Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 28

Thread: Assistance with Malware Removal - Tyler

  1. #11
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    # AdwCleaner v6.030 - Logfile created 28/10/2016 at 22:08:04
    # Updated on 19/10/2016 by Malwarebytes
    # Database : 2016-10-28.2 [Server]
    # Operating System : Windows 8.1 (X64)
    # Username : ttwebb - TYLER
    # Running from : C:\Users\ttwebb\Downloads\AdwCleaner.exe
    # Mode: Clean
    # Support : hxxps://www.malwarebytes.com/support



    ***** [ Services ] *****

    [-] Service deleted: Update service


    ***** [ Folders ] *****

    [-] Folder deleted: C:\Users\ttwebb\AppData\Roaming\UpdaterEX
    [-] Folder deleted: C:\ProgramData\Webitar Production Inc
    [#] Folder deleted on reboot: C:\ProgramData\Application Data\Webitar Production Inc


    ***** [ Files ] *****



    ***** [ DLL ] *****



    ***** [ WMI ] *****



    ***** [ Shortcuts ] *****



    ***** [ Scheduled Tasks ] *****



    ***** [ Registry ] *****

    [-] Key deleted: HKU\S-1-5-21-608214363-481693584-3176531325-1002\Software\UpdaterEX
    [#] Key deleted on reboot: HKCU\Software\UpdaterEX
    [-] Key deleted: HKLM\SOFTWARE\Webitar Production Inc.
    [#] Key deleted on reboot: [x64] HKCU\Software\UpdaterEX
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com


    ***** [ Web browsers ] *****



    *************************

    :: "Tracing" keys deleted
    :: Winsock settings cleared

    *************************

    C:\AdwCleaner\AdwCleaner[C0].txt - [1422 Bytes] - [28/10/2016 22:08:04]
    C:\AdwCleaner\AdwCleaner[S0].txt - [1635 Bytes] - [28/10/2016 22:05:49]

    ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1568 Bytes] ##########

  2. #12
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.9 (09.30.2016)
    Operating System: Windows 8.1 x64
    Ran by ttwebb (Administrator) on Fri 10/28/2016 at 22:18:43.77
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    File System: 1

    Successfully deleted: C:\WINDOWS\wininit.ini (File)



    Registry: 0





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Fri 10/28/2016 at 22:49:40.02
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  3. #13
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Please download the Malwarebytes Anti-Malware setup file to your Desktop.

    OR from this location Malwarebytes' Anti-Malware

    • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
    • On the Dashboard click on Update Now
    • Go to the Setting Tab
    • Under Setting go to Detection and Protection
    • Under PUP and PUM make sure both are set to show Treat Detections as Malware
    • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
    • Then on the Dashboard click on Scan
    • Make sure to select THREAT SCAN
    • Then click on Scan
    • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
    • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
    • Upon completion of the scan (or after the reboot), click the History tab.
    • Click Application Logs, followed by the first Scan Log.
    • Click Export,followed by Copy to Clipboard. Paste the log in your next reply.


    ~~~~~~~~~~~~~~~~~~``

    Please download Emsisoft Emergency Kit and save it to your desktop.
    Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop.
    • Leave all settings as they are and click the Extract button at the bottom.
    • A folder named EEK will be created in the root of the drive (usually c:\).
    • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
    • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates.
    • Please click Yes so that it downloads the latest database updates.
    • When the update process is complete, a new button will appear in the lower-left corner that says Back. Click on this button to return to the Overview screen.
    • Click on Scan to be taken to the scan options.
    • If you are asked if you want the scanner to scan for Potentially Unwanted Programs, then click Yes.
    • Click on the Malware Scan button to start the scan.
    • When the scan is completed click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
    • Please save the log in Notepad on your desktop, and copy it to your next reply.
    • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.


    ~~~~~~~~~
    Last edited by Juliet; 2016-11-02 at 21:57.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  4. #14
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 11/2/2016
    Scan Time: 2:42 PM
    Logfile:
    Administrator: Yes

    Version: 2.2.1.1043
    Malware Database: v2016.11.02.13
    Rootkit Database: v2016.10.31.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled

    OS: Windows 8.1
    CPU: x64
    File System: NTFS
    User: ttwebb

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 302387
    Time Elapsed: 12 min, 56 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 0
    (No malicious items detected)

    Physical Sectors: 0
    (No malicious items detected)


    (end)

  5. #15
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Emsisoft Emergency Kit - Version 11.9
    Last update: 11/2/2016 3:49:58 PM
    User account: Tyler\ttwebb
    Computer name: TYLER
    OS version: Windows 8.1x64

    Scan settings:

    Scan type: Malware Scan
    Objects: Rootkits, Memory, Traces, Files

    Detect PUPs: On
    Scan archives: Off
    ADS Scan: On
    File extension filter: Off
    Advanced caching: On
    Direct disk access: Off

    Scan start: 11/2/2016 3:50:51 PM

    Scanned 75966
    Found 0

    Scan end: 11/2/2016 3:54:40 PM
    Scan time: 0:03:49

  6. #16
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    How's the computer now?

    Scans show bits and pieces of Popcorn Time have been removed, is it still in Add/Remove programs list?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #17
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Yea computer seems to be running tip top. Popcorn time is still on the programs list. It still wont let me remove it.

  8. #18
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Yea computer seems to be running tip top.
    yes!

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    Double-click SystemLook.exe to run it.
    Copy the content of the bolded text below into the main textfield:

    :filefind
    Popcorn time
    :folderfind
    Popcorn time
    :regfind
    Popcorn time


    Click the Look button to start the scan.
    When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  9. #19
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    SystemLook 30.07.11 by jpshortstuff
    Log created at 01:30 on 04/11/2016 by ttwebb
    Administrator - Elevation successful
    WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

    ========== filefind ==========

    Searching for "Popcorn time"
    No files found.

    ========== folderfind ==========

    Searching for "Popcorn time"
    C:\Program Files (x86)\Popcorn Time d------ [06:44 03/09/2016]
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time d------ [06:45 03/09/2016]
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Popcorn Time d------ [06:45 03/09/2016]
    C:\Users\ttwebb\AppData\Local\VirtualStore\Program Files (x86)\Popcorn Time d------ [06:44 03/09/2016]

    ========== regfind ==========

    Searching for "Popcorn time"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\a11d984a_0]
    @="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0282&subsys_103c1984&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume4\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe%b{00000000-0000-0000-0000-000000000000}"
    [HKEY_CURRENT_USER\Software\Popcorn Time]
    [HKEY_CURRENT_USER\Software\Popcorn Time\Popcorn Time]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "Inno Setup: App Path"="C:\Program Files (x86)\Popcorn Time"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "InstallLocation"="C:\Program Files (x86)\Popcorn Time"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "Inno Setup: Icon Group"="Popcorn Time"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "DisplayName"="Popcorn Time"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "DisplayIcon"="C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "UninstallString"=""C:\Program Files (x86)\Popcorn Time\unins000.exe""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "QuietUninstallString"=""C:\Program Files (x86)\Popcorn Time\unins000.exe" /SILENT"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "Publisher"="Popcorn Time"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "UDP Query User{112358B7-5556-4A0B-BF7A-1387948DC188}C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe"="v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe|Name=popcorn time.exe|Desc=popcorn time.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "TCP Query User{0E8CC3C6-E926-49F3-A900-E5CBC55846E5}C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe"="v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe|Name=popcorn time.exe|Desc=popcorn time.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{C5A19E09-F6DD-418F-BAE5-865031D71FA0}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\Updater.exe|Name=Updater.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\Updater.exe|Name=Updater.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{071431ED-691D-4B60-80EC-F4246E964C16}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe|Name=Popcorn Time|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{6769E495-9FBB-42B9-81BF-12C607744CB8}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe|Name=Popcorn Time|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{521424FF-6F92-4D22-A8BB-8BDBC6C99B60}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\chromecast\node.exe|Name=node.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{BEC08786-FA53-409B-908F-26BE1C7F0129}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\chromecast\node.exe|Name=node.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "UDP Query User{112358B7-5556-4A0B-BF7A-1387948DC188}C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe"="v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe|Name=popcorn time.exe|Desc=popcorn time.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "TCP Query User{0E8CC3C6-E926-49F3-A900-E5CBC55846E5}C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe"="v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe|Name=popcorn time.exe|Desc=popcorn time.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{C5A19E09-F6DD-418F-BAE5-865031D71FA0}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\Updater.exe|Name=Updater.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\Updater.exe|Name=Updater.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{071431ED-691D-4B60-80EC-F4246E964C16}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe|Name=Popcorn Time|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{6769E495-9FBB-42B9-81BF-12C607744CB8}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe|Name=Popcorn Time|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{521424FF-6F92-4D22-A8BB-8BDBC6C99B60}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\chromecast\node.exe|Name=node.exe|"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{BEC08786-FA53-409B-908F-26BE1C7F0129}"="v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\chromecast\node.exe|Name=node.exe|"
    [HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\a11d984a_0]
    @="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0282&subsys_103c1984&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume4\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe%b{00000000-0000-0000-0000-000000000000}"
    [HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time]
    [HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time\Popcorn Time]

    -= EOF =-

  10. #20
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
    To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)





    start
    CreateRestorePoint:
    CloseProcesses:
    C:\Program Files (x86)\Popcorn Time\Updater.exe
    R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe
    C:\Program Files (x86)\Popcorn Time\Updater.exe
    C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe
    FirewallRules: [{C5A19E09-F6DD-418F-BAE5-865031D71FA0}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
    FirewallRules: [{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
    FirewallRules: [{071431ED-691D-4B60-80EC-F4246E964C16}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
    FirewallRules: [{6769E495-9FBB-42B9-81BF-12C607744CB8}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
    FirewallRules: [{521424FF-6F92-4D22-A8BB-8BDBC6C99B60}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
    FirewallRules: [{BEC08786-FA53-409B-908F-26BE1C7F0129}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
    C:\Program Files (x86)\Popcorn Time
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Popcorn Time
    C:\Users\ttwebb\AppData\Local\VirtualStore\Program Files (x86)\Popcorn Time
    StartRegedit:
    [-HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time]
    [-HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time\Popcorn Time]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "UninstallString"=-
    [-HKEY_CURRENT_USER\Software\Popcorn Time]
    [-HKEY_CURRENT_USER\Software\Popcorn Time\Popcorn Time]
    EndRegedit:
    EmptyTemp:
    End
    Open FRST/FRST64 and press the > Fix < button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •