This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ntapi32d.exe? Trojan Virus

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, well this seems to keep coming back and not leaving whenever I try to delete it. If I try with AVG, it gets it but comes back. I tried deleting it in safe mode and it came back again?

Also it keeps changing my security settings to "trusted" from my regular "internet" when it comes to internet settings.

Here is my hijack this log. Please help, I've run the gammit of my knowledge or lack thereof.

Logfile of HijackThis v1.98.2
Scan saved at 10:21:47 PM, on 9/9/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: BHO - {06CAD548-14DD-4fa3-9EA9-05F83C18CBD7} - C:\WINDOWS\SYSTEM\MSPXS32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [Win32 Explorer] C:\WINDOWS\SYSTEM\explorer32.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [Win32 Explorer] C:\WINDOWS\SYSTEM\explorer32.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
Greetings and welcome to TomCoyote.org!

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

O2 - BHO: BHO - {06CAD548-14DD-4fa3-9EA9-05F83C18CBD7} - C:\WINDOWS\SYSTEM\MSPXS32.DLL

O4 - HKLM\..\Run: [Win32 Explorer] C:\WINDOWS\SYSTEM\explorer32.exe

O4 - HKCU\..\Run: [Win32 Explorer] C:\WINDOWS\SYSTEM\explorer32.exe

Reboot in "safe" mode. Use the link in my signature to tell you how if necessary.

Find and delete:

c:\windows\system\explorer32.exe <— file

c:\windows\system\mspxs32.dll <— file

Some malware files may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

Reboot in normal mode and post a new log file. :)
Thank you for replying Micah_6:8. I did as you suggested, however, I had already removed explorer32.exe earlier so it was not around for this time to delete. Here is my new log. Should this now clear my problem with the switch in internet security settings as I eluded to in my first post?

Thanks again.


Logfile of HijackThis v1.98.2
Scan saved at 11:21:08 AM, on 9/10/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\MY DOCUMENTS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
Ahh yes, its still there ntapi32d.exe. This is really annoying!!! My AVG keeps popping up a red screen with the trojan 7.B and asking me to enable it. I of course say "no" but its really annoying. Micah_6:8, can you help me further to rid me of this pestilence? Sincere thanks
Well… On the positive side of things, the log is clean now. :thumbup:

From what little info I can find on "ntapi32d.exe", I believe it is a trojan horse dialer.

I'd suggest trying some free online virus scanning/removing tools:

Please try these free online virus scans of your system:

Trend-Micro:
http://housecall.trendmicro.com/housecall/start_corp.asp

Panda:
http://www.pandasoftware.com/activescan/

Etrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Choose fix or clean.

Let them remove any infections found. Reboot inbetween each scan.

After the last scan, reboot and run your resident antivirus and let me know if any infections are lingering.

We have other free tools available to use in the removal of malware. :)

P.S. - If that file makes thru undetected by the scans, please post the full path name of the file (probably "C:\WINDOWS\SYSTEM\NTAPI32D.EXE"). We'll need that info if windows won't let you just go there and delete the file.
Well Micah_6:8 the son of gun made it past each inspection, and is still located in as you appropriately stated, C:\WINDOWS\SYSTEM\NTAPI32D.EXE. Is it possible that AVG is bringing it back? I am guessing of course because I just can't figure this thing out? Thanks
First I would suggest just navigating there with windows explorer and trying to delete the file. It may be "hidden" (see the link in my signature to explain how to show "hidden" files). You've probably already tried this approach.

If you find it, but windows won't let you delete it, then please do this:

Download killbox from here

http://www.downloads.subratam.org/KillBox.zip

Close all windows and programs.

Then unzip it and run it.

Copy and paste the next line in the "path of file name to delete" text box,.

C:\WINDOWS\SYSTEM\NTAPI32D.EXE

Do not press kill File button,..

Click on the Action menu and choose Delete on Reboot, then on the next window that pops up, choose the File Menu, then Add File. The above file should show up in that window. Click the Action Menu and choose "Process and Reboot" it should reboot.

Afterwards, run your resident virus scan in insure that it is gone.

Post back and let me know how things go. :)
Hey I've download Killbox, but its pocket Killbox and there are no menu's as you suggest so I am unsure of what to do. I have listed the name of the file but my options are all listed on the same screen, with the left side having: Standard Kill file Delete on Reboot Replace on Reboot use dummy (this option is not highlighted or visible) And the right side showing: End explorer shell while killing file unregister .dll before deleting (unhighlighted) deltree (include subdirectories) (unhighlighted) this is followed by a list headed by Kernel32.dll file So my question is, how should I work with this version of Killbox?
I'm at work right now. I have killbox on my home PC, but don't remember the exact process. I am sure it's the same version of Killbox. I will have to post more precise instructions in 3 or 4 hours when I get home. M68 :)
I apologize for the confusion. :oops:

I've always thought those instructions left a little to be desired. They were "pasted" in from a "canned response". You've given me the impetus and opportunity to (hopefully) improve them.

Close all windows and programs.

Run Killbox and paste the next line into the "Paste Full Path of File to Delete" text box.

C:\WINDOWS\SYSTEM\NTAPI32D.EXE

At the top of the Killbox window you'll see:

File Find Action FixL2m About Killbox

Click on "Action", then choose "Delete on Reboot".

At the top next window that pops up, choose "File", then "Add File".

The file you pasted into the text box should show up in that window.

At the top of that window, click "Action", and choose "Process and Reboot" it should reboot.
Hi Micah_6:8, yet another problem. This version only has Files, Tools, and About as menu headings. There is no Action menu. The version you sent me via weblink is Pocket Killbox 2.0.0.17 How can we get on the same page here? Also of note, I searched (albeit a limited search) for and add file but to no avail.
Well… Isn't that bizarre!! :weee:

I didn't know they changed the program…..

I just downloaded the same version you have.

That's life… Just when you figure out the answers… Someone changes the questions… ;)

Try these instrctions on for size:

Close all windows and programs.

Run Killbox and paste the next line into the "Full Path of File to Delete" text box.

C:\WINDOWS\SYSTEM\NTAPI32D.EXE

Check the button to the left of "Delete on Reboot".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes".

:)
I have performed the task using killbot and it went well. I, of course still sceptical, then used AVG, spybot, ad-aware, Trend, Panda, etc. to make sure there were no left over pieces of the mess. So far so good! I did find a DSO exploit and Searchforit with Spybot, and I recall deleting them the last time I saw them only for them to still be lingering around. Should I concern myself with these? Or should I be glad that the virus is gone? Thanks so much Micah_6:8

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI