Computer Hope

Software => Computer viruses and spyware => Virus and spyware removal => Topic started by: Jbravo45 on August 06, 2010, 10:40:26 PM

Title: File XXX.exe cannot be executed, this file is infected!
Post by: Jbravo45 on August 06, 2010, 10:40:26 PM
Hi, my issue is very similar to this thread:
http://www.computerhope.com/forum/index.php/topic,95177.0.html
running on windows Vista, with a HP laptop, after not being able to run any programs I restarted the computer and loaded it up in safe mode, while in safe mode I hit Start, and searched for run.  I then typed /msconfig and looked through the start up applications, I found a weird file called vsileudi from manufacturer "unknown" so I disabled it from starting up.  I restarted windows and loaded the normal mode and the "virus" stopped popping up. I was then able to load applications just fine, it says the internet is connected and it works from my desktop but I couldn't get it to work on my laptop.  So I played around with the options in firefox and clicked on the option for "auto-detect proxy settings for this connection" and I was able to surf the web again.  but when I load IE or I use a program that needs internet connection (iTunes) it fails to work.  I went ahead and did the scans required from the sticky thread of what we should do before posting and my logs from superanti spyware, Mbam log, and hijackthis are attached.  any help would be appreciated!


[recovering disk space - old attachment deleted by admin]
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Crush on August 09, 2010, 06:16:18 PM
Hello, and welcome to Computer Hope Forums!

I'm Crush but, you can call me Chris too :) and I will be helping you with your Malware issues

Please note the following information about the malware forum:



Reply to this topic with the word BUMP.


Now that we have that out of the way:

Please download and run RKill.

    Download mirror 1 (http://download.bleepingcomputer.com/grinler/rkill.com) - Download mirror 2 (http://download.bleepingcomputer.com/grinler/rkill.exe) - Download mirror 3 (http://download.bleepingcomputer.com/grinler/rkill.scr)

    Note: This tool only kills the active infection, the actual infection will not be gone. Once you reboot the infection will be active again! Please do not reboot until instructed further to do so.
=======

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop

Code: [Select]
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
c:\$recycle.bin\*.* /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
nvstor32.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
explorer.exe
svchost.exe
userinit.exe
qmgr.dll
ws2_32.dll
proquota.exe
imm32.dll
kernel32.dll
ndis.sys
autochk.exe
spoolsv.exe
xmlprov.dll
ntmssvc.dll
mswsock.dll
Beep.SYS
ntfs.sys
termsrv.dll
sfcfiles.dll
st3shark.sys
ahcix86.sys
srsvc.dll
nvrd32.sys
/md5stop
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles

Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Jbravo45 on August 09, 2010, 08:40:19 PM
Rkill, and the OTL logs are all attached

[recovering disk space - old attachment deleted by admin]
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Crush on August 09, 2010, 10:12:11 PM
Please download ComboFix (http://img7.imageshack.us/img7/4930/combofix.gif) from BleepingComputer.com (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

Alternate link: GeeksToGo.com (http://subs.geekstogo.com/ComboFix.exe)


Rename ComboFix.exe to commy.exe before you save it to your Desktop
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Jbravo45 on August 10, 2010, 08:39:41 AM
I disabled my antispyware and antivirus applications, and then I downloaded combofix and renamed it to my desktop, after I click start and search for "%userprofile%\desktop\commy.exe" /stepdel, nothing pops up.  I also changed %userprofile% with the name of the user and it still doesn't do anything.  I tried opening combofix from the desktop and it opens a progress bar and as it fills up green, when it gets to the end a pop up appears saying "Incompatible OS.  ComboFix only works for workstations with Windows 2000 and XP."
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Crush on August 10, 2010, 11:21:52 AM
Is this a 64 bit OS?
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: christy66 on August 10, 2010, 11:32:51 AM
yes
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Crush on August 10, 2010, 11:39:45 AM
Alrighty. This should be fun  ;D

    Please run OTL.exe.
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
========

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe)

Double Click mbam-setup.exe to install the application.Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log along with the OTL fix log
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Jbravo45 on August 11, 2010, 05:56:37 PM
The OTL log and MBAM logs are attached, thanks

[recovering disk space - old attachment deleted by admin]
Title: Re: File XXX.exe cannot be executed, this file is infected!
Post by: Crush on August 12, 2010, 01:02:03 AM
Hi,

How are things running now? Can you please post a fresh OTL log?