By通过 Kristopher Kristopher

How to Remove Trojan Monder如何删除木马Monder

Updated Dec 18, 2008更新2008年12月18号

Trojan Monder Threat Level: 木马Monder威胁级别: 木马Monder是一个危险

Trojan Monder is a downloader Monder是一个木马下载 Trojan木马 that sneaks into your system through vulnerabilities.这偷偷进入您的系统通过漏洞。 Once Trojan Monder is installed, Trojan Monder downloads more malware and adware, and launches ads on Internet Explorer.一旦木马Monder安装后,木马Monder下载更多的恶意软件和广告软件,并推出广告,在Internet Explorer 。

Unless identity theft, hacker botnets, and Trojan Monder popups sound like a fun weekend, remove Trojan Monder.除非身份盗用,黑客僵尸网络,以及木马Monder弹出听起来像一个有趣的周末,删除木马Monder 。

I'll show you how to get rid of Trojan Monder for free.我会告诉您如何摆脱木马Monder是免费的。

Do You Have Trojan Monder?你有木马Monder ?

When you're infected with badware — whether it's Trojan Monder, spyware, adware, a Trojan, or a virus — there are a few key symptoms.当你感染了恶意软件-无论是Monder木马,间谍软件,广告软件,木马,或病毒-有几个关键的症状。 Have you noticed…你注意到...

  • Slow computer performance : It just takes one parasite like Trojan Monder to slow your computer dramatically. 电脑的性能降低 :这只是需要一个木马Monder寄生虫一样缓慢您的计算机显着。 If your PC takes longer than usual to reboot, or if your Internet connection is unusually slow, you may be infected with Trojan Monder.如果您的电脑需要花费较长的时间比平常要重新启动,或如果您的互联网连接异常缓慢,您可能感染木马Monder 。
  • New desktop shortcuts or switched homepage : Badware like Trojan Monder may change your Internet settings to redirect your homepage to another site. 新的桌面快捷方式或切换网页 :恶意软件类似木马Monder可能会改变您的互联网设置您的主页重定向到另一个网站。 Badware can even add desktop shortcuts to your PC.恶意软件甚至可以添加桌面快捷方式到您的PC 。
  • Annoying popups : Badware can bombard your computer with popup ads, even when you're not online. 恼人的弹出 :恶意软件可以轰炸电脑弹出式广告,即使您不在线。 Through these popups, you may be tricked into downloading more spyware.通过这些弹出,您可能会欺骗用户下载更多的间谍软件。

How to Remove Trojan Monder Manually如何删除木马Monder手动

木马Monder预警 Before we get started, you should backup your system and your registry, so it'll be easy to restore your computer if anything goes wrong.在我们开始使用,您应该备份您的系统和你的注册表,因此它会很容易将计算机还原如果任何事情都会发生错误的。

To remove Trojan Monder manually, you need to delete Trojan Monder files.要删除木马Monder手动,您需要删除木马Monder文件。 Not sure不知道 how to delete Trojan Monder files如何删除木马Monder文件 ? Click here点击这里 , and I'll show you. ,我会向您显示。 Otherwise, go ahead and…否则,继续进行并...

Stop Trojan Monder processes: 阻止木马Monder过程:

8142.exe 8142.exe

Delete Trojan Monder DLLs: 删除木马Monder的DLL :

%system%\lkkrem.dll %系统% \ lkkrem.dll
%system%\blvpho.dll %系统% \ blvpho.dll
%system%\codnnrjl.dll %系统% \ codnnrjl.dll
%system%\byXPFXnn.dll %系统% \ byXPFXnn.dll
%system%\fccccasi.dll %系统% \ fccccasi.dll
%system%\mriqfycp.dll %系统% \ mriqfycp.dll
%system%\nnnljiyx.dll %系统% \ nnnljiyx.dll
%system%\pmnopNeb.dll %系统% \ pmnopNeb.dll
%system%\tlmpgior.dll %系统% \ tlmpgior.dll
%system%\urqqhghb.dll %系统% \ urqqhghb.dll
%system%\xxywxxys.dll %系统% \ xxywxxys.dll
7ac3f42f-0fd7-4644-a801-a60155859c57.dll 7ac3f42f - 0fd7 - 4644 - a801 - a60155859c57.dll
033826fa0020f4a7b0970040d35cf300ecdc00b0.dll 033826fa0020f4a7b0970040d35cf300ecdc00b0.dll
4194967c8083e49385d1007d0e4c920089930298.dll 4194967c8083e49385d1007d0e4c920089930298.dll
4194967c8083e49385d1007d0e4c92009d434516.dll 4194967c8083e49385d1007d0e4c92009d434516.dll

Get rid of Trojan Monder registry keys and values: 摆脱木马Monder注册表项和值:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@^BM0bdb02fb HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \运行@ ^ BM0bdb02fb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@^BM3f6b100a HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \运行@ ^ BM3f6b100a
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^dmdko.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ dmdko.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^dmrqa.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ dmrqa.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^dmzyb.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ dmzyb.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^kdfra.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ kdfra.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^kdid HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ kdid
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^kdram.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ kdram.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion@^_d HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion @ ^ _d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run@^A00F2DE004.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \运行@ ^ A00F2DE004.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run@^A00F67E1C.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \运行@ ^ A00F67E1C.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run@^A00F691BEAC.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \运行@ ^ A00F691BEAC.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run@^A00F8BF047.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \运行@ ^ A00F8BF047.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run@^A00F8D713A.exe HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \运行@ ^ A00F8D713A.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg@^BM53d35ead HKEY_LOCAL_MACHINE \软件\微软\共享工具\ MSConfig \ startupreg @ ^ BM53d35ead
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@^System^=^kdfra.exe HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon系统^ @ ^ = ^ kdfra.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@^{67B0058D-B342-4CB2-A7F0-EDAB6C4F927D} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ ShellExecuteHooks @ ^ ( 67B0058D - B342 - 4CB2 - A7F0 - EDAB6C4F927D )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@^{F9DF827A-8FA7-48A3-B268-CA4DB563EA40} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ ShellExecuteHooks @ ^ ( F9DF827A - 8FA7 - 48A3 - B268 - CA4DB563EA40 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@^BM07c179c1 HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \运行@ ^ BM07c179c1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@^BM53d35ead HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \运行@ ^ BM53d35ead
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run@^gadcom HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \运行@ ^ gadcom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@^{0524B01A-F7AF-4665-8BE1-BE460478A4FF} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ ShellExecuteHooks @ ^ ( 0524B01A - F7AF - 4665 - 8BE1 - BE460478A4FF )
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@^C:\WINDOWS\system32\winver.exe HKEY_LOCAL_MACHINE \系统\ CurrentControlSet \服务\ SharedAccess \参数\ FirewallPolicy \ StandardProfile \ AuthorizedApplications \名单@ ^ ç : \窗口\ system32 \ winver.exe

HKEY_CLASSES_ROOT\CLSID\{e9782a99-765d-41da-a4b7-51d7d1f80b29} HKEY_CLASSES_ROOT \ CLSID中\ ( e9782a99 - 765d - 41da - a4b7 - 51d7d1f80b29 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid HKEY_LOCAL_MACHINE \软件\微软\ affltid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws HKEY_LOCAL_MACHINE \软件\微软\ aoprndtws
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\08e823e9 HKEY_LOCAL_MACHINE \软件\微软\ 08e823e9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct HKEY_LOCAL_MACHINE \软件\微软\ dslcnnct
HKEY_CLASSES_ROOT\CLSID\{3480eed8-1c5a-4090-bdfd-9b0831269e91} HKEY_CLASSES_ROOT \ CLSID中\ ( 3480eed8 - 1c5a - 4090 - bdfd - 9b0831269e91 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3480EED8-1C5A-4090-BDFD-9B0831269E91} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( 3480EED8 - 1C5A - 4090 - BDFD - 9B0831269E91 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3480eed8-1c5a-4090-bdfd-9b0831269e91} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( 3480eed8 - 1c5a - 4090 - bdfd - 9b0831269e91 )
HKEY_CLASSES_ROOT\CLSID\{67B0058D-B342-4CB2-A7F0-EDAB6C4F927D} HKEY_CLASSES_ROOT \ CLSID中\ ( 67B0058D - B342 - 4CB2 - A7F0 - EDAB6C4F927D )
HKEY_CLASSES_ROOT\CLSID\{88e2e10c-cd87-45c6-af08-b44646a16d1a} HKEY_CLASSES_ROOT \ CLSID中\ ( 88e2e10c - cd87 - 45c6 - af08 - b44646a16d1a )
HKEY_CLASSES_ROOT\CLSID\{A546EA3D-05F1-0D5E-FB38-79A2E3EB4FE0} HKEY_CLASSES_ROOT \ CLSID中\ ( A546EA3D - 05F1 - 0D5E - FB38 - 79A2E3EB4FE0 )
HKEY_CLASSES_ROOT\CLSID\{aac0b7a8-d61f-4f5c-bf53-fdeae69ceb50} HKEY_CLASSES_ROOT \ CLSID中\ ( aac0b7a8 - d61f - 4f5c - bf53 - fdeae69ceb50 )
HKEY_CLASSES_ROOT\CLSID\{AE41E538-02F9-5C5C-FF38-79A2E3EB4DB7} HKEY_CLASSES_ROOT \ CLSID中\ ( AE41E538 - 02F9 - 5C5C - FF38 - 79A2E3EB4DB7 )
HKEY_CLASSES_ROOT\clsid\{B3102264-D09D-4322-B625-503FBF18DD7E} HKEY_CLASSES_ROOT \ CLSID中\ ( B3102264 - D09D - 4322 - B625 - 503FBF18DD7E )
HKEY_CLASSES_ROOT\CLSID\{D5750A4D-DFC7-4A7D-9F75-226D723AAB32} HKEY_CLASSES_ROOT \ CLSID中\ ( D5750A4D - DFC7 - 4A7D - 9F75 - 226D723AAB32 )
HKEY_CLASSES_ROOT\CLSID\{F9DF827A-8FA7-48A3-B268-CA4DB563EA40} HKEY_CLASSES_ROOT \ CLSID中\ ( F9DF827A - 8FA7 - 48A3 - B268 - CA4DB563EA40 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88E2E10C-CD87-45C6-AF08-B44646A16D1A} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( 88E2E10C - CD87 - 45C6 - AF08 - B44646A16D1A )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A546EA3D-05F1-0D5E-FB38-79A2E3EB4FE0} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( A546EA3D - 05F1 - 0D5E - FB38 - 79A2E3EB4FE0 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AAC0B7A8-D61F-4F5C-BF53-FDEAE69CEB50} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( AAC0B7A8 - D61F - 4F5C - BF53 - FDEAE69CEB50 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE41E538-02F9-5C5C-FF38-79A2E3EB4DB7} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( AE41E538 - 02F9 - 5C5C - FF38 - 79A2E3EB4DB7 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3102264-D09D-4322-B625-503FBF18DD7E} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( B3102264 - D09D - 4322 - B625 - 503FBF18DD7E )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D5750A4D-DFC7-4A7D-9F75-226D723AAB32} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( D5750A4D - DFC7 - 4A7D - 9F75 - 226D723AAB32 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9DF827A-8FA7-48A3-B268-CA4DB563EA40} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( F9DF827A - 8FA7 - 48A3 - B268 - CA4DB563EA40 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\_r HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \ _r
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct HKEY_LOCAL_MACHINE \软件\微软\ dslcnnct
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnnnKAT HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ opnnnKAT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUoMfdC HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ wvUoMfdC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c001DB2E HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ __c001DB2E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c004637D HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ __c004637D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0082FB9 HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ __c0082FB9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c009E324 HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ __c009E324
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00DA228 HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ __c00DA228
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00EAD62 HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ __c00EAD62
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88e2e10c-cd87-45c6-af08-b44646a16d1a} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( 88e2e10c - cd87 - 45c6 - af08 - b44646a16d1a )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A546EA3D-05F1-0D5E-FB38-79A2E3EB4FE0} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( A546EA3D - 05F1 - 0D5E - FB38 - 79A2E3EB4FE0 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{aac0b7a8-d61f-4f5c-bf53-fdeae69ceb50} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( aac0b7a8 - d61f - 4f5c - bf53 - fdeae69ceb50 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE41E538-02F9-5C5C-FF38-79A2E3EB4DB7} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( AE41E538 - 02F9 - 5C5C - FF38 - 79A2E3EB4DB7 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3102264-D09D-4322-B625-503FBF18DD7E} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( B3102264 - D09D - 4322 - B625 - 503FBF18DD7E )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5750A4D-DFC7-4A7D-9F75-226D723AAB32} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( D5750A4D - DFC7 - 4A7D - 9F75 - 226D723AAB32 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9DF827A-8FA7-48A3-B268-CA4DB563EA40} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( F9DF827A - 8FA7 - 48A3 - B268 - CA4DB563EA40 )
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A546EA3D-05F1-0D5E-FB38-79A2E3EB4FE0} HKEY_USERS \ 。缺省\软件\微软\的Windows \ CurrentVersion \分机\统计\ ( A546EA3D - 05F1 - 0D5E - FB38 - 79A2E3EB4FE0 )
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE41E538-02F9-5C5C-FF38-79A2E3EB4DB7} HKEY_USERS \ 。缺省\软件\微软\的Windows \ CurrentVersion \分机\统计\ ( AE41E538 - 02F9 - 5C5C - FF38 - 79A2E3EB4DB7 )
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9DF827A-8FA7-48A3-B268-CA4DB563EA40} HKEY_USERS \ 。缺省\软件\微软\的Windows \ CurrentVersion \分机\统计\ ( F9DF827A - 8FA7 - 48A3 - B268 - CA4DB563EA40 )
HKEY_CURRENT_USER\Software\Microsoft\contim HKEY_CURRENT_USER \软件\微软\ contim
HKEY_CURRENT_USER\Software\Microsoft\isfiaf HKEY_CURRENT_USER \软件\微软\ isfiaf
HKEY_CLASSES_ROOT\CLSID\{0524B01A-F7AF-4665-8BE1-BE460478A4FF} HKEY_CLASSES_ROOT \ CLSID中\ ( 0524B01A - F7AF - 4665 - 8BE1 - BE460478A4FF )
HKEY_CLASSES_ROOT\CLSID\{417C0667-F5ED-4867-834C-6992DAC12203} HKEY_CLASSES_ROOT \ CLSID中\ ( 417C0667 - F5ED - 4867 - 834C - 6992DAC12203 )
HKEY_CLASSES_ROOT\CLSID\{9e36cbe7-0cbd-488a-a508-fd08c0e2270f} HKEY_CLASSES_ROOT \ CLSID中\ ( 9e36cbe7 - 0cbd - 488a - a508 - fd08c0e2270f )
HKEY_CLASSES_ROOT\CLSID\{B03E6FDB-37CB-4054-BF9D-FE96C33FB937} HKEY_CLASSES_ROOT \ CLSID中\ ( B03E6FDB - 37CB - 4054 - BF9D - FE96C33FB937 )
HKEY_CLASSES_ROOT\CLSID\{db48387f-ca03-4511-8663-98da65f98fc6} HKEY_CLASSES_ROOT \ CLSID中\ ( db48387f - ca03 - 4511 - 8663 - 98da65f98fc6 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{417C0667-F5ED-4867-834C-6992DAC12203} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( 417C0667 - F5ED - 4867 - 834C - 6992DAC12203 )
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E36CBE7-0CBD-488A-A508-FD08C0E2270F} HKEY_CURRENT_USER \软件\微软\的Windows \ CurrentVersion \分机\统计\ ( 9E36CBE7 - 0CBD - 488A - A508 - FD08C0E2270F )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim HKEY_LOCAL_MACHINE \软件\微软\ contim
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkJaAR HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ opnkJaAR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnoOHAt HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ pmnoOHAt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winndy32 HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ winndy32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wintqv32 HKEY_LOCAL_MACHINE \软件\微软\的Windows NT \ CurrentVersion \ Winlogon \通知\ wintqv32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{417C0667-F5ED-4867-834C-6992DAC12203} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( 417C0667 - F5ED - 4867 - 834C - 6992DAC12203 )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9e36cbe7-0cbd-488a-a508-fd08c0e2270f} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( 9e36cbe7 - 0cbd - 488a - a508 - fd08c0e2270f )
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B03E6FDB-37CB-4054-BF9D-FE96C33FB937} HKEY_LOCAL_MACHINE \软件\微软\的Windows \ CurrentVersion \ Explorer的\ Browser Helper物件\ ( B03E6FDB - 37CB - 4054 - BF9D - FE96C33FB937 )

Note: In any Trojan Monder files I mention above, “%UserProfile%” is a variable referring to your current user's profile folder. 注:在任何木马Monder档案我提到上述情况, “ % UserProfile %是指一个变量的当前用户配置文件文件夹。 If you're using Windows NT/2000/XP, by default this is “C:\Documents and Settings\[CURRENT USER]” (eg, “C:\Documents and Settings\JoeSmith”). 如果您使用Windows NT/2000/XP ,这是默认 C : \的Documents and Settings \ [当前用户] ” (例如, C : \的Documents and Settings \ JoeSmith ” ) 。 If you have any questions about manual Trojan Monder removal, go ahead and leave a comment. 如果您有任何疑问手工清除木马Monder ,继续进行并发表评论。

How Do You Remove Trojan Monder Files?如何在删除木马Monder文件?

Need help figuring out how to delete Trojan Monder files?需要帮助搞清楚如何删除木马Monder文件吗? While there's some risk involved, and you should only manually remove Trojan Monder files if you're comfortable editing your system, you'll find it's fairly easy to delete Trojan Monder files in Windows.虽然有一些风险,你应该只手动删除木马Monder文件如果您已经满意编辑您的系统,你会发现它很容易删除木马Monder文件在Windows 。

How to delete Trojan Monder files in Windows XP and Vista: 如何删除木马Monder文件在Windows XP和Vista :

  1. Click your Windows Start menu, and then click “ Search .”按一下您的Windows 开始菜单,然后单击“ 搜索 ” 。
  2. A speech bubble will pop up asking you, “ What do you want to search for? ” Click “ All files and folders .”讲话泡沫会弹出问你, “ 你要什么寻找 ? ”点击“ 所有文件和文件夹 。 ”
  3. Type a Trojan Monder file in the search box, and select “ Local Hard Drives .”键入一个木马Monder档案在搜索框中,然后选择“ 本地硬盘驱动器 。 ”
  4. Click “ Search .” Once the file is found, delete it.单击“ 搜索 ” 。一旦找到该文件,删除它。

How to stop Trojan Monder processes: 如何阻止木马Monder过程:

  1. Click the Start menu, select Run .单击开始菜单中,选择运行
  2. Type taskmgr.exe into the the Run command box, and click “ OK .” You can also launch the Task Manager by pressing keys CTRL + Shift + ESC .键入taskmgr.exe进入运行命令框中,单击“ 确定 ” 。您也可以启动任务管理器,按下键按Ctrl + Shift + ESC键
  3. Click Processes tab, and find Trojan Monder processes.单击进程选项卡 ,找到木马Monder进程。
  4. Once you've found the Trojan Monder processes, right-click them and select “ End Process ” to kill Trojan Monder.一旦找到了特洛伊Monder过程中,右键单击并选择“ 结束进程 ”杀木马Monder 。

How to remove Trojan Monder registry keys: 如何删除木马Monder注册表项:

木马Monder预警 Because your registry is such a key piece of your Windows system, you should always backup your registry before you edit it.因为您的注册表是一个关键的Windows系统,您应该总是备份注册表之前,对其进行修改。 Editing your registry can be intimidating if you're not a computer expert, and when you change or a delete a critical registry key or value, there's a chance you may need to reinstall your entire system. Make sure your backup your registry before editing it.修改您的注册表可以恐吓如果您不是计算机专家,以及当您更改或删除一个关键的注册表项或值,有机会你可能需要重新安装整个系统。 请确保您的备份你的注册表之前编辑。

  1. Select your Windows menu “ Start ,” and click “ Run .” An “ Open ” field will appear.选择Windows菜单“ 开始 ” ,并点击“ 运行 ” 。 “ 开放 ”领域将会出现。 Type “ regedit ” and click “ OK ” to open up your Registry Editor.键入“ 注册 ” ,然后单击“ 确定 ”打开你的注册表编辑器。
  2. Registry Editor will open as a window with two panes. 注册表编辑器将打开一个窗口,两个窗格。 The left side Registry Editor's window lets you select various registry keys, and the right side displays the registry values of the registry key you select.左边的注册表编辑器的窗口,您可以选择不同的注册表项,并在右边显示的注册表值的注册表项,您选择。
  3. To find a registry key, such as any Trojan Monder registry keys, select “ Edit ,” then select “ Find ,” and in the search bar type any of Trojan Monder's registry keys.为了找到一个注册表项,如木马Monder任何注册表项,选择“ 修改 ” ,然后选择“ 查找 ” ,并在搜索栏键入任何木马Monder的注册表项。
  4. As soon as Trojan Monder registry key appears, you can delete the Trojan Monder registry key by right-clicking it and selecting “ Modify ,” then clicking “ Delete .”一旦木马Monder注册表项出现时,您可以删除该木马Monder注册表项,右键单击它并选择“ 修改 ” ,然后点击“ 删除 ” 。

How to delete Trojan Monder DLL files: 如何删除木马Monder DLL文件:

  1. First locate Trojan Monder DLL files you want to delete.首先找到木马Monder DLL文件要删除。 Open your Windows Start menu, then click “ Run .” Type “ cmd ” in Run, and click “ OK .”打开你的Windows 开始菜单,然后单击“ 运行 ” 。键入“ cmd ”在运行,单击“ 确定 ” 。
  2. To change your current directory, type “ cd ” in the command box, press your “ Space ” key, and enter the full directory where the Trojan Monder DLL file is located.若要变更您的当前目录,输入“ cd ”命令中,按您的“ 空间 ”键,并输入完整的目录下的木马Monder DLL文件的位置。 If you're not sure if the Trojan Monder DLL file is located in a particular directory, enter “ dir ” in the command box to display a directory's contents.如果您不能确定,如果该木马Monder DLL文件位于一个特定的目录,输入“ 目录 ”中的命令框中显示目录的内容。 To go one directory back, enter “ cd .. ” in the command box and press “ Enter .”去一个目录后,进入“ 的CD .. ”命令中的方块,然后按“ Enter ”键。
  3. When you've located the Trojan Monder DLL file you want to remove, type “ regsvr32 /u SampleDLLName.dll ” (eg, “regsvr32 /u jl27script.dll”) and press your “ Enter ” key.当您找到木马Monder DLL文件要删除,输入“ regsvr32 / ü SampleDLLName.dll ” (例如, “ regsvr32 / ü jl27script.dll ” ) ,然后按你的“ Enter ”键。

That's it.就是这样。 If you want to restore any Trojan Monder DLL file you removed, type “regsvr32 DLLJustDeleted.dll” (eg, “regsvr32 jl27script.dll”) into your command box, and press your “Enter” key.如果你想恢复任何木马Monder DLL文件删除,输入“ regsvr32 DLLJustDeleted.dll ” (例如, “ regsvr32 jl27script.dll ” )到您的命令中,并按下您的“ Enter ”键。

Did Trojan Monder change your homepage? 没有木马Monder更改主页?

  1. Click Windows Start menu > Control Panel > Internet Options .单击Windows 开始菜单 > “ 控制面板 ” > Internet选项
  2. Under Home Page , select the General > Use Default .首页中, 选择一般“使用默认
  3. Type in the URL you want as your home page (eg, “http://www.homepage.com”).输入您想要的网址为您的主页(例如, “ http://www.homepage.com ” ) 。
  4. Select Apply > OK .选择套用“确定
  5. You'll want to open a fresh web page and make sure that your new default home page pops up.您要打开一个新网页,并确保您的新默认主页弹出。

Trojan Monder Removal Tip木马Monder去除提示

Is your computer acting funny after deleting any Trojan Monder files?是您的计算机上删除后,代理有趣任何木马Monder文件吗? I recommend using a program like我建议使用一个程序一样 File Recover文件恢复 from PC Tools.从PC工具。 File Recover saves deleted files that otherwise can't be recovered by Windows operating sytem.文件恢复删除的文件保存,否则不能恢复Windows操作系统体系。

Want to save time finding Trojan Monder files?想节省时间找到木马Monder文件吗? Download Spyware Doctor Spyware Doctor的下载 , let it find the Trojan Monder files for you, and then manually delete Trojan Monder files. ,让它找到木马文件为您Monder ,然后手动删除木马Monder文件。

How Did You Get Trojan Monder?你是如何开始木马Monder ?

Wondering how Trojan Monder ended up on your PC?想知道如何木马Monder上涨在你的电脑? If you're infected with Trojan Monder or other badware, perhaps you were using…如果您感染了木马Monder或其他有害软件,也许你正在使用...

  • Freeware or shareware : Did you download and install shareware or freeware? 免费软件或共享 :在您下载并安装共享软件或免费? These low-cost or free software applications may come bundled with spyware, adware, or programs like Trojan Monder.这些低成本或免费的软件应用程序可能会捆绑间谍软件,广告软件,木马等程序或Monder 。 Sometimes adware is attached to the free software to “pay” developers for the cost of creating the software, and more often spyware is secretly attached to free software to harm your computer and steal your personal and financial information.有时广告是重视自由软件“支付”开发商的成本创造了软件和间谍软件往往是秘密附加到免费软件,以损害您的计算机和窃取您的个人信息和财务信息。
  • Peer-to-peer software : Do you use a peer-to-peer (P2P) program or other application with a shared network? 点对点软件 :您使用的是点对点( P2P )的程序或其他应用程序共享的网络? When you use these applications, you put your system at risk for unknowingly downloading an infected file, including applications like Trojan Monder.当您使用这些应用程序,你把你的系统风险的不知不觉下载受感染的文件,其中包括应用软件,如木马Monder 。
  • Questionable websites : Did you visit a website that's of questionable nature? 可疑网站 :你访问的网站的有问题的性质? When you visit malicious sites that are fishy and phishy, badware may be automatically downloaded and installed onto your computer, sometimes including applications like Trojan Monder.当您访问恶意网站,这些鱼和phishy ,恶意软件可能会自动下载并安装到您的电脑,有时包括应用软件,如木马Monder 。 I recommend you use Firefox web browser, if you don't already.我建议你使用Firefox Web浏览器,如果您还没有。

Understanding Trojan Monder了解木马Monder

If you're infected with Trojan Monder, you should know what you're fighting.如果您感染了木马Monder ,你应该知道你在战斗。 I'll explain some definitions related to Trojan Monder.我要解释一些有关的定义木马Monder 。

Trojan Monder May Be a Trojan木马Monder可能是一个木马

Trojans install themselves secretly onto your computer, most often through your downloading a simple email attachment (often Trojans pose as harmless pictures).木马安装自己偷偷到您的电脑,通常是通过您下载一个简单的电子邮件的附件(通常木马程序伪装成无害的照片) 。 Most Trojans are able to gain complete control over your PC after installation.大多数木马能够完全控制你的电脑安装后。 With this control, the Trojan and the hacker behind it may change your system settings, delete important files, steal your passwords, and watch your computer acitivity.与此对照,该木马程序和黑客背后可能会改变您的系统设置,删除重要文件,窃取您的密码,并观看您的计算机活性。

Infection Methods of Trojan Monder and Other Trojans 特洛伊木马病毒感染的方法和其他木马Monder

Most Trojans infect your computer by tricking you into launching an infected file.大多数木马感染您的计算机通过引诱你进入启动受感染的文件。 This poisoned file could disguised as a small file, such as a jpeg or other email attachment, or it might be downloaded via a website or FTP.这中毒档案可以伪装成一个小文件,如JPEG或其他电子邮件附件,或可能是通过网站下载或FTP 。

  • Email: Your PC may be infected with a Trojan when you download infected email attachments, or sometimes even when you simply open an email. 电子邮件:您的电脑可能感染了病毒感染时,您下载的电子邮件附件,或有时甚至当您只需打开一封电子邮件。 Many Trojans exploit security holes in Microsoft Outlook.许多特洛伊木马程序利用的安全漏洞在Microsoft Outlook中。 You may be able to reduce your chances of getting infected by a Trojan by using a spam-blocking software.您可以降低您的机会感染了特洛伊木马病毒利用的垃圾邮件拦截软件。
  • Websites: Your PC may be infected with a Trojan when you visit a rogue site. 网站:您的电脑可能感染了木马,当您访问一个恶意网站。 Many Trojans exploit security holes in Internet Explorer web browser so that by simply visiting a website you may unknowingly download a Trojan.许多特洛伊木马程序利用的安全漏洞在Internet Explorer网络浏览器,这样,只需访问某个网站您可能不知不觉地下载一个木马程序。
  • Open ports: If your computer runs programs that provide file-sharing functions - such as AOL Instant Messenger (AIM), MSN Messenger, and more - you may open your computer up to vulnerabilities. 打开端口:如果您的计算机运行的程序提供文件共享功能-如AOL的即时通讯(目的) , MSN Messenger和更多的-您可以打开您的计算机的漏洞。 Using file sharing through these applications may create a network that gives attackers the opportunity to remotely access your computer.使用文件共享,通过这些应用程序可能会创建一个网络,使攻击者有机会能够远程访问您的计算机。

Trojan Monder May Be a Backdoor木马Monder可能是一个后门

“Backdoor” describes a parasite that gets past your system's normal means of authentication, remotely accesses your PC, or otherwise enters your system without being detected. “后门”描述了一种寄生虫会过去您的系统的正常手段,验证,远程访问您的个人电脑,或以其他方式进入您的系统不被察觉。 Trojans and worms often use backdoor methods to access your computer and steal your personal and financial information and/or install more malware into your PC.特洛伊木马和蠕虫经常使用后门方法访问您的计算机和窃取您的个人资料和财务资料和/或安装更多的恶意软件到您的PC 。