<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to Remove Monder Trojan Virus?</title>
	<atom:link href="http://silkenhut.com/solution-monder-trojan-virus-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://silkenhut.com/solution-monder-trojan-virus-removal/</link>
	<description>Earning Money Online. Wordpress tips, blogging, sports, psp games, opinions by Allen Michael Gurrea</description>
	<lastBuildDate>Mon, 22 Mar 2010 00:09:40 +0800</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Solution : High CPU Usage by SVCHOST.exe Problem &#124; Silkenhut&#39;s World</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-10837</link>
		<dc:creator>Solution : High CPU Usage by SVCHOST.exe Problem &#124; Silkenhut&#39;s World</dc:creator>
		<pubDate>Mon, 04 Jan 2010 04:30:09 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-10837</guid>
		<description>[...] I have experienced both of these programs and I really would suggest that you use MalwareBytes first before using ComboFix. MalwareBytes has an easy interface (click to scan, and click to fix) while Combofix requires some additional input via notepad (you have to create that file with the correct inputs) before it can help you. Basically, Malwarebytes is for the average user and Combofix is for the more advanced user. [Click here for a sample post that shows you how to use ComboFix] [...]</description>
		<content:encoded><![CDATA[<p>[...] I have experienced both of these programs and I really would suggest that you use MalwareBytes first before using ComboFix. MalwareBytes has an easy interface (click to scan, and click to fix) while Combofix requires some additional input via notepad (you have to create that file with the correct inputs) before it can help you. Basically, Malwarebytes is for the average user and Combofix is for the more advanced user. [Click here for a sample post that shows you how to use ComboFix] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to remove the PSP Virus? &#124; Silkenhut's World</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-7537</link>
		<dc:creator>How to remove the PSP Virus? &#124; Silkenhut's World</dc:creator>
		<pubDate>Sun, 03 May 2009 15:10:36 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-7537</guid>
		<description>[...] trojan is a program that claims to do something good for you but instead, it does someting bad to your [...]</description>
		<content:encoded><![CDATA[<p>[...] trojan is a program that claims to do something good for you but instead, it does someting bad to your [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mafia Wars - Cheats and Hacks &#124; Silkenhut's World</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-7445</link>
		<dc:creator>Mafia Wars - Cheats and Hacks &#124; Silkenhut's World</dc:creator>
		<pubDate>Thu, 16 Apr 2009 01:36:03 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-7445</guid>
		<description>[...] :: Never download anything that says it is a mafia war cheat, most likely, it is a virus or a trojan that will just infect your computer making your cry all day long ok? Protection is still the key [...]</description>
		<content:encoded><![CDATA[<p>[...] :: Never download anything that says it is a mafia war cheat, most likely, it is a virus or a trojan that will just infect your computer making your cry all day long ok? Protection is still the key [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen Gurrea</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-7216</link>
		<dc:creator>Allen Gurrea</dc:creator>
		<pubDate>Mon, 02 Mar 2009 03:09:14 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-7216</guid>
		<description>@Pristine Angie, hello Pristine Angie. Thanks for the modification. After I removed the monder trojan, I have yet to be infected again. I just reread my guide and yes, I agree with your modification. They can simply copy the text that they see in the log file and they would be fine. :)</description>
		<content:encoded><![CDATA[<p>@Pristine Angie, hello Pristine Angie. Thanks for the modification. After I removed the monder trojan, I have yet to be infected again. I just reread my guide and yes, I agree with your modification. They can simply copy the text that they see in the log file and they would be fine. <img src='http://silkenhut.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pristine Angie</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-7185</link>
		<dc:creator>Pristine Angie</dc:creator>
		<pubDate>Wed, 25 Feb 2009 10:09:32 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-7185</guid>
		<description>This worked great.  Thanks for sharing.

By the way I tried going at it three times without any luck.

When I used the following modifications below, it worked like a charm.

1. Since Combofix scans again after the reboot, it will take just as much time as before the reboot.  If it &quot;appears&quot; to be freezing, don&#039;t touch anything.  Put your ear up to your computer and look at the HD activity light blinking.  It is still running.  It is only done when you see the log file on your screen.

2. The CFScript, because most of us create it on notepad, will have a .txt extension.  That is fine.

3. I tried writing my CFScript to your instructions (ie. KILLALL:, registry entries) and for me it didn&#039;t work.  A little searching around the internet turned up these alternate rules:

INCLUDE FULL PATH OF THE FILES TO KILL.  Therefore, suspicious.dll would become
************
File:
c:\windows\system32\suspicious.dll
c:\windows\system32\suspicious32.dll

************
Omit KILLALL on the heading of the CFScript

And registry entries to be killed only need the portion within the square brackets listed.  Unless there are multiple entries under a square braketed key, I found I didn&#039;t need the descriptive line.  Cutting and pasting from HiJackThis log or ComboFix log is recommended.

Additional notes: Some sites recommend that you change the ComboFix.exe icon into a numerical icon.  (ie. &quot;123.exe&quot;) because some malwares are smart enough to disable any programs called combofix.exe.  However, ComboFix instructors seem vociferous about not changing the name.

Cheers!</description>
		<content:encoded><![CDATA[<p>This worked great.  Thanks for sharing.</p>
<p>By the way I tried going at it three times without any luck.</p>
<p>When I used the following modifications below, it worked like a charm.</p>
<p>1. Since Combofix scans again after the reboot, it will take just as much time as before the reboot.  If it &#8220;appears&#8221; to be freezing, don&#8217;t touch anything.  Put your ear up to your computer and look at the HD activity light blinking.  It is still running.  It is only done when you see the log file on your screen.</p>
<p>2. The CFScript, because most of us create it on notepad, will have a .txt extension.  That is fine.</p>
<p>3. I tried writing my CFScript to your instructions (ie. KILLALL:, registry entries) and for me it didn&#8217;t work.  A little searching around the internet turned up these alternate rules:</p>
<p>INCLUDE FULL PATH OF THE FILES TO KILL.  Therefore, suspicious.dll would become<br />
************<br />
File:<br />
c:\windows\system32\suspicious.dll<br />
c:\windows\system32\suspicious32.dll</p>
<p>************<br />
Omit KILLALL on the heading of the CFScript</p>
<p>And registry entries to be killed only need the portion within the square brackets listed.  Unless there are multiple entries under a square braketed key, I found I didn&#8217;t need the descriptive line.  Cutting and pasting from HiJackThis log or ComboFix log is recommended.</p>
<p>Additional notes: Some sites recommend that you change the ComboFix.exe icon into a numerical icon.  (ie. &#8220;123.exe&#8221;) because some malwares are smart enough to disable any programs called combofix.exe.  However, ComboFix instructors seem vociferous about not changing the name.</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-6991</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Sat, 24 Jan 2009 16:57:28 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-6991</guid>
		<description>One of my computers was infested with Monder. I have spent hours trying to remove it with various other &#039;solutions&#039;; none worked. Then I tried your method - it has worked and now I am virus &amp; Trojan free. Thanks for publishing your solution.</description>
		<content:encoded><![CDATA[<p>One of my computers was infested with Monder. I have spent hours trying to remove it with various other &#8217;solutions&#8217;; none worked. Then I tried your method &#8211; it has worked and now I am virus &amp; Trojan free. Thanks for publishing your solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Free Kaspersky Antivirus Internet Security Unlimited Trial Crack &#124; Silkenhut's World</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-6912</link>
		<dc:creator>Free Kaspersky Antivirus Internet Security Unlimited Trial Crack &#124; Silkenhut's World</dc:creator>
		<pubDate>Fri, 16 Jan 2009 04:49:28 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-6912</guid>
		<description>[...] trial crack so I don&#8217;t have to look for Kaspersky keys but I found failed. All I got was a monder trojan in exchange for searching. However, don&#8217;t give up because sooner or later, we could really [...]</description>
		<content:encoded><![CDATA[<p>[...] trial crack so I don&#8217;t have to look for Kaspersky keys but I found failed. All I got was a monder trojan in exchange for searching. However, don&#8217;t give up because sooner or later, we could really [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-4996</link>
		<dc:creator>Allen</dc:creator>
		<pubDate>Tue, 08 Jul 2008 01:13:22 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-4996</guid>
		<description>&lt;b&gt;@Sarath&lt;/b&gt; - Hello Sarath, thanks for sharing your experience. I would still recommend that you do a scan of combofix just to be sure. :)</description>
		<content:encoded><![CDATA[<p><b>@Sarath</b> &#8211; Hello Sarath, thanks for sharing your experience. I would still recommend that you do a scan of combofix just to be sure. <img src='http://silkenhut.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sarath</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-4921</link>
		<dc:creator>sarath</dc:creator>
		<pubDate>Fri, 04 Jul 2008 13:31:36 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-4921</guid>
		<description>I too got infected with this today. It took me half day to remove this. I have used malware bytes anti malware (http://www.malwarebytes.org/mbam.php) to remove this Monder trojan. I think it is relatively more easy and safe.</description>
		<content:encoded><![CDATA[<p>I too got infected with this today. It took me half day to remove this. I have used malware bytes anti malware (<a href="http://www.malwarebytes.org/mbam.php">http://www.malwarebytes.org/mbam.php</a>) to remove this Monder trojan. I think it is relatively more easy and safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen</title>
		<link>http://silkenhut.com/solution-monder-trojan-virus-removal/comment-page-1/#comment-4861</link>
		<dc:creator>Allen</dc:creator>
		<pubDate>Mon, 30 Jun 2008 02:06:36 +0000</pubDate>
		<guid isPermaLink="false">http://silkenhut.com/?p=480#comment-4861</guid>
		<description>&lt;b&gt;@Rodaflip&lt;/b&gt; - You should execute combofix via run command at first. 
Use this &lt;i&gt;“%userprofile%\desktop\combofix.exe” /killall&lt;/i&gt;</description>
		<content:encoded><![CDATA[<p><b>@Rodaflip</b> &#8211; You should execute combofix via run command at first.<br />
Use this <i>“%userprofile%\desktop\combofix.exe” /killall</i></p>
]]></content:encoded>
	</item>
</channel>
</rss>
