Assistance with Malware Removal - Tyler

Status
Not open for further replies.
Hey Juliet, I am sure you will have no problem helping me with this completely perplexing problem im having. =)

When I open the Farbar Recovery Tool, It updates, then closes itself, then reopens over and over again and I have to shutdown my computer. I have removed it and re downloaded it but it is doing the same thing. I will be away from keyboard for a few hours this morning so I'll check back with you later. Thanks again for all your help so far, It is extremely appreciated.

Tyler.
 
The tool has been fixed, delete the version you have now and run the script again.
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016
Ran by ttwebb (05-11-2016 06:27:42) Run:2
Running from C:\Users\ttwebb\Desktop
Loaded Profiles: ttwebb (Available Profiles: ttwebb)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
C:\Program Files (x86)\Popcorn Time\Updater.exe
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe
C:\Program Files (x86)\Popcorn Time\Updater.exe
C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{C5A19E09-F6DD-418F-BAE5-865031D71FA0}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{071431ED-691D-4B60-80EC-F4246E964C16}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{6769E495-9FBB-42B9-81BF-12C607744CB8}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{521424FF-6F92-4D22-A8BB-8BDBC6C99B60}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{BEC08786-FA53-409B-908F-26BE1C7F0129}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
C:\Program Files (x86)\Popcorn Time
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Popcorn Time
C:\Users\ttwebb\AppData\Local\VirtualStore\Program Files (x86)\Popcorn Time
StartRegedit:
[-HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time]
[-HKEY_USERS\S-1-5-21-608214363-481693584-3176531325-1002\Software\Popcorn Time\Popcorn Time]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1]
"UninstallString"=-
[-HKEY_CURRENT_USER\Software\Popcorn Time]
[-HKEY_CURRENT_USER\Software\Popcorn Time\Popcorn Time]
EndRegedit:
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Program Files (x86)\Popcorn Time\Updater.exe => moved successfully
Update service => service not found.
"C:\Program Files (x86)\Popcorn Time\Updater.exe" => not found.
"C:\users\ttwebb\appdata\local\popcorn time\node-webkit\popcorn time.exe" => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C5A19E09-F6DD-418F-BAE5-865031D71FA0} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{63F8AFBD-C8BA-4265-9EFE-3DBAE500D60D} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{071431ED-691D-4B60-80EC-F4246E964C16} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6769E495-9FBB-42B9-81BF-12C607744CB8} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{521424FF-6F92-4D22-A8BB-8BDBC6C99B60} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BEC08786-FA53-409B-908F-26BE1C7F0129} => value removed successfully
C:\Program Files (x86)\Popcorn Time => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time => moved successfully
"C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Popcorn Time" => not found.
C:\Users\ttwebb\AppData\Local\VirtualStore\Program Files (x86)\Popcorn Time => moved successfully

====> Registry

=========== EmptyTemp: ==========

BITS transfer queue => 12582912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12681736 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 1691919 B
Edge => 0 B
Chrome => 0 B
Firefox => 372970636 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 14863534 B
NetworkService => 0 B
ttwebb => 47041254 B

RecycleBin => 5197779 B
EmptyTemp: => 445.4 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 06:29:21 ====
 
Popcorn time uninstalled, everything seems to be running great. Thanks so much Juliet. Anything I can do for you?
 
Popcorn time uninstalled, everything seems to be running great. Thanks so much Juliet. Anything I can do for you?

Saying thank you is my reward :)


  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • -- This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
********************

  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • E8I37RF.png
    CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • EG85Vjt.png
    Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • 6YRrgUC.png
    Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • jv4nhMJ.png
    NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • DgW1XL2.png
    Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • j1OLIec.png
    SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • sHjS79L.png
    Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
  • JEP5iWI.png
    Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.
 
Glad we could help. :)
sparkle.gif


Since this issue appears resolved ... this Topic is closed.
 
Status
Not open for further replies.
Back
Top