I am unable to find or remove the trojan TR/Dldr.WinShow.AX. It is being detected by AntiVir as TR/Dldr.WinShow.AX and by Norton as MHTMLRedir.Exploit. The virus is inserting itself into the windows temp file. Once I direct my virus programs to delete the virus, it reinserts itself into the same windows temp file under a slightly different name each time. For example, AntiVir is currently reporting that C:\WINDOWS\TEMP\TMP182.TMP is the Trojan horse TR/Dldr.WinShow.AX. If I tell AntiVir to delete the file it will reappear immediately as TMP183.TMP. Occasionally other directories will be simultaneously infected with the virus under different names as well. I found generic manual removal instructions for winshow in several forums on the net and I have searched my system and reg using those instructions. I did find winshow and winlink in the reg by performing a search within the reg, but I did not find any malicious files or entries in the folders in which the directions said to look. Once I deleted the file I found with the reg search tool my virus programs still report the virus. I cannot find any information for this specific virus on the net. I have found removal instructions for many of the winshow variants, but not the one I have. I'm not even sure that matters, but none of the directions I have followed have worked. If it helps, my HijackThis log file reads as follows:

Logfile of HijackThis v1.99.1
Scan saved at 2:37:53 PM, on 7/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
F:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\GUARDGUI.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
F:\Program Files\Virus Tools\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SmcService] f:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{B3927CAA-4919-4C65-803C-0C48E19A816B}: NameServer =
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - F:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - f:\Program Files\Sygate\SPF\Smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe.

AntiVir, Norton, Spyware Blaster, Adaware SE, Spyware Doctor, SpyBot SD, Bazooka, and CW Shredder all failed to remove this virus. I would appreciate any help you may be able to offer.

Thanks :eek:

Dani AI

Generated

Short diagnosis and next steps (quick reference)

This is the MHTML redirection/exploit detection that Norton shows as MHTMLRedir.Exploit and that Antivir flags as TR/Dldr.WinShow.AX. Applying the Outlook/IE MHTML patch is important because the exploit uses the MHTML handler to drop or launch payloads; the patch Microsoft published (MS04-013) is the fix for the MHTML URL processing issue. (learn.microsoft.com)

Why clearing TEMP alone didn’t fix it

Thanks to for the temp-file advice — emptying Temporary Internet Files and %TEMP% is a required first step, but it won’t stop reinfection if a downloader is still active, if a Run/Service key keeps re-creating files, or if restore points or DNS/proxy settings redirect requests back to an attacker server. O17 (NameServer) entries in a HijackThis log indicate DNS changes; O4 Run keys (like an UpdReg entry) or a local proxy (R1 = 127.0.0.1:8080) are common persistence mechanisms and should be investigated. (aumha.org)

Practical cleanup plan (ordered, safe to follow)

  1. Disconnect from the network.
  2. Reboot into Safe Mode (no networking). Turn off System Restore (this deletes old restore points so they can’t re-seed an infection). (support.microsoft.com)
  3. Delete temp/IE cache, then run up-to-date on-demand scanners (Malwarebytes, Microsoft Safety Scanner, or a rescue ISO) and let them clean/quarantine. If the AV can’t remove a locked file, use an offline rescue disk. (malwarebytes.com)
  4. Use Autoruns and Process Explorer to find and remove startup entries, services, and loaded DLLs that recreate the temp files. Look for unknown items that point to C:\Windows\ or Temp and delete their files after disabling entries in Autoruns. (learn.microsoft.com)
  5. Repair networking artefacts: run these commands from an elevated prompt (after scanning) to clear socket and DNS artifacts:
netsh winsock reset
ipconfig /flushdns

Restart after the winsock reset. ()

If the files still reappear or you’re unsure, export data, wipe and reinstall Windows. After cleaning or reinstalling, install all Windows/IE/Outlook patches, re-enable System Restore, create a fresh restore point, and keep AV definitions current. If following these steps, mention the specific HijackThis lines (O4/O17/R1) you find — they point to where the reinfection is coming from. (cisa.gov)

Recommended Answers

All 3 Replies

Clear out your Temporary internet files and other temp files.
Go to Start > Settings > Control Panel >Internet Options.

Under the General tab click the Delete temporary internet files,
delete all Offline content as well. Clear out Cookies.

Also, go to Start > Find/search > Files or folders > in the named box, type: *.tmp and choose Edit > select all -> File > delete.

Empty/delete the entire contents of the C:\Windows\temp folder and C:\temp folder, if you have one. (Contents but not the folder itself.)

C:\Documents and Settings\username\Local Settings\Temp\

In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.

Empty the Recycle Bin.

Run your AV again.

Thanks for the help :) . I followed all of you directions, but the virus is still present and behaving in the same irritating manner. If you have any other suggestions, I will gladly try them too. I am contemplating the 12 gauge solution :eek: ...lol.

Thanks,
Colonel Fox

Microsoft has released a patch MS04-013 to address this issue.
Check to see if you have it downloaded already. There is nothing to remove from your PC as this is an exploit.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.