Can't fully remove virus, but turned it off

jamesonstrong

Commendable
Mar 7, 2016
1
0
1,510
I got a virus at the end of last week and I've been working to remove it since but it has been fighting. The virus was creating video ad windows on webpages which is what let me know I had a virus. When I looked at the task manager I had a process running called gamey.exe which I could not end without it coming back up. I have malewarebytes full version installed and I was using bitdefender but now using windows defender. I have gone into safe mode and went through to delete all of the exe's and other files that I can find that are associated with the virus. I have also gone through the registry and manually deleted files since malewarebytes and windows defender and bitdefender haven't found anything. There seem to be multiple files with this virus and most of them seem to live inside of one folder.

The folder that they live inside is in the program files (x86) folder \ and then plate. Inside of this folder live most of the files and they are " gamy.exe, wax.exe, fiddlerCore.dll, Ukey.ini, Microsoft.Win32.TaskSchedular.dll". When I go to delete the folder or change/ delete any of the files in this folder they get re created automatically by a process that pops up and then disappears called dllHost.exe with a discription of Com_surrogate.

I found some other files that seem to be associated with the virus that don't live in that folder call getcap.exe and greasy.exe. I've deleted everything I could find associated with these files as well in safe mode and in the registry.

As I've said I've gone into safe mode to delete the files which works just fine and have gone through the registry and manually deleted files that have anything to do with these. The gamy.exe is no longer running in my task manager processes anymore but I am unable to delete the folder "plate" with all of the exe's and dll files which tells me I've disabled the virus from actively running but I haven't deleted or removed it yet. Any help would be much appreciated and I thank anyone in advance for any help.