Application cannot be executed.. The file ___ is infected.... [Solved] - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Application cannot be executed.. The file ___ is infected.... [Solved] Can't open WinExplorere, or any other program, can't rename co

#1 tlmtlm59

  • Group: Member
  • Posts: 3
  • Joined: 02-May 10

Posted 02 May 2010 - 09:36 AM

most programs I try to run I get the Windows security alert bubble. Can't run WinExplorer, itunes, antisoftware programs (excpet SuperAntiSpyware which is running now), add/remove programs, etc...

I downloaded combifix.exe, but when downloading in Firefox, it doesn't give me the opportunity to rename it, just downloads it and without explorer, I can't rename it. I think downloads are goign to a /download file.

"Application cannot be executed. The file wscntfy.exe is infected. Do you want to activate your antivirus software now?"
And I get a lot of different .exe files in that message, depends on which app I try to run.

"Windows reports that computer is infected. antivirus software helps to protect....click here to". Then when I do, it tries to get me to buy AntiSpyware Soft, a product I may have downloaded a year ago but never bought. Pops up in the system tray.

Help?

#2 Essexboy

  • Group: GeekU Moderator
  • Posts: 55,596
  • Joined: 31-May 06

Posted 02 May 2010 - 10:22 AM

Download OTL to your Desktop (Firefox users right click and select save as...)

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post both logs


#3 tlmtlm59

  • Group: Member
  • Posts: 3
  • Joined: 02-May 10

Posted 02 May 2010 - 10:28 AM

After posting this, I was redirected to another page that gave additional things to try.
I tried a few, then I unclicked the LAN setting/Proxy and that seemed to do it.?.?

I downloaded a new version of malwarebytes, which I couldn't run before(kept getting that error). Downloaded and am running it now, nothing found.

I had to turn off the bypass/hijack in Lan/Proxy in IE. I use Firefox, but I think the directions on this page for turning it off were slightly wrong--I couldn't find the setting using the path suggested on that page. Might need a little tweaking.
I can't find it now, but I think it said go to Tools||Options||Advanced|| then somewhere that wasn't on my Options page. The IE instructions were fine.

So at this point I think I'm ok.

Fell free to delete this or close it out.

Thanks!

#4 Essexboy

  • Group: GeekU Moderator
  • Posts: 55,596
  • Joined: 31-May 06

Posted 02 May 2010 - 10:34 AM

If you are sure I will close

#5 tlmtlm59

  • Group: Member
  • Posts: 3
  • Joined: 02-May 10

Posted 02 May 2010 - 11:08 AM

Yea, I think it's good now.

#6 Essexboy

  • Group: GeekU Moderator
  • Posts: 55,596
  • Joined: 31-May 06

Posted 02 May 2010 - 11:14 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Share this topic: