Why everybody wants to invent their own crappy password hashing scheme? Just pick one of already widely used ones, eg.: PBKDF, bcrypt, scrypt, any non-DES-based algorithm offered by crypt(3)... And when you want to really design your own scheme, at least look at how all previously mentioned schemes are designed and try to understand why.
And as for why this scheme is bad: your application has access to this "protected file" with secret shared key and so does attacker.