Jump to content

How to make it stop coming back


Recommended Posts

I've been getting the same exact malware being installed every day almost of like a month. I have no idea how it keeps getting on my system.  I can easily clean it, and I make sure its gone, and it is. But more or less the following keeps coming back somehow.  Does anyone know how the hell I can figure out where its coming from?  How it keeps coming back?

OS: Windows 10
CPU: x64

Modules: 9
Trojan.Miuref, C:\Users\Scott\AppData\Local\YnPack\cksnymwk.dll, , [f69739c8e7b3231306cd09f55aa6bf41],

Registry Values: 2
PUP.Optional.GoldClick, HKU\S-1-5-21-3114127665-887777169-917595795-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ProxyGate, C:\Users\Scott\AppData\Roaming\ProxyGate\MainService.exe, , [424b45bceab0cf676b8a89e0a160a65a]
Trojan.Boaxxe.Gen, HKU\S-1-5-21-3114127665-887777169-917595795-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|YnPack, regsvr32.exe C:\Users\Scott\AppData\Local\YnPack\cksnymwk.dll, , [b1dc21e0801a49ed6ae81be2a36013ed]

Folders: 2
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\ocx, , [0d802fd28e0cc373a02a86473dc5916f],

Files: 22
Trojan.Miuref, C:\Users\Scott\AppData\Local\YnPack\cksnymwk.dll, , [f69739c8e7b3231306cd09f55aa6bf41],
Trojan.Kovter, C:\Windows\Temp\spcd32.exe, , [e0ad22df0595d660ab767be8fa06c838],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\Cloud.exe, , [820bd928e3b7a4920ea4ddaf659c36ca],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\MainService.exe, , [424b45bceab0cf676b8a89e0a160a65a],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\PGChk.exe, , [404d19e81f7bd6601dd890d914edd32d],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\PGCommon.dll, , [226bec159a00270fbc391158b9487f81],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\PGHelp.exe, , [6e1f10f19ffb5adc995cd39629d8728e],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\PGLog.exe, , [fa93a75a158573c339bce68318e9d42c],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\PGNet.exe, , [6f1e9b66d4c651e582735c0d867bd42c],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\PGUpd.exe, , [632ae51c5941999dfafbd7923cc5c53b],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\ProxyGate.exe, , [216cff02930710269c5988e16b9659a7],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\Socket.exe, , [95f8a45d45554fe701f4c3a6df2255ab],
PUP.Optional.GoldClick, C:\Users\Scott\AppData\Roaming\ProxyGate\TrafficMonitor.exe, , [5e2f41c0b1e9f83ef302244521e0956b],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\TrafficMonitor.ini, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\conf.dat, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\Config.ini, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\dbghelp.dll, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\dns.dat, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\list.dat, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\msvbvm60.dll, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\Skin.dll, , [0d802fd28e0cc373a02a86473dc5916f],
PUP.Optional.ProxyGate.PrxySvrRST, C:\Users\Scott\AppData\Roaming\ProxyGate\ocx\mscomctl.ocx, , [0d802fd28e0cc373a02a86473dc5916f],

 

Link to post
Share on other sites

Hello and :welcome:

 

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button. button.

    x5o4gh.png

  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.

  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Link to post
Share on other sites

  • 1 month later...
  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.