This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

problem with embedit.exe outlook.exe, etc [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You’ve done well and that’s looking good, just a bit of Incredimail tidying up.

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
FirewallRules: [{E9F347C7-082D-472C-9373-8E6A5531EC79}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{9A2509B0-479C-4B3A-A75D-9AF0F20F7232}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{9DA777ED-59BB-4DA6-84FD-74D4D3182780}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
FirewallRules: [{0E8AE6E8-21A5-49E7-A6FE-7BC9150EF50C}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
FirewallRules: [{DEA1D5D0-B459-4E83-9DA5-632E4AC81B26}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{32A7A37B-868E-4220-A347-04E63BCAA138}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{B3D62698-2D3F-4793-9DC6-71F9B324588E}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{10489BF1-AC7F-4E74-8BF5-DD1A79861B23}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{6FE27D94-A12A-42E0-8E44-2BC036117709}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{1CEAF09E-FF11-4827-A258-A2BB9B69A4C5}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{BDB49341-0EC2-465A-A631-4E0EC7A8B805}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{C2C80745-9B08-4DE9-949A-4A8C4D96C18F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{0AD9F96A-83CA-4E97-AD3D-23BAD127A468}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{FB8ACBD4-A8F1-44C5-ABD2-93545D20EB93}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{BC9656A9-7DDA-44F0-9E49-AB5EE42879A2}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{995FFE81-F89B-4F1B-8D91-1EBE5236BC0F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{61B979B7-A946-4506-A5C3-A8B16B9B4B23}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{34269BA0-E4CC-474C-A8AE-939D50E8AC0F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{97F4AADB-827E-4B89-9F89-C220D0B73962}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
FirewallRules: [{612B7E69-54FC-4A3D-B657-CACA942D4D53}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

Can you tell me if there are any outstanding problems.

Satchfan

 

hi!

 

Sorry I ran late in responding.  It was dinner time.  Now that is over. I have run the latest step in this problem of mine.  I have inserted  the fixlog.txt below.

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 19-04-2020
Ran by [removed] (19-04-2020 20:02:41) Run:2
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
FirewallRules: [{E9F347C7-082D-472C-9373-8E6A5531EC79}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{9A2509B0-479C-4B3A-A75D-9AF0F20F7232}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{9DA777ED-59BB-4DA6-84FD-74D4D3182780}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
FirewallRules: [{0E8AE6E8-21A5-49E7-A6FE-7BC9150EF50C}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
FirewallRules: [{DEA1D5D0-B459-4E83-9DA5-632E4AC81B26}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{32A7A37B-868E-4220-A347-04E63BCAA138}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{B3D62698-2D3F-4793-9DC6-71F9B324588E}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{10489BF1-AC7F-4E74-8BF5-DD1A79861B23}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{6FE27D94-A12A-42E0-8E44-2BC036117709}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{1CEAF09E-FF11-4827-A258-A2BB9B69A4C5}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{BDB49341-0EC2-465A-A631-4E0EC7A8B805}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{C2C80745-9B08-4DE9-949A-4A8C4D96C18F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{0AD9F96A-83CA-4E97-AD3D-23BAD127A468}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{FB8ACBD4-A8F1-44C5-ABD2-93545D20EB93}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{BC9656A9-7DDA-44F0-9E49-AB5EE42879A2}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{995FFE81-F89B-4F1B-8D91-1EBE5236BC0F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe No File
FirewallRules: [{61B979B7-A946-4506-A5C3-A8B16B9B4B23}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{34269BA0-E4CC-474C-A8AE-939D50E8AC0F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe No File
FirewallRules: [{97F4AADB-827E-4B89-9F89-C220D0B73962}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
FirewallRules: [{612B7E69-54FC-4A3D-B657-CACA942D4D53}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe No File
*****************
Processes closed successfully.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E9F347C7-082D-472C-9373-8E6A5531EC79}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9A2509B0-479C-4B3A-A75D-9AF0F20F7232}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9DA777ED-59BB-4DA6-84FD-74D4D3182780}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0E8AE6E8-21A5-49E7-A6FE-7BC9150EF50C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DEA1D5D0-B459-4E83-9DA5-632E4AC81B26}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{32A7A37B-868E-4220-A347-04E63BCAA138}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3D62698-2D3F-4793-9DC6-71F9B324588E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10489BF1-AC7F-4E74-8BF5-DD1A79861B23}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6FE27D94-A12A-42E0-8E44-2BC036117709}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1CEAF09E-FF11-4827-A258-A2BB9B69A4C5}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BDB49341-0EC2-465A-A631-4E0EC7A8B805}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C2C80745-9B08-4DE9-949A-4A8C4D96C18F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0AD9F96A-83CA-4E97-AD3D-23BAD127A468}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FB8ACBD4-A8F1-44C5-ABD2-93545D20EB93}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BC9656A9-7DDA-44F0-9E49-AB5EE42879A2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{995FFE81-F89B-4F1B-8D91-1EBE5236BC0F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{61B979B7-A946-4506-A5C3-A8B16B9B4B23}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{34269BA0-E4CC-474C-A8AE-939D50E8AC0F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{97F4AADB-827E-4B89-9F89-C220D0B73962}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{612B7E69-54FC-4A3D-B657-CACA942D4D53}" => removed successfully

The system needed a reboot.
==== End of Fixlog 20:02:44 ====

 

 

I have not noticed anything out of whack and I have you to thank for that!!    Can you tell me exactly what was wrong? Trojan? Worm? Virus?

I would really like to know so I don't repeat it!!

 

 

As long as I don't plug my Babyloc Pathfinder into this laptop, I will be fine.  I don't really understand why plugging it in would cause such turmoil!!

 

Dar

As long as I don't plug my Babyloc Pathfinder into this laptop, I will be fine.  I don't really understand why plugging it in would cause such turmoil!!

Have you plugged it in before?

 

From a quick look on Google, it says that you have to download to a usb stick and then plug the usb stick into your Babylock. See this.

 

I'd like an online scan before we finish because Malwarebytes got some pretty nasty stuff and I want to make sure there's nothing left.

 

Download ESET Online Scanner and save it to your desktop.

  • right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • when the tool opens, click Get Started.
  • read and accept the license agreement.
  • at the Welcome to ESET Online Scanner window, click Get Started.
  • select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • click on the Full Scan option.
  • select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • when the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature: click on Continue.
  • on the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

I won't reply tonight but the scan may take a while anyway.

 

Satchfan

Great news and well done.

 

Now that it seems to be running well, please follow these steps to tidy up and decrease the likelihood of getting infected again:

Uninstall FRST

  • right-click on FRST.exe/FRST64.exe and select Rename
  • rename the file to Uninstall.exe
  • double-click on Uninstall.exe – this will uninstall FRST

===================================================

Uninstall AdwCleaner

  • open adwcleaner.exe
  • click on Settings
  • click on the Application tab and scroll down to the bottom
  • click on Remove.

===================================================

Uninstall remaining programmes

Press the Windows Key + R at the same time, then type appwiz.cpl then Enter.

You can uninstall Eset

You can also delete all other logs and programmes we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Recommended

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

I also recommend that you read the following:

Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams

Answers to Common Security Questions - Best Practices by quietman7

How Malware Spreads - How Did I Get Infected by quietman7

I will keep this open for 24 hours in case you have any problems, after which I’ll close the topic.

Safe computing

Satchfan

 

HI!

 

Thank you very much for dedication and help you have given me for the past two days.  I really appreciate it!

 

I will follow your last set of instructions.  Can you tell me exactly what was wrong with my laptop?

 

dar

Thank you very much for dedication and help you have given me for the past two days.  I really appreciate it!

You're welcome.

 

You had some very bad adware that caused a lot of the problems but Malwarebytes got most of it and all I had to do was finish it off.

 

Take care and good luck with your embroidery.

 

Nina (Satchfan)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI