I recently got a virus which will not let me run any of my programs. I read the sticky thread about what to do before you post, but I cannot access the internet. I do however, have a USB which I can transfer over the programs requested, however, I will not be able to run any of those. My computer will not even let me use Ctrl+Alt+Del to view the processes. I have another laptop handy to download any files and transfer the via USB to my laptop. I have no idea what to do and would greatly appriciate some help. Everytime I try to access anyprogram (I have been trying to run Malwarebytes) a pop up appears and says something is broken and to go to this site and download an antivirus (which is obviously a scam). I cannot access the internet from the infected computer anyother way. Please advise. Thanks!

I recently got a virus which will not let me run any of my programs.

-- What rogue product are you asked to install?

-- What is your OS on infected compy?

-- Are you able to boot to Safe Mode? (tap F8 at startup)
-- If so, do you have the option for Safe Mode with Networking?

-- Are you able to get a command prompt (START > RUN > Type cmd ENTER)
-- If that is blocked, try (START > RUN > Type command.com ENTER)

Let us know and we'll have a whack at this.

Cheers :)


I also have a problem like this....i can see my desktop and transfer my files (except outlook) over to my flashdrive, so i got my files...for the most part...saved. Whenever I try and click on ANY program, it says "Application cannot be exeduted. The file (insert file name here).exe is infected. Do you want to activate your antivirus software now?" No matter what I hit yes or no, the same thing pops up and the my (or so it like like my) antivirus "ATTENTION! SPYWARE ALERT...Vulnerailites found"

Any suggestions??

Thanks in advance :)


Oh and I have no idea what you are talking about doing with the first 2 things you suggested. Once I boot in safe mode (if I can) what do I do from there?


I would love to be able to do any of that, but I cant do anything on my laptop. I am on my work laptop right now. I can't get to anything to download anything and my work computer will not allow me to download, so I can't transfer anything from my flashdrive to my 'bad' laptop.


even when i reboot in safe mode with networking, it still does not let me on the internet.. "The proxy server is refusing connections"


Unless you have access to another computer that can get online to get these needed tools then there isn't much that can be done.

ARE you actually using a proxy server? If not these may have been changed by the infection.
Check these settings on the infected computer, go to Control Panel, Internet Options, Connection Tab, LAN button. Make sure there is NO check mark in Use Proxy Server. Then try to get online.

I also have some advice concerning that flash drive you have used to move items from the infected computer, there would be a very good chance that you have also moved infected files to that flash drive so don't insert it into any other computer without fully scanning it or else you could likely infect another computer.


OH NO!! I didnt even think about my flash drive!!!!! IF I can get back on my computer (it is running a virus scan now) and do the provided steps, will it just walk me through what I need to do? OR if I can get to a computer and go to the provided steps, what do I do? Just dowload it on my flash and then when I get back to my infected computer insert the flash and then what?

Sorry to be so unknowledgeable when it comes to this stuff....I am just WAY out of my element!!!


Calm down, the steps are easy to do. They are all very simple as long as you take your time and read everything. Be sure to scan that flash drive before using it again. OR get another clean one to use for the removal programs and worry about the infected one later. Just don't use it until you are 100% certain that it is completely free of any infected files, chances are that it is NOT clean.

The tools, steps and how to do each are listing in full on the sticky. The programs themselves do no walk you through the steps, they are on the sticky so print it out if needed.Or read it from another computer as you do the steps on the infected one.


You download the tools and save them to the flash drive. Then insert the flash drive into the infected computer. Open the flash drive and move the tools from the flash drive to the computer. Install and run each tool. Save each log. Post back here with the logs.

With MBA-M it will need to be updated if possible. Then when you run the scan run a Full Scan. When it's finished it will show you in a box every bad file found in red. Make sure there are check marks next to each and then click the Clean/Quarantine box. Reboot the computer, that is very important.

Then go to the MBA-M program, click the Logs tab and open that bottom log. Copy/Paste it back here along with all the other logs.

shewww! okay, that sounds easy enough. I will try to get on my internet after the scan finishes...which btw it is at 95% and still has not found anything. I have McAfee and I did the "run through every file" option. But I will say that the entire time, the same boxes keep popping up saying that "Application cannot be executed. The file werfault.exe is infected. Do you want to activate your antivirus software now?" I click no and there is the box behind it saying "ATTENTION! SPYWARE ALERT" and then 2 options at the bottom saying "Activate your spwyare software now" and "Stay unprotected". I have had to click the "stay unprotected" a few times to see if my scan was still running and where it was.

Thanks again JHolland :)


werfault.exe is the Windows Error Reporting. Allow this scan to finish and then try the other steps. There may be one additional file you will need but try the steps I gave first about the flash drive and see if you can do them. If you can't let me know.


okay, it is in the process right now...as soon as it finishes, I will let you know :)


oh and i didn't do anything with the first step...maybe i should have asked about this first before continuing on. But i have no idea with a peer 2 peer program is....what is a p2p or how can i find if i have them?


P2P are file sharing programs like Limewire, iTorrent, BitTorrent, Frostwire. Anything like those, there are many of them, too many to list here. They are used to usually download music illegally instead of paying for it from a legitimate site like iTunes. With P2P programs you get these types of things from a person you don't know and those very often contain infections.
If you have downloaded music from anywhere without paying for it, these would be current songs, then delete the songs.

it's doing the step 5 right now....Microsoft® Windows® Malicious Software Removal Tool


okay it wouldnt let me do the GMER rootkit scanner...my screen went blue and shut down. I continued on to the MBA and it is working on it, so far 2 files found.

I have my DDS and the attach files, they are so huge, do i need to put them both on here?


Don't worry about the GMER problem. Many people have difficulties with it. Just continue on.
Add this to your list to do after the MBA-M scan is complete and you have it remove all and reboot:

IF you can get online with the infected computer. If not then that's fine.
Run the ESET Online Scanner

* You will need to allow an Active X to be installed in order to run it so be sure to do that.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt.
Once that is finished then post back here with all the logs.


YAY!!! I think everything has worked so far :) After I rebooted from the last step, my computer started up just fine and got on the internet and everything!!!!!!!!!!!!!! I am running the ESET download now. With everything working correctly do I need to still post all the files or can I just leave you alone now ;)

I do have a question about my flash drive though...do I need to just chunk it? Although I might have a file that I need on one of them...how do I get this off without infecting my computer again? I know you have said to run a scan before, but how do I do that if it doesn't give me that option when I insert it?

jholland...thank you so much! I wish I had your address so I could send you a thank you card and cookies :)


oh wait...with the ESET it says "Cannot get update. Is proxy configured". What now?


Oh yes, we do need to see ALL of those logs. Just because the computer is running right now and apparently running fine that doesn't mean that everything is gone, it could just be somewhat "crippled" and can "heal" itself and fire up again. So we need to take a look to be sure other steps aren't required. Hopefully they won't be but it is much better to assure that all is clean rather than have the same thing come up only worse the next time.


Just curious....is there anything in these logs that can have personal information attached to it? It says at the top of one, not to post this log, if i have to to zip it up and then attach it...


Nothing personal is in the logs. No, don't zip it we want you to copy/paste the logs. Know that one piece of instruction from the creator says to zip it but our instructions say;
Copy&Paste both the DDS.txt and the DDS Attach.txt into your post for assistance.


Need to see the log from MBA-M also. The full log can be found in the program itself under the Logs Tab. It would be the last log there. Open it, Go to Edit, Select All, Copy. Come back here and paste it into a reply. Can't give you any other instructions or make any determinations until all the logs are posted.


Malwarebytes' Anti-Malware 1.50

Database version: 5351

Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.6001.18999

12/18/2010 5:16:10 PM
mbam-log-2010-12-18 (17-16-10).txt

Scan type: Full scan (C:\|)
Objects scanned: 340987
Time elapsed: 57 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wbaivyds (Trojan.FakeAV.Gen) -> Value: wbaivyds -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Emily\AppData\Local\Temp\ygfhorlma\pnjrtcjaffm.exe (Trojan.FakeAV.Gen) -> Quarantined and deleted successfully.

