Forum Home
Press F1
 
Thread ID: 136534 2014-03-11 19:44:00 Trovigo problem lakewoodlady (103) Press F1
Post ID Timestamp Content User
1369983 2014-03-11 19:44:00 A friend's XP computer has got the Trovigo browser hijacker on it. I am going there today to get rid of it for her and will run AdWcleaner, JRT and Malwarebytes.
Is it better to run these in safe mode, or in normal?

Cheers, LL
lakewoodlady (103)
1369984 2014-03-11 19:53:00 If it doesnt go away in normal windows boot into safe mode and scan again. Looks like this can get installed, with free software. And the user downloaded free software / didnt do a custom install. And it installed

There maybe an entry in add/remove programs. If it's there uninstall it first then delete / disable the toolbars, in whatever browser. Then do a scan

If they use IE reset the homepage / reset settings
Speedy Gonzales (78)
1369985 2014-03-11 20:03:00 If it doesnt go away in normal windows boot into safe mode and scan again. Looks like this can get installed, with free software. And the user downloaded free software / didnt do a custom install. And it installed

There maybe an entry in add/remove programs. If it's there uninstall it first then delete / disable the toolbars, in whatever browser. Then do a scan

If they use IE reset the homepage / reset settings


Thanks Speedy, yes she downloaded Chrome and did not untick some boxes. It has no entry in Add/Remove Programs, that I could tell.

LL
lakewoodlady (103)
1369986 2014-03-11 20:09:00 Did the user get Chrome from the Google site. Avoid getting ANYTHING from Cnet or download.com. Cnet puts malware into some of their downloads. Speedy Gonzales (78)
1369987 2014-03-11 21:50:00 Avoid getting ANYTHING from Cnet or download.com. Cnet puts malware into some of their downloads.

Same with SourceForge .
Stupid thing is, MalwareBytes lists Cnet as a trusted Partner for Downloads :horrified Definitely giving the wrong message even if the Mbytes installer is clean.
Sites like that also try & trick you into clicking on the wrong button. About time they were shut down .

You can go into Internet setup & manually disable IE addons/search providers. With Chrome, hunt around in the settings/options to disable addons & search engines/providers .
1101 (13337)
1369988 2014-03-11 22:05:00 I managed to get rid of all the Trovigo nasties using all the instructions from MalwareTips!
Seems all ok now.

LL
lakewoodlady (103)
1