Approx 20 hours of removal attempts

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mo_Steel, Apr 16, 2009.

  1. Mo_Steel

    Mo_Steel Private E-2

    Alright I have got one of the tough varieties. I was downloading some shareware items for a website I was working on, and when opening what I thought to be a trusted zip file, I found them to be what looked like corrupted files. I deleted the files and have had trouble ever since. Yesterday noticed degraded internet performance but not horrible, as the day wore on I started noticing I was not going to the sites I clicked on in Google and search engines. It looked to be real picky. Ran NOD32 and it detected win32/agentDGO or can't remember now. Its been a long night and I really want to get this ugly thing out of my computer. I ran GMER, MBAM, and Norman Malware as suggested at another site. I have throughout the day weeded out all the remnants of the culprit and then following guide here I thought I had found the very last file, I think I have removed 9 items in total but only one in this run through. Somewhere earlier in the day I had gotten the majority and then ESET quit reporting the virus. However when going to google many times the link you click on ends up redirecting to a survey site with cow spots and cow image, Stopzilla or a local yellowpages with some item looked up. Don't try to go to a banking institution it won't let you of google practically, then it will give up and you can surf. Nothing consistent but definitely something hiding in there as I can type in a Bank name and I can go fill out cattle surveys or visit some of those other sites, at this point I just need a clear concise direction of where to go. Attached are the files after going through all the steps in order to get help here.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Program Files\Mozilla Firefox\extensions\{1F5F5EDA-F437-48C8-A539-FE4CF8E89DAE}\chrome\content\"
    overlay.xul

    Tell me what problems you still have.
     
  3. Mo_Steel

    Mo_Steel Private E-2

    checked it again using a term in the google search bar. I am still being redirected to the poiskin.ru type sites. It really seems like everything is gone but remnants still remain. Not sure it is doing anything other than redirect at this point. Where we go next. :cry
     
  4. Mo_Steel

    Mo_Steel Private E-2

    I deleted that whole folder, I hadn't seen the overlay part originally. Still getting redirected, there are several similar folders with that overlay file in it???

    Some of the redirects if it helps http://www.petside.com/health/petvet/?utm_source=miva&utm_medium=text&utm_campaign=petvet_cat
    http://www.google.com/undefined

    http://yellowcom.addresses.com/yp_r...MO&PHPSESSID=edd59da0d8a221f98868f9d4eb5d8119
    http://finddecent.info/search.php
    http://www.cowsurvey.com/?sub=51&pub=231&cid=373616993 <----Very common (Cowsurvey)
    http://www.google.com/undefined
    Finally after about 6 re-directs let me through.
     
  5. Mo_Steel

    Mo_Steel Private E-2

    OK today or tonight had some time and I uninstalled Firefox, then deleted all folders associated with Firefox and now seems to have fixed the redirect issue. Can you plug in the final steps to cleaning up all the files I have now on the computer after running all the logs and such? Appreciate the assistance on this.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds