Trovi Virus - help to remove please

Tousdae

New member
Member
VIP
Local time
12:44 AM
Messages
351
I don't know where I picked this up but it's attached to my Chrome. I followed some directions for regedit to try to get rid of it. It's still here. Please help.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Would you happen to know a way I could find out if I still have the virus? It attached to Chrome. Everytime I tried to open Chrome I'd get Trovi windows. I uninstalled Chrome so now I can't tell if I still have the virus.

I'm looking thru the directions and I did use "AdwCleaner" yesterday. I'm still going to follow your directions. I just have no idea if I'm still infected or not.

Thank you
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
Did you follow fully the removal guide which Bill posted earlier?

Then if a full scan with your AV, Malwarebytes and SUPERAntiSpyware - Downloads finds nothing then you should be OK.

Monitor your browser Add-On's to make sure nothing is in there except Flash, Silverlight and a Reader. No Search services except Google in the stable browser Search box or Omnibox where it cannot spy unless it's Chrome which is spyware to begin with - like all installed and signed-in Google.

Those who get chronically infected I recommend should buy the real time protection of MBAM in addition to their lightweight AV like MSE - at $29 for life I've never had anyone get reinfected again.

After reboot test again and when all scans show clear run SFC /SCANNOW Command to see if System files were damaged.

If so then I'd strongly consider reinstalling following these same steps compiling everything that works best in tens of thousands of installs we've directly helped with here: Clean Reinstall - Factory OEM Windows 7

If not then monitor performance to decide if you need to reinstall because infection shows lingering effects.

Then it depends on how performance goes
 
Last edited:
Would you happen to know a way I could find out if I still have the virus? It attached to Chrome. Everytime I tried to open Chrome I'd get Trovi windows. I uninstalled Chrome so now I can't tell if I still have the virus.

I'm looking thru the directions and I did use "AdwCleaner" yesterday. I'm still going to follow your directions. I just have no idea if I'm still infected or not.

Thank you

If you have not followed the removal guide, then your machine is still infected.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Please download AdwCleaner by Xplode and save to your Desktop.
Step 1.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


Step 2.
Using AdwCleaner v3: Scan & Clean:
This time click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
Copy and paste the contents of that logfile in your next reply.
A copy of that logfile will also be saved in the C:\AdwCleaner folder


******Post both .txt logs
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
:D I seem to be fine now! Thank you for your responses!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
I did the best I could. When I was done I ran the scans as you suggested. I used Malwarebytes, spybot, and that adwcleaner and nothing turned up. There was nothing in add-on's that was out of the ordinary. :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
Spybot is 7-8 years out of favor and has never been recommended here in our five years as top tech forums. Use SUPERAntiSpyware - Downloads real time scanner (decline trial) then remove it from startup programs.
 
Thanks for the tip. I will check it out in 5. I still have this stinkin Trovi. I reinstalled Chrome becuz it plays best with FB games and there it was. I'm currently backing up the pc and I'm just going to do a reinstall of windows. You see how confused I get so I think this is my best option. Incredible that I picked this up by trying to download the right memory test thingy. How's that for ironic. smh
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
Speaking of memory test thing, I bought a new video card and a bigger power supply (since my 350 couldn't support the new card) and no more black screen.

Whoa ... those are some steps! ... ok :( lol

Do I need to copy over the App Data folder to put back on the clean install?

Thanks :)
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
Thanks!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
... I reinstalled windows twice. Both time Trovi is here. ... wth!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Possibly your Windows disk/image is corrupted with the malware, or there's a possibility that you have a rootkit, which can survive a clean install in some instances. Did you make the Windows disk/image on a clean PC? If you made it on the infected one, the image could become corrupted.

It also wouldn't hurt to run TDSSKiller just to be sure.

When running TDSSKiller, launch the program, click on the blue text "Change Parameters" & check the box marked "Detect TDLFS File system." Click OK & then run the scan.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
I've begun the process.

Last night after a clean install when I looked in the C drive it had items in there that have been long deleted. I never got a chance to put anything back on the pc so, I'm really confused about this.

Back to the tutorial. Thanks. I'm actually following along for now lol :o
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
Hi Borg. Continue with removal guide first? .. I do not know what you mean by "Did you make the Windows disk/image on a clean PC?" I stick the windows disk in the drive and we're on our way.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
(1) Hitachi HDP725050GLA360 ATA Device (2) ST31000528AS ATA Device (3) Generic USB CF Reader USB
OS
Windows 7 Professional 64 bit
CPU
AMD Phenom(tm) II X4 955 Processor
Motherboard
ASUSTeK Computer INC. M3A78-CM
Memory
8 GB
Graphics Card(s)
XFX Radeon R7 260 X 1GB
Sound Card
AMD High Definition Audio Device
Monitor(s) Displays
Westinghouse TV 26"
Screen Resolution
1366x768
Hard Drives
1TB SATA
PSU
Corsair CX 750 ATX 80 Plus
Keyboard
Standard PS/2
Mouse
Standard
Internet Speed
80-100
Antivirus
Defender
Browser
Opera and Firefox
Back
Top