gray box with mrt.exe and mrtstub.exe on desktop [Closed]
Started by
ecjacks
, Jul 02 2014 12:16 PM
#1
Posted 02 July 2014 - 12:16 PM
#2
Posted 02 July 2014 - 06:59 PM
Hello and welcome to Geeks to Go! My nickname is Pystryker , and I will be helping you with your issue today.
Before we get started, I have a few things I need to go over with you
Step 1: Scan with OTL
Download OTL
Download OTL to your desktop by clicking here. If for some reason, that link is not working, please click here for a secondary site.
OTL Log
Extras.txt Log
aswMBR Log
Before we get started, I have a few things I need to go over with you
- If you are receiving help for this issue at another forum, please let me know so I can close this thread.
- Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process.
- Please do not attach your logs or put them inside code/quote tags. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
- At the top of your post, please click on the "Follow this topic" button and make sure that the "Received notification" box is checked and set to "Instantly" This will send an email to you as soon as I reply to your topic, allowing us to solve your problem faster.
- If any of your security programs give you a warning about any tool I ask you to use, please do not worry. All the links and tools I provide to you will be safe.
- Please read through my instructions carefully and completely before executing them. I will lay the instructions out in a step by step order to make them easy to follow.
- Please make sure that all the programs I ask you to download are downloaded to and run from your Desktop.
- Please make sure you (if you are able) to print out these instructions so that you will be able to refer to them while working on your machine. Part of the solution(s) to your problem may involve us working in Safe Mode and you will need them to go by.
- Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
- This is a complicated process. It requires several steps, patience, and careful following of my instructions in the order they are given to diagnose your problems to get your machine back in working order.
- Please stay with me until the end of all steps and procedures and I declare your system clean. Just because there is a lack of symptoms does not indicate a clean machine. I promise to do the same for you.
- Please make sure you reply within 3 days to my responses, if there is no reply within 3 days, the topic will be closed and you will need to request the topic be reopened.
- Before we get started, please remember we will do our best to get your machine repaired. However, there are some cases where the only solution is a reformat and reinstall of the operating system. This is a worst case scenario though.
- It is impossible for me to know what interactions may happen between your computer's software and the tools we will use to clean your machine. Therefore, I highly recommend you backup any critical personal files on your machine before we start.
- If possible, please have your original Windows installation disks handy, just in case.
- If you have any questions at all, please don't hesitate to ask. There's no such thing as a stupid question when dealing with malware.
- If you are unsure of an instruction I give you, or if something unexepected occurs, Do NOT proceed! Stop and ask for clarification of the instruction or tell me what occurred.
- Please remember, the fixes are for your machine and your machine ONLY! Do not use these fixes on any other machine, each fix is tailor made for your system only. Using a fix on another machine can and will cause serious damage.
- Once we have cleaned your machine, we'll have some cleanup and prevention steps to go through. We will also provide you with some information about how to reduce your chances of infection and get some protections in place to help defend you against this in the future
- Please be patient while I am analyzing your logs. I know you are probably scared and very frustrated with this problem, but I am a volunteer and sometimes life does get in the way.
Step 1: Scan with OTL
Download OTL
Download OTL to your desktop by clicking here. If for some reason, that link is not working, please click here for a secondary site.
- Close any open windows and then double click (Vista, Windows 7, 8, right click and then click Run as Administrator) the icon to start OTL.
- Please make sure the following boxes are checked.
- Scan All Users
- Use Company-Name WhiteList
- Skip Microsoft Files
- Use No-Company-Name Whitelist
- LOP Check
- Purity Check
- Please check Use Safelist is checked under Extra Registry.
- Copy the contents of the quote box below Do not copy the word quote! and paste them into the Custom Scans/Fixes box at the bottom of OTL's control panel.
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
rpcss.dll
/md5stop
dir "%systemdrive%\*" /S /A:L /C - Click the Run Scan button.
- Please do not interrupt the scanning process. It may take a while to complete the scan, so please be patient.
- When the scan is finished, it will generate 2 logs, OTL.txt and Extras.txt, each in a Notepad window. Both of these logs are saved in the same location as OTL. In this case, on your desktop.
- Please post each log in your next reply.
- Please download aswMBR.exe to your desktop.
- Double click the file to run it.
- It will ask if you want to download the latest Avast! virus definitions, please answer yes.
- Click the Scan button to begin the scan.
- Once the scan has finished, click on Save Log, save it to your desktop as asw.txt, and please post it in your next reply.
- Click Exit
OTL Log
Extras.txt Log
aswMBR Log
#3
Posted 06 July 2014 - 05:45 AM
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users