Can't get rid of W32_API.cab, adapi.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by su8_z3r0, Nov 15, 2004.

  1. su8_z3r0

    su8_z3r0 Private E-2

    Hi there,
    I ran a virus scan with Norton and found I was infected with downloader.trojan, - theres a new file C:W/32_API.cab. Norton couldn't remove the file or fix the registry, even in Safe Mode, so I thought I'd post my HT log and see what you think.
    I've googled for this, but only found German users with this problem - no English advice anywhere...

    Any advice much appreciated!

    Here's my log:

    [log removed]
     
  2. Kodo

    Kodo SNATCHSQUATCH

  3. su8_z3r0

    su8_z3r0 Private E-2


    Ok fine, thanks Kodo:

    Now I have the latest HiJackthis, l've unzipped it into its own folder, and I've read the READ ME FIRST info. I've run both AdAware and Spybot, but neither of them find anything. Only Norton...
    I'm using WinXP with Firefox.

    What do I do next?
     
  4. Kodo

    Kodo SNATCHSQUATCH

  5. su8_z3r0

    su8_z3r0 Private E-2

    Attached Files:

  6. Kodo

    Kodo SNATCHSQUATCH

    I don't see anything in your log file. have you tried the alternate scans listed in the READ ME FIRST at the bottom?

    was this the name of the virus
    C:W/32_API.cab
    or is that the file that is infected?
     
  7. su8_z3r0

    su8_z3r0 Private E-2

    I found it with Norton - other scans (AdAware, Spybot) don't find anything, although admittedly I haven't tried ALL the ones listed in the RMF.

    Norton comes up with an infected file adapi.exe in C:/W32_API.cab. It says it contains the virus download.trojan. This cab file appeared in my C: directory. File size is 29,484. Norton is unable to remove it, even in safe mode.

    The computer is noticeably slower.

    As I said, I did a google search for w32_api.cab, but all the results were in German. I'm in the Czech Republic, right next door, as if that might affect it...
     
  8. Kodo

    Kodo SNATCHSQUATCH

  9. su8_z3r0

    su8_z3r0 Private E-2

    Cheers for the link, I'll try rebooting in safe mode and manually removing it. I'll let you know how it goes after I've run another scan.
     
  10. su8_z3r0

    su8_z3r0 Private E-2

    Hmm, that's odd. I deleted the C:/W32_API.cab file, but there were none of those 5 register entries given on that page. I've scanned again and I'm clean, so let's hope that's that.

    Thanks a lot Kodo, I appreciate your advice...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds