic 22" WS 1680x1050 Display
Hard Drives
2x500 GB WD Caviar Green
1x250 GB WD Caviar Blue
PSU
Corsair TX750
Case
ThermalTake Armor 8003BWS
Cooling
Zalman CNPS 10X Flex with 120 mm CoolerMaster Fan
Good post, Warhammer.
 

My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
I deleted mine... could someone please upload a copy of trustedinstaller.exe for Windows 7 Home Premium 64-bit?
 

My Computer

Computer Manufacturer/Model Number
Asus UX50V
OS
Windows 7 Home Premium 64-bit
CPU
Intel® Core™2 Duo Processor SU9600 1.6 GHz
Motherboard
Asus 60-NVLMB1200-C14
Memory
4GB SDRAM
Graphics Card(s)
NVIDIA® GeForce® G 105M
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
15.6" HD LED backlight, Color-Shine
Screen Resolution
1366x768
Hard Drives
2.5" 9.5mm SATA 500GB
Why did you delete it? It's an important system component.

Run sfc/scannow with an elevated cmd prompt.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
I deleted mine... could someone please upload a copy of trustedinstaller.exe for Windows 7 Home Premium 64-bit?

Welcome to the forum, RockStar. A word of advice - don't mess with Windows system files.
 

My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
Avast prompted me to and like a fool I followed the recommended action.
 

My Computer

Computer Manufacturer/Model Number
Asus UX50V
OS
Windows 7 Home Premium 64-bit
CPU
Intel® Core™2 Duo Processor SU9600 1.6 GHz
Motherboard
Asus 60-NVLMB1200-C14
Memory
4GB SDRAM
Graphics Card(s)
NVIDIA® GeForce® G 105M
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
15.6" HD LED backlight, Color-Shine
Screen Resolution
1366x768
Hard Drives
2.5" 9.5mm SATA 500GB
Tried sfc /scannow... got the following message.

"Another servicing or repair operation is currently running. Wait for this to finish and run sfc again."

I also noticed that Windows Modules Installer is not listed under services.
 

My Computer

Computer Manufacturer/Model Number
Asus UX50V
OS
Windows 7 Home Premium 64-bit
CPU
Intel® Core™2 Duo Processor SU9600 1.6 GHz
Motherboard
Asus 60-NVLMB1200-C14
Memory
4GB SDRAM
Graphics Card(s)
NVIDIA® GeForce® G 105M
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
15.6" HD LED backlight, Color-Shine
Screen Resolution
1366x768
Hard Drives
2.5" 9.5mm SATA 500GB
Strange. maybe you could reboot, and try it again.

Can you do a system restore to before you deleted it?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
Tried rebooting, tried safe mode... same message.

Unfortunately, before I realized I had a problem... I deleted my restore points.
 

My Computer

Computer Manufacturer/Model Number
Asus UX50V
OS
Windows 7 Home Premium 64-bit
CPU
Intel® Core™2 Duo Processor SU9600 1.6 GHz
Motherboard
Asus 60-NVLMB1200-C14
Memory
4GB SDRAM
Graphics Card(s)
NVIDIA® GeForce® G 105M
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
15.6" HD LED backlight, Color-Shine
Screen Resolution
1366x768
Hard Drives
2.5" 9.5mm SATA 500GB
This is from Win 7 Home Premium 64-Bit. Not sure if that matters. (Except probably the 64-Bit part.) I'd use it only as a last resort if the SFC gets you nowhere.

Use at your own risk! :shock:
 

Attachments

My Computer

Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable

My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
Cab Files

Isn't there a convention to extract files from the cabs on the install disk. It used to run in a dos box (probably elevated)?
 

My Computer

Computer Manufacturer/Model Number
BGC (Bob's Garage Crew)
OS
win 7 X64 Ultimate SP1
CPU
I3770K
Motherboard
Asus P8Z77-V Deluxe
Memory
G Skill F3-14900CL9-4GBXL x 4
Graphics Card(s)
NVIDIA GeForce GTX670 + Intel 4000
Sound Card
Realtek HD 5.1 (MOB)
Monitor(s) Displays
Asus VW224T (1)
Screen Resolution
1920 x 1080
Hard Drives
SATA Corsair Force GT 2.5" 180GB (System) Sata 3
OCZ Vertex3 120GB
OCZ Vertex 2 120GB 2.5" SATA II
ST31000524AS 1000.2GB
WD15EARS (External)
PSU
CoolerMaster 1000 Watt
Case
CoolerMaster HAF X
Cooling
CPU -- CoolerMaster 520N
Keyboard
MS Wireless 3000 V2
Mouse
MS Wireless 3000 V2
Internet Speed
Cable
Antivirus
Norton Internet Security
Browser
IE9
Other Info
AMI Bios 1805
OC'd 3%
Thanks guys for the suggestions. Copied the trustedinstaller.exe profdlp uploaded to the servicing folder and everything seems to be working fine. Ran sfc and did not find any integrity violations. So big thanks to profdlp for the upload and everyone else for their input!!

Best Regards,
RS21
 

My Computer

Computer Manufacturer/Model Number
Asus UX50V
OS
Windows 7 Home Premium 64-bit
CPU
Intel® Core™2 Duo Processor SU9600 1.6 GHz
Motherboard
Asus 60-NVLMB1200-C14
Memory
4GB SDRAM
Graphics Card(s)
NVIDIA® GeForce® G 105M
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
15.6" HD LED backlight, Color-Shine
Screen Resolution
1366x768
Hard Drives
2.5" 9.5mm SATA 500GB

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Back
Top