Computer Hope

Software => Computer viruses and spyware => Virus and spyware removal => Topic started by: Aphrod on May 24, 2010, 09:47:36 PM

Title: Application cannot be executed, file is infected.
Post by: Aphrod on May 24, 2010, 09:47:36 PM
 :'(

Today I started getting popups from Windows Security Alert that say "Application can not be executed. The file ****.exe is infected. Would you like to activate your antivirus now?" and I can't open any programs I'm also getting random pornography popups now.. If anyone could help it would be GREATLY appreciated.

and I can't post a SUPERAntiSpyware or MBAM log because my computer doesn't allow me to open those programs. I can't even go into add or remove programs.
Title: Re: Application cannot be executed, file is infected.
Post by: Dr Jay on May 25, 2010, 01:10:22 PM
Hello, and welcome to Computer Hope.

Please note the following information about the malware forum:

Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.
Title: Re: Application cannot be executed, file is infected.
Post by: Aphrod on May 25, 2010, 11:38:24 PM
When I go to download it it says it's not compatible with my OS and I need Windows 2000 or XP
Title: Re: Application cannot be executed, file is infected.
Post by: Dr Jay on May 25, 2010, 11:58:34 PM
(http://www.malwarebytes.org/forums/style_images/1/bf_new.gif) Please download Malwarebytes Anti-Malware from Malwarebytes.org (http://www.malwarebytes.org/mbam/program/mbam-setup.exe).
Alternate link: BleepingComputer.com (http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe).
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
Title: Re: Application cannot be executed, file is infected.
Post by: Aphrod on May 26, 2010, 02:39:55 AM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4144

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

5/26/2010 1:39:10 AM
mbam-log-2010-05-26 (01-39-10).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 355964
Time elapsed: 1 hour(s), 52 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jqhckmtx (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Kyle\AppData\Local\exgbmshuv\uvvkxgwtssd.exe (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
Title: Re: Application cannot be executed, file is infected.
Post by: Dr Jay on May 26, 2010, 09:14:03 AM
Please run a free online scan with the ESET Online Scanner (http://www.eset.com/onlinescan/)
Title: Re: Application cannot be executed, file is infected.
Post by: Aphrod on May 26, 2010, 03:10:03 PM
I've tried for hours trying to get it to work, when I try to install it it says "Can not get update. Is proxy configured?"
Title: Re: Application cannot be executed, file is infected.
Post by: Dr Jay on May 26, 2010, 09:00:10 PM
Please do a scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html)

Click on the Accept button and install any components it needs.
Title: Re: Application cannot be executed, file is infected.
Post by: Aphrod on May 27, 2010, 11:21:03 AM
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
 Thursday, May 27, 2010
 Operating system: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002)
 Kaspersky Online Scanner version: 7.0.26.13
 Last database update: Thursday, May 27, 2010 00:19:03
 Records in database: 4177357
--------------------------------------------------------------------------------

Scan settings:
   scan using the following database: extended
   Scan archives: yes
   Scan e-mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   E:\
   F:\

Scan statistics:
   Objects scanned: 246628
   Threats found: 1
   Infected objects found: 3
   Suspicious objects found: 0
   Scan duration: 05:11:13


File name / Threat / Threats count
C:\Users\Kyle\Downloads\mmBOT.546.rar   Infected: not-a-virus:AdWare.Win32.Maxifiles.ad   3

Selected area has been scanned.
Title: Re: Application cannot be executed, file is infected.
Post by: Dr Jay on May 27, 2010, 08:15:16 PM
To manually create a new Restore PointNow we can purge the infected ones
You are now done

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe (http://oldtimer.geekstogo.com/OTC.exe) by OldTimer:
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop
==

Download Security Check by screen317 from SpywareInfoforum.org (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or Changelog.fr (http://screen317.changelog.fr/SecurityCheck.exe).
Title: Re: Application cannot be executed, file is infected.
Post by: Aphrod on May 27, 2010, 09:33:27 PM
 Results of screen317's Security Check version 0.99.4 
 Windows Vista  (UAC is enabled)
 Out of date service pack!! (http://support.microsoft.com/kb/935791)
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Enabled! 
 avast! Free Antivirus   
 Norton Internet Security (Symantec Corporation) 
 Antivirus up to date! 
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 CCleaner     
 Java(TM) 6 Update 17 
 Out of date Java installed!
 Adobe Flash Player 10.0.32.18 
Adobe Reader 8.1.4
Out of date Adobe Reader installed!
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Norton ccSvcHst.exe
 Windows Defender MSASCui.exe
 Windows Defender MSASCui.exe   
 Alwil Software Avast5 AvastSvc.exe 
 Alwil Software Avast5 AvastUI.exe 
````````````````````````````````
DNS Vulnerability Check:

 GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

I'm not sure why it says Norton, I tried to uninstall that but it never worked all the way and I get 2 pop ups from it every time I start my computer.

and Thank you very much!  ;D

Title: Re: Application cannot be executed, file is infected.
Post by: Dr Jay on May 28, 2010, 03:10:57 PM
Please consider updating to Windows Vista Service Packs 1 & 2.
Windows Vista Service Packs 1 & 2 contain all the updates released since the first release plus support for new types of hardware and emerging hardware standards.
It is now available via Windows Update (http://support.microsoft.com/kb/935791#Method2) or as a standalone installation here (http://support.microsoft.com/kb/935791#Method3).

========

Please download the newest version of Adobe Acrobat Reader from Adobe.com (http://www.adobe.com/products/acrobat/readstep2.html)

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==

Please download the newest version of Java from Java.com (http://www.java.com/en/download/manual.jsp).

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

========================

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

AntiSpywareNOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm (http://www.spywarewarrior.com/rogue_anti-spyware.htm)

Securing your computerPlease consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
See this page (http://www.helpmyos.com/learn-security-f40/preventing-malware-and-being-resistant-to-the-dangers-of-the-internet-t1516.htm) for more info about malware and prevention.