Page 3 of 3 FirstFirst 123
Results 21 to 28 of 28

Thread: Assistance with Malware Removal - Tyler

  1. #21
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Hey Juliet, I am sure you will have no problem helping me with this completely perplexing problem im having. =)

    When I open the Farbar Recovery Tool, It updates, then closes itself, then reopens over and over again and I have to shutdown my computer. I have removed it and re downloaded it but it is doing the same thing. I will be away from keyboard for a few hours this morning so I'll check back with you later. Thanks again for all your help so far, It is extremely appreciated.

    Tyler.

  2. #22
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    The tool has been fixed, delete the version you have now and run the script again.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #23
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Fix result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016
    Ran by ttwebb (05-11-2016 06:27:42) Run:2
    Running from C:\Users\ttwebb\Desktop
    Loaded Profiles: ttwebb (Available Profiles: ttwebb)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    start
    CreateRestorePoint:
    CloseProcesses:
    C:\Program Files (x86)\Popcorn Time\Updater.exe
    R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe
    C:\Program Files (x86)\Popcorn Time\Updater.exe
    C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe
    FirewallRules: [{C5A19E09-F6DD-418F-BAE5-865031D71FA0}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
    FirewallRules: [{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
    FirewallRules: [{071431ED-691D-4B60-80EC-F4246E964C16}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
    FirewallRules: [{6769E495-9FBB-42B9-81BF-12C607744CB8}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
    FirewallRules: [{521424FF-6F92-4D22-A8BB-8BDBC6C99B60}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
    FirewallRules: [{BEC08786-FA53-409B-908F-26BE1C7F0129}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
    C:\Program Files (x86)\Popcorn Time
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Popcorn Time
    C:\Users\ttwebb\AppData\Local\VirtualStore\Program Files (x86)\Popcorn Time
    StartRegedit:
    [-HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time]
    [-HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time\Popcorn Time]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
    "UninstallString"=-
    [-HKEY_CURRENT_USER\Software\Popcorn Time]
    [-HKEY_CURRENT_USER\Software\Popcorn Time\Popcorn Time]
    EndRegedit:
    EmptyTemp:
    End
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    C:\Program Files (x86)\Popcorn Time\Updater.exe => moved successfully
    Update service => service not found.
    "C:\Program Files (x86)\Popcorn Time\Updater.exe" => not found.
    "C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe" => not found.
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C5A19E09-F6DD-418F-BAE5-865031D71FA0} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{071431ED-691D-4B60-80EC-F4246E964C16} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6769E495-9FBB-42B9-81BF-12C607744CB8} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{521424FF-6F92-4D22-A8BB-8BDBC6C99B60} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BEC08786-FA53-409B-908F-26BE1C7F0129} => value removed successfully
    C:\Program Files (x86)\Popcorn Time => moved successfully
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time => moved successfully
    "C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Popcorn Time" => not found.
    C:\Users\ttwebb\AppData\Local\VirtualStore\Program Files (x86)\Popcorn Time => moved successfully

    ====> Registry

    =========== EmptyTemp: ==========

    BITS transfer queue => 12582912 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12681736 B
    Java, Flash, Steam htmlcache => 0 B
    Windows/system/drivers => 1691919 B
    Edge => 0 B
    Chrome => 0 B
    Firefox => 372970636 B
    Opera => 0 B

    Temp, IE cache, history, cookies, recent:
    Default => 0 B
    ProgramData => 0 B
    Public => 0 B
    systemprofile => 128 B
    systemprofile32 => 0 B
    LocalService => 14863534 B
    NetworkService => 0 B
    ttwebb => 47041254 B

    RecycleBin => 5197779 B
    EmptyTemp: => 445.4 MB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 06:29:21 ====

  4. #24
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    How we doing now?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #25
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Popcorn time uninstalled, everything seems to be running great. Thanks so much Juliet. Anything I can do for you?

  6. #26
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Quote Originally Posted by ttwebb View Post
    Popcorn time uninstalled, everything seems to be running great. Thanks so much Juliet. Anything I can do for you?
    Saying thank you is my reward


    • Please download DelFix or from Here and save the file to your Desktop.
    • Double-click DelFix.exe to run the programme.
    • Place a checkmark next to the following items:
    • Activate UAC
    • Remove disinfection tools
    • Click the Run button.
    • -- This will remove the specialized tools we used to disinfect your system.
      Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
      ).

    ********************


    • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
    • CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
    • Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
    • Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
    • NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
    • Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
    • Secunia PSI will scan your computer for vulnerable softwarethat is outdated, and automatically find the latest update for you.
    • SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
    • Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
    • Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #27
    Junior Member
    Join Date
    Oct 2016
    Posts
    16

    Default

    Well thanks a bunch! Happy Hunting.

    Tyler

  8. #28
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Glad we could help.

    Since this issue appears resolved ... this Topic is closed.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •