MonaRonaDona

  • Thread starter Thread starter Lou
  • Start date Start date
M.I.5¾ said:
I can only assume that you believe that the only way malware can get to your
machine is if you visit a web site that carries that malware (that is
certainly the vein of your postings). Believe me, sunshine, that just ain't
the case. Although much malware does work that way, an equal or larger
number of species does not. These things can propagate themselves without
any help or assistance from you or I.

You've taken it from "virus" to "malware". Fine. I'll read on.
A few years ago we had the dubious privilege of watching a self replicating
worm spreading around our network of PCs without any of them looking at
anything on the internet or intranet.

I'm not on a network, bucko.
It might have been difficult to keep
up except that it actually slowed down probably due to all the network
traffic each copy was generating looking for new uninfected machines to
transfer itself to. It took a couple of hours to do the whole network of
several thousand machines, but it's probably accurate to say that the
infection also spread to other machines and networks conected to the
planetary network.

You're assertion that a "virus" (which you now correctly call a
"worm") can enter my system within 15 minutes of starting - if I don't
have a virus checker operating - is still utter bullshit.
 
Ken Blake said:
I run an anti-virus program and six different anti-spyware programs, in
addition to a firewall. In my case, nothing more than Tracking Cookies has
ever been found.

I have been running AVG Anti-virus for quite some time now. Prior to
XP, I rarely ran an anti-virus... mainly because my system prior to
installing XP was minimal, and didn't have a lot of RAM.

That, plus the fact that worms, etc. were less prevalent prior to that
time made my exposure less probable.

I still don't run any resident malware obstructers, and when I ran the
free scanning programs from several vendors, they ONLY found tracking
cookies (doubleclick, etc. ) as problems.
 
Shenan Stanley said:
Virus installed applicatioon, malware. I should have stated,
"Somebody/something added it to your Titlebar - likely through
registry/group policy."

Most of the buzz on it points to some software called, "Unigray
Antivirus". Did you install that lately?

Have you rebooted and made sure the title does not get 'put back'?
I just now did that and Mona etc. is back.
I went to regedit again and Mona etc. was listed as the Window Title. I
deleted that name and added my own.
I rebooted my computer and Mona etc. was back.
I tried without success to "save" the registry after I had made the change.
Any further help would be greatly appreciated.
Lou
 
Lou said:
I just now did that and Mona etc. is back.
I went to regedit again and Mona etc. was listed as the Window Title. I
deleted that name and added my own.
I rebooted my computer and Mona etc. was back.
I tried without success to "save" the registry after I had made the change.
Any further help would be greatly appreciated.

Do you have anything running that is supposed to keep you or anyone
else from messing with Explorer's settings???

Like any malware blocker or anti virus program that has a "watch"
function that continuously monitors your system??
 
PD43 said:
You've taken it from "virus" to "malware". Fine. I'll read on.

Malware is a superset of virus.
I'm not on a network, bucko.

You said that you surf the internet. The internet is a very large network.
Ergo, you *are* on a network.
You're assertion that a "virus" (which you now correctly call a
"worm") can enter my system within 15 minutes of starting - if I don't
have a virus checker operating - is still utter bullshit.

Please yourself sunshine.
 
PD43 said:
You're assertion that a "virus" (which you now correctly call a
"worm") can enter my system within 15 minutes of starting - if I don't
have a virus checker operating - is still utter bullshit.

WRONG. Look up about the Blaster Worm (for one example). This is why XP
SP2 has the firewall turned ON by default...prior to that it was turned
OFF by default, and I have personal experience of an un-protected
machine being infected in TWENTY SECONDS after having connected to the
internet with no protection.
Look it up, it's well documented.
 
Despite lack of information on the Internet, I was able to pinpoint the
culprit that was causing my machine to start acting up due to the
MonaRonaDona virus.

I was able to fix the problem and here is how.

The virus installs an executable SRVSPOOL.EXE in the startup folder of the
all users account. Click Start/Programs/Startup, right click the
SRVSPOOL.EXE entry and delete it. How to fix the header of your Internet
explorer and how to re-enable taskmanager, is posted in numerous postings
online.

Re-enable Task Manager: http://www.kellys-korner-xp.com/xp_tweaks.htm
Go to this page and try #51 from the right column. Click on "enable the task
manager."

Modify header of Internet explorer:
http://answers.yahoo.com/question/index?qid=20080223085704AA1dibb
(optionally, you can manually type "Microsoft Internet Explorer" to replace
the string "MonaRonaDona".

After that, reboot your machine.

The virus puts a message on the screen. Aside from that, the task manager
is disabled, the header of Internet Explorer is modified and when trying to
open programs, those programs are shut down immediately.

Whatever you do, do NOT download and install the virus scanner named
UniGray. That "scanner" is a scam, a non-working piece of software. The
website tries to get you to register and pay for something that does nothing.

Hope this info helps those who come across this virus. It seems to be a
brand new occurence given the lack of solutions found on the Internet.
 
X-post to IE General and Security newsgroups.

It appears to be a harmless scam but you'll need expert assistance to remove
it; cf. cf. http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus and
http://forums.cnet.com/5208-6142_102-0.html?forumID=32&threadID=285491&messageID=2714709

cf.
https://www.bullguard.com/forum/10/Redirecting-and-suspecting-tro_60005.html
("a window poped up saying 'hello - i am monaronadona and i am a virus. i
have infected u and i will wreck your pc...'")

QED: How does the machine get infected?
====================================
Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
 
Hope this info helps those who come across this virus. It seems to be
a brand new occurence given the lack of solutions found on the Internet.

Barely 6-7 days old, in fact.
 
Anyone who'd be foolish enough to risk downloading/running such anonymously
posted files deserves what they get.
 
Does anyone know what the above Subject phrase is all about?
It appears when I access the Internet at the end of the page name.
For instance: The top line of my home page reads "(My ISP) Start Page -
MonaRonaDona"
It continues to appear on all pages that I access.

How to remove the monaronadona virus/spyware
http://securitynewsfromthenet.blogspot.com/2008/03/how-to-remove-monaronadona-virusspyware.html

click start>click Run >type in msconfig [press enter]>goto the Start-
up tab

....uncheck SRVSPOOL.exe click ok
....restart computer
 
paul said:
Does anyone know what the above Subject phrase is all about?
It appears when I access the Internet at the end of the page name.
For instance: The top line of my home page reads "(My ISP) Start Page -
MonaRonaDona"
It continues to appear on all pages that I access.

How to remove the monaronadona virus/spyware
http://securitynewsfromthenet.blogspot.com/2008/03/how-to-remove-monaronadona-virusspyware.html

click start>click Run >type in msconfig [press enter]>goto the Start-
up tab

...uncheck SRVSPOOL.exe click ok
...restart computer

You'll need to do more than that. See
http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top