Somebody added it to your Titlebar - likely through registry/group policy.
Look in your registry:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
"Window Title"=
--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html
"Lou" <lou...@toast.net> wrote in message
news:13s6in6...@corp.supernews.com...
If you are using Spywareblaster (and you should be), you can change that to
whatever you want it to be.
http://www.javacoolsoftware.com/spywareblaster.html
--
Mike Pawlak
>Lou wrote:
>> Does anyone know what the above Subject phrase is all about?
>> It appears when I access the Internet at the end of the page name.
>> For instance: The top line of my home page reads "(My ISP) Start Page
>> - MonaRonaDona"
>> It continues to appear on all pages that I access.
>> -----
>> Lou
>
>If you are using Spywareblaster (and you should be), you can change that to
>whatever you want it to be.
Without Spywareblaster: http://support.microsoft.com/kb/176497
Nice but that doesn't stop crap from installing on your system as well.
--
Mike Pawlak
If you had searched the net you would easily find the answers which people
have posted, but also you would find that you possibly have a virus
installed, so maybe it was time you did overhaul on your computer.
--
Bjarke Andersen
>> Without Spywareblaster: http://support.microsoft.com/kb/176497
>
>Nice but that doesn't stop crap from installing on your system as well.
I've been surfing the 'net for 15 years and have yet to get my first
virus/malware infestation.
I find that seriously hard to believe. Even if you keep your virus checker
as up to date as you can, there is always a short interval between the
release of a new virus and the virus checker gaining the ability to detect
it. As for other malware: have you tried a scan with AdAware and other
similar products? They usually turn up all sorts of surprises (and plenty
of them to boot).
As far as YOU know. Some viruses/malware don't manifest themselves to the
user of the machine - they just use the machine to propagate themselves to
other unprotected machines and then set up a network of zombie machines to
send spam emails without your knowledge.....
>> I've been surfing the 'net for 15 years and have yet to get my first
>> virus/malware infestation.
>
>I find that seriously hard to believe.
Sorry... it's true. And for probably half of that time I ran without
virus protection.
It's simple: I don't visit strange websites, don't download from
unknown sites, don't do file-sharing and I play safe with email.
>Even if you keep your virus checker
>as up to date as you can, there is always a short interval between the
>release of a new virus and the virus checker gaining the ability to detect
>it. As for other malware: have you tried a scan with AdAware and other
>similar products? They usually turn up all sorts of surprises (and plenty
>of them to boot).
Stopped doing that a couple years ago... all it ever found was
"tracking cookies". I now regularly check my cookie file and delete
those I don't want (CC Cleaner).
well all I can say is you've been EXTREMELY lucky. Do you get attachments by
email? Many viruses are spread by people opening attachments from PEOPLE
THEY KNOW.....
I'm well aware of that... one can hardly have spent as much time on
the 'net as I have and NOT know that. Why does it seem to bother you
so much that I have never had a virus or malware infestation?
It doesn't - I am concerned however that you may not KNOW you've ever had a
virus, and may, unwittingly, have spread it to others. That is why there are
virus checkers for Linux, not, to protect Linux, because it doesn't need
protecting, but to protect WINDOWS machines that might be in contact with
that Linux box.
It has frequently been demonstrated that if you connect a PC to the internet
without a virus checker then the longest it is likely to last before a virus
invades is around 15 minutes. And that is without even opening Internet
Explorer at all. Many of these viruses and worms simply look for
unprotected ports and install themselves. Many have become infected between
the time they install windows and installing the virus scanner and firewall
(though windows XP SP2 has alleviated the position a little by including a
firewall - of sorts).
> It's simple: I don't visit strange websites, don't download from
> unknown sites, don't do file-sharing and I play safe with email.
>
It is not necessary to do any of these things to get infected. For all you
know, your PC could have been silently infected with a bot of some sort and
is even as you read interfering with something somewhere - and you can be
totally unaware of it.
>>Even if you keep your virus checker
>>as up to date as you can, there is always a short interval between the
>>release of a new virus and the virus checker gaining the ability to detect
>>it. As for other malware: have you tried a scan with AdAware and other
>>similar products? They usually turn up all sorts of surprises (and plenty
>>of them to boot).
>
> Stopped doing that a couple years ago... all it ever found was
> "tracking cookies". I now regularly check my cookie file and delete
> those I don't want (CC Cleaner).
I don't do anything you don't do except keep my protection up to date, but
every malware scan still turns up a lot more than just 'tracking cookies'.
>It has frequently been demonstrated that if you connect a PC to the internet
>without a virus checker then the longest it is likely to last before a virus
>invades is around 15 minutes.
Whatta bunch of bullshit.
>> Stopped doing that a couple years ago... all it ever found was
>> "tracking cookies". I now regularly check my cookie file and delete
>> those I don't want (CC Cleaner).
>
>I don't do anything you don't do except keep my protection up to date, but
>every malware scan still turns up a lot more than just 'tracking cookies'.
Your problem, not mine. You are obviously more active visiting
strange websites than I am.
I can only assume that you believe that the only way malware can get to your
machine is if you visit a web site that carries that malware (that is
certainly the vein of your postings). Believe me, sunshine, that just ain't
the case. Although much malware does work that way, an equal or larger
number of species does not. These things can propagate themselves without
any help or assistance from you or I.
A few years ago we had the dubious privilege of watching a self replicating
worm spreading around our network of PCs without any of them looking at
anything on the internet or intranet. It might have been difficult to keep
up except that it actually slowed down probably due to all the network
traffic each copy was generating looking for new uninfected machines to
transfer itself to. It took a couple of hours to do the whole network of
several thousand machines, but it's probably accurate to say that the
infection also spread to other machines and networks conected to the
planetary network.
Shenan Stanley wrote:
> Somebody added it to your Titlebar - likely through registry/group
> policy.
> Look in your registry:
>
> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
> "Window Title"=
Lou wrote:
> Many thanks. Title removed.
> Was it a virus that placed it on my computer?
Virus installed applicatioon, malware. I should have stated,
"Somebody/something added it to your Titlebar - likely through
registry/group policy."
Most of the buzz on it points to some software called, "Unigray Antivirus".
Did you install that lately?
Have you rebooted and made sure the title does not get 'put back'?
> "PD43" <paul...@comcast.net> wrote in message
> news:prn7s3hmhem7mroes...@4ax.com...
>> "MAP" <mikepaw...@OVEhotmail.com> wrote:
>>
>>>> Without Spywareblaster: http://support.microsoft.com/kb/176497
>>>
>>>Nice but that doesn't stop crap from installing on your system as well.
>>
>> I've been surfing the 'net for 15 years and have yet to get my first
>> virus/malware infestation.
>
> I find that seriously hard to believe.
I'll say the same thing PD43 did. I have twice inserted an infected diskette
into the drive (both times were years ago), but both times my anti-virus
software alerted me and the diskette was taken out before any damage was
done. Other than that, nothing.
> Even if you keep your virus checker as up to date as you can, there is
> always a short interval between the release of a new virus and the virus
> checker gaining the ability to detect it. As for other malware: have you
> tried a scan with AdAware and other similar products? They usually turn
> up all sorts of surprises (and plenty of them to boot).
I run an anti-virus program and six different anti-spyware programs, in
addition to a firewall. In my case, nothing more than Tracking Cookies has
ever been found.
.
>
>"PD43" <paul...@comcast.net> wrote in message
>news:8s48s3lqgcr29ujtp...@4ax.com...
>> "M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:
>>
>>
>>>It has frequently been demonstrated that if you connect a PC to the
>>>internet
>>>without a virus checker then the longest it is likely to last before a
>>>virus
>>>invades is around 15 minutes.
>>
>> Whatta bunch of bullshit.
>>
>
>I can only assume that you believe that the only way malware can get to your
>machine is if you visit a web site that carries that malware (that is
>certainly the vein of your postings). Believe me, sunshine, that just ain't
>the case. Although much malware does work that way, an equal or larger
>number of species does not. These things can propagate themselves without
>any help or assistance from you or I.
You've taken it from "virus" to "malware". Fine. I'll read on.
>
>A few years ago we had the dubious privilege of watching a self replicating
>worm spreading around our network of PCs without any of them looking at
>anything on the internet or intranet.
I'm not on a network, bucko.
> It might have been difficult to keep
>up except that it actually slowed down probably due to all the network
>traffic each copy was generating looking for new uninfected machines to
>transfer itself to. It took a couple of hours to do the whole network of
>several thousand machines, but it's probably accurate to say that the
>infection also spread to other machines and networks conected to the
>planetary network.
You're assertion that a "virus" (which you now correctly call a
"worm") can enter my system within 15 minutes of starting - if I don't
have a virus checker operating - is still utter bullshit.
>I run an anti-virus program and six different anti-spyware programs, in
>addition to a firewall. In my case, nothing more than Tracking Cookies has
>ever been found.
I have been running AVG Anti-virus for quite some time now. Prior to
XP, I rarely ran an anti-virus... mainly because my system prior to
installing XP was minimal, and didn't have a lot of RAM.
That, plus the fact that worms, etc. were less prevalent prior to that
time made my exposure less probable.
I still don't run any resident malware obstructers, and when I ran the
free scanning programs from several vendors, they ONLY found tracking
cookies (doubleclick, etc. ) as problems.
--
jeese45
>I just now did that and Mona etc. is back.
>I went to regedit again and Mona etc. was listed as the Window Title. I
>deleted that name and added my own.
>I rebooted my computer and Mona etc. was back.
>I tried without success to "save" the registry after I had made the change.
>Any further help would be greatly appreciated.
Do you have anything running that is supposed to keep you or anyone
else from messing with Explorer's settings???
Like any malware blocker or anti virus program that has a "watch"
function that continuously monitors your system??
Malware is a superset of virus.
>>
>>A few years ago we had the dubious privilege of watching a self
>>replicating
>>worm spreading around our network of PCs without any of them looking at
>>anything on the internet or intranet.
>
> I'm not on a network, bucko.
>
You said that you surf the internet. The internet is a very large network.
Ergo, you *are* on a network.
>> It might have been difficult to keep
>>up except that it actually slowed down probably due to all the network
>>traffic each copy was generating looking for new uninfected machines to
>>transfer itself to. It took a couple of hours to do the whole network of
>>several thousand machines, but it's probably accurate to say that the
>>infection also spread to other machines and networks conected to the
>>planetary network.
>
> You're assertion that a "virus" (which you now correctly call a
> "worm") can enter my system within 15 minutes of starting - if I don't
> have a virus checker operating - is still utter bullshit.
Please yourself sunshine.
>
> You're assertion that a "virus" (which you now correctly call a
> "worm") can enter my system within 15 minutes of starting - if I don't
> have a virus checker operating - is still utter bullshit.
WRONG. Look up about the Blaster Worm (for one example). This is why XP
SP2 has the firewall turned ON by default...prior to that it was turned
OFF by default, and I have personal experience of an un-protected
machine being infected in TWENTY SECONDS after having connected to the
internet with no protection.
Look it up, it's well documented.
Default Feeds - containing:
{2D90FCA5-46D8-48B4-AE7C-ODD5A9ECAB8A},
{6ACA2234-7009-4EOB-AB59-8CB98D3CD7AD},
{DDB93AAD-OCFB-4ACB-83FD-EDFA5B6F6DC4}
FeatureControl - containing:
FEATURE_LOCALMACHINE_LOCKDOWN. In this folder is a subfolder
entitled "Settings."
I have looked thoroughly through each of these folders and I do not see the
"Window Title - MonaRonaDona."
What should I do now?
Thanks in advance, Mary
I was able to fix the problem and here is how.
The virus installs an executable SRVSPOOL.EXE in the startup folder of the
all users account. Click Start/Programs/Startup, right click the
SRVSPOOL.EXE entry and delete it. How to fix the header of your Internet
explorer and how to re-enable taskmanager, is posted in numerous postings
online.
Re-enable Task Manager: http://www.kellys-korner-xp.com/xp_tweaks.htm
Go to this page and try #51 from the right column. Click on "enable the task
manager."
Modify header of Internet explorer:
http://answers.yahoo.com/question/index?qid=20080223085704AA1dibb
(optionally, you can manually type "Microsoft Internet Explorer" to replace
the string "MonaRonaDona".
After that, reboot your machine.
The virus puts a message on the screen. Aside from that, the task manager
is disabled, the header of Internet Explorer is modified and when trying to
open programs, those programs are shut down immediately.
Whatever you do, do NOT download and install the virus scanner named
UniGray. That "scanner" is a scam, a non-working piece of software. The
website tries to get you to register and pay for something that does nothing.
Hope this info helps those who come across this virus. It seems to be a
brand new occurence given the lack of solutions found on the Internet.
"Lou" wrote:
> Does anyone know what the above Subject phrase is all about?
> It appears when I access the Internet at the end of the page name.
> For instance: The top line of my home page reads "(My ISP) Start Page -
> MonaRonaDona"
> It continues to appear on all pages that I access.
> -----
> Lou
>
>
>
Despite lack of information on the Internet, I was able to pinpoint the
culprit that was causing my machine to start acting up due to the
MonaRonaDona virus.
I was able to fix the problem and here is how.
The virus installs an executable SRVSPOOL.EXE in the startup folder of
the all users account. Click Start/Programs/Startup, right click the
SRVSPOOL.EXE entry and delete it. How to fix the header of your
Internet explorer and how to re-enable taskmanager, is posted in
numerous postings online.
Re-enable Task Manager: 'Troubleshooting Windows XP, Tweaks and Fixes
for Windows XP' (http://www.kellys-korner-xp.com/xp_tweaks.htm)
Go to this page and try #51 from the right column. Click on "enable the
task
manager."
Modify header of Internet explorer: 'How do i get rid of monaronadona
on top bar of my homepage? - Yahoo! Answers'
(http://answers.yahoo.com/question/index?qid=20080223085704AA1dibb)
It appears to be a harmless scam but you'll need expert assistance to remove
it; cf. cf. http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus and
http://forums.cnet.com/5208-6142_102-0.html?forumID=32&threadID=285491&messageID=2714709
cf.
https://www.bullguard.com/forum/10/Redirecting-and-suspecting-tro_60005.html
("a window poped up saying 'hello - i am monaronadona and i am a virus. i
have infected u and i will wreck your pc...'")
QED: How does the machine get infected?
====================================
Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315
Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.
Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware
When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**
If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/
Barely 6-7 days old, in fact.
You can download the “free monaronadona remover” from:
'RapidShare: 1-Click Webhosting'
(http://rapidshare.com/files/95966868/RemoveMonaRonaDona.exe)
OR shrinked RAR version
'RapidShare: 1-Click Webhosting'
(http://rapidshare.com/files/95964607/RemoveMonaRonaDona.rar) (small in
size but you will need winrar to extract the exe)
=========================================
I went to Run, typed in MSCONFIG, then to Startup.
While in Startup, I unchecked the SRVSPOOL.exe file which was listed
there. I re-started my computer and it was gone. I was then able to
delete shortcuts to that exe. file also.
Now the only problem I have, is it still on my blue titlebar. It is
also still listed on the Startup but unchecked.
How do I go about removing it from both those places permanently ??
I ran AML Registry Cleaner and was able to find and delete some entries
but not all ??
I also ran Spybot, but it didn't come up with anything.
I heard there is a way to remove it from the blue title bar, but don't
know how to do it, any suggestions ?
:o
I am unable to do a "run" on my Registry, for some reason it won't let
me on ???
MonaRonaDona also appears on the Titlebar, no matter where I go to.
I have run Spybot, it didn't delete it (ugh). I ran Nortons, didn't
delete it (ugh) ! I ran Ad-Aware SE , didn't delete it either ! I am at
a loss right now.
I have been searching all day for a solution from different forums, but
apparently this is quite new and no one seems to have a plan that will
rectify this problem ??
I also went to Rapidshare but there was no solution there. It asked me
what file I wanted to DL, but where is the remover for this MonaRonaDona
? This is web server ??? or what ?? I saw nothing for the remover.
Anyone that has a solution I would love to try it .
Thank you in advance
>I heard there is a way to remove it from the blue title bar, but don't
>know how to do it, any suggestions ?
NOT AGAIN!!
OK... check this out:
How to remove the monaronadona virus/spyware
http://securitynewsfromthenet.blogspot.com/2008/03/how-to-remove-monaronadona-virusspyware.html
click start>click Run >type in msconfig [press enter]>goto the Start-
up tab
...uncheck SRVSPOOL.exe click ok
...restart computer
You'll need to do more than that. See
http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus
--
~Robear Dyer (PA Bear)
PA Bear [MS MVP] wrote:
> X-post to IE General and Security newsgroups.
>
> It appears to be a harmless scam but you'll need expert assistance to
> remove
> it; cf. cf. http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus
> and
> http://forums.cnet.com/5208-6142_102-0.html?forumID=32&threadID=285491&messageID=2714709
> cf.
> https://www.bullguard.com/forum/10/Redirecting-and-suspecting-tro_60005.html
> ("a window poped up saying 'hello - i am monaronadona and i am a virus. i
> have infected u and i will wreck your pc...'")
>
> QED: How does the machine get infected?
<snip>
Thank you Spywareblaster !
My computer should be free of this virus, trojan, worm, whatever it
was.
I now have extra protection with Spywareblaster.
It took alot of searching and thought but I am finally free of it, I
hope ??
The steps I took were easy;
Disable System Restore , restore later when done.
Start in Safe mode if preferred,
Run > Msconfig > Start-up
..uncheck SRVSPOOL.exe
..restart computer
MonaRonaDona should be gone !!!
To change blue title bar:
Download Spywareblaster and follow directions, very easy !
Make sure you remove/delete any shortcuts it left on your computer
also.
Check your Startup menu on the Start/Programs and delete from there as
well.
Delete from your Recycle Bin as well.
This should solve your problem with MonaRonaDona
I have not seen the MonaRonaDona appear on any window since I did
this.
With all the tools I have, you would think I could, but, alas, I cannot
completely get rid of it.
I have read the articles from Castner, but, they are too technical for
me.
The only problem I have is the constant Malware that re-routes my
Search pages, but only when I use Google on IE. , which is my home page.
It doesn't happen on MSN search.
Another annoying problem I have is other windows showing up with AVS
System Scanners, etc. , wanting me to DL their programs. This happens
only when I first click on one of my icons on the desktop, example:
Hotmail
I do spyware scans everyday , I have virus protection with Nortons, I
do registry checks, the whole nine yards, but, they keep coming back !
I feel at this time the only option left for me is to reformat my
computer!
I have HijackThis, Spybot, Spywareblaster, Ad-Aware SE, AML Registry
Cleaner & Nortons, how much more do I need to protect my computer ???
They all list the malware that I am having problems with, but none seem
to remove it completely ! Very frustrating !