TR/Monder.atde Trojan caught by Avira

Discussion in 'Malware Help (A Specialist Will Reply)' started by patra7, Feb 7, 2009.

  1. patra7

    patra7 Private E-2

    Here's the story: I have Windows XP Professional SP3 installed and I'm using Avira Antivir Personal as an antivirus. I have had an Avira message popping up with the following:
    I tried the options "Move to Quarantine", "Delete", "Deny Access" several times without result.

    I also had the following message when rebooting:
    (I have Greek Windows so I'm translating from Greek as precisely as I can)

    I then run all the fixes you specify in the guide to the best of my ability (SuperAntiSpyware, Spybot, ComboFix, MGTools, etc...). All these programs found something and temporarily the thing seems to work. But after I surf on the internet for a while or the computer sits idle for some time a message pops up again from Avira. Now the message states the following:
    See logs attached.

    P.S. I almost forgot to say that I was using some P2P program and I now know that this probably was the cause of my troubles. I have since uninstalled it as well as some other unecessary programs.
     

    Attached Files:

  2. patra7

    patra7 Private E-2

    Here's the final log file:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    This is just in System Restore and will be removed after you complete all of my final instructions below.

    Your logs are clean but you need to do the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2
    Now reboot your PC and after reboot install the current version of Sun Java from: Sun Java Runtime Environment


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. patra7

    patra7 Private E-2

    I ran MessengerDisable (complete removal), I uninstalled JRE, re-booted and re-installed the latest version of JRE from Sun (the link at MajorGeeks you gave me was broken and did not work 3 times - now that I think of it maybe I tried to use the same server all 3 times).

    But then, I got another message from Avira Antivir. It had also popped up 1 day ago, after my first posts. It states:
    I tried to open the folder System Volume Information to see the exact path but I'm not allowed to access it... Again this message is infrequent, it does not pop up all of the time.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in my last message
     
  6. patra7

    patra7 Private E-2

    The problem itself is actually solved but I cannot uninstall Combofix.

    When I do the Start --> Run -->"%userprofile%\Desktop\combofix" /u (to uninstall Combofix) I get a message that states
    (net is the name of my profile)

    I have copied - pasted the command exactly as shown in your instructions. The combofix file is indeed located on my desktop and I can see the folder C:\Combofix\ with all the files inside it.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The steps state that it will only work if you have followed the iinstructions in the READ & RUN ME and copied ComboFix.exe to the Desktop. Since you are using a non-English version of the Windows, you will have to replace the word Desktop with whatever Desktop is in your language. According to your ComboFix log it was:

    c:\documents and settings\net\ÅðéöÜíåéá åñãáóßáò\ComboFix.exe
     
    Last edited: Feb 22, 2009
  8. patra7

    patra7 Private E-2

    OK. Thank you very much!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds