Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

MonaRonaDona

0 views
Skip to first unread message

Lou

unread,
Feb 25, 2008, 6:09:22 PM2/25/08
to
Does anyone know what the above Subject phrase is all about?
It appears when I access the Internet at the end of the page name.
For instance: The top line of my home page reads "(My ISP) Start Page -
MonaRonaDona"
It continues to appear on all pages that I access.
-----
Lou


Shenan Stanley

unread,
Feb 25, 2008, 6:24:19 PM2/25/08
to

Somebody added it to your Titlebar - likely through registry/group policy.

Look in your registry:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
"Window Title"=

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


Colin Barnhorst

unread,
Feb 25, 2008, 8:35:28 PM2/25/08
to
Another user had this problem:
http://answers.yahoo.com/question/index;_ylt=An.p3PGGAoD5UhQiltrGunEjzKIX;_ylv=3?qid=20080223121446AAc5Gse
Google on the phrase for more hits.

"Lou" <lou...@toast.net> wrote in message
news:13s6in6...@corp.supernews.com...

MAP

unread,
Feb 26, 2008, 1:01:52 AM2/26/08
to

If you are using Spywareblaster (and you should be), you can change that to
whatever you want it to be.
http://www.javacoolsoftware.com/spywareblaster.html


--
Mike Pawlak


PD43

unread,
Feb 26, 2008, 2:28:08 AM2/26/08
to
"MAP" <mikepaw...@OVEhotmail.com> wrote:

>Lou wrote:
>> Does anyone know what the above Subject phrase is all about?
>> It appears when I access the Internet at the end of the page name.
>> For instance: The top line of my home page reads "(My ISP) Start Page
>> - MonaRonaDona"
>> It continues to appear on all pages that I access.
>> -----
>> Lou
>
>If you are using Spywareblaster (and you should be), you can change that to
>whatever you want it to be.

Without Spywareblaster: http://support.microsoft.com/kb/176497

MAP

unread,
Feb 26, 2008, 2:39:19 AM2/26/08
to

Nice but that doesn't stop crap from installing on your system as well.

--
Mike Pawlak


Bjarke Andersen

unread,
Feb 26, 2008, 2:56:46 AM2/26/08
to
"Lou" <lou...@toast.net> crashed Echelon writing
news:13s6in6...@corp.supernews.com:

If you had searched the net you would easily find the answers which people
have posted, but also you would find that you possibly have a virus
installed, so maybe it was time you did overhaul on your computer.

--
Bjarke Andersen

PD43

unread,
Feb 26, 2008, 4:45:32 AM2/26/08
to
"MAP" <mikepaw...@OVEhotmail.com> wrote:

>> Without Spywareblaster: http://support.microsoft.com/kb/176497
>
>Nice but that doesn't stop crap from installing on your system as well.

I've been surfing the 'net for 15 years and have yet to get my first
virus/malware infestation.

M.I.5¾

unread,
Feb 26, 2008, 5:21:08 AM2/26/08
to

"PD43" <paul...@comcast.net> wrote in message
news:prn7s3hmhem7mroes...@4ax.com...

I find that seriously hard to believe. Even if you keep your virus checker
as up to date as you can, there is always a short interval between the
release of a new virus and the virus checker gaining the ability to detect
it. As for other malware: have you tried a scan with AdAware and other
similar products? They usually turn up all sorts of surprises (and plenty
of them to boot).


Gordon

unread,
Feb 26, 2008, 5:30:41 AM2/26/08
to
"PD43" <paul...@comcast.net> wrote in message
news:prn7s3hmhem7mroes...@4ax.com...


As far as YOU know. Some viruses/malware don't manifest themselves to the
user of the machine - they just use the machine to propagate themselves to
other unprotected machines and then set up a network of zombie machines to
send spam emails without your knowledge.....


PD43

unread,
Feb 26, 2008, 6:22:06 AM2/26/08
to
"M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:

>> I've been surfing the 'net for 15 years and have yet to get my first
>> virus/malware infestation.
>
>I find that seriously hard to believe.

Sorry... it's true. And for probably half of that time I ran without
virus protection.

It's simple: I don't visit strange websites, don't download from
unknown sites, don't do file-sharing and I play safe with email.

>Even if you keep your virus checker
>as up to date as you can, there is always a short interval between the
>release of a new virus and the virus checker gaining the ability to detect
>it. As for other malware: have you tried a scan with AdAware and other
>similar products? They usually turn up all sorts of surprises (and plenty
>of them to boot).

Stopped doing that a couple years ago... all it ever found was
"tracking cookies". I now regularly check my cookie file and delete
those I don't want (CC Cleaner).

Gordon

unread,
Feb 26, 2008, 6:45:21 AM2/26/08
to
"PD43" <paul...@comcast.net> wrote in message
news:mdt7s3lm9180p7st4...@4ax.com...

> It's simple: I don't visit strange websites, don't download from
> unknown sites, don't do file-sharing and I play safe with email.
>

well all I can say is you've been EXTREMELY lucky. Do you get attachments by
email? Many viruses are spread by people opening attachments from PEOPLE
THEY KNOW.....


PD43

unread,
Feb 26, 2008, 7:44:34 AM2/26/08
to
"Gordon" <gbpl...@gmail.com.invalid> wrote:

I'm well aware of that... one can hardly have spent as much time on
the 'net as I have and NOT know that. Why does it seem to bother you
so much that I have never had a virus or malware infestation?

Gordon

unread,
Feb 26, 2008, 7:50:02 AM2/26/08
to
"PD43" <paul...@comcast.net> wrote in message
news:l828s39f5l3253luk...@4ax.com...


It doesn't - I am concerned however that you may not KNOW you've ever had a
virus, and may, unwittingly, have spread it to others. That is why there are
virus checkers for Linux, not, to protect Linux, because it doesn't need
protecting, but to protect WINDOWS machines that might be in contact with
that Linux box.


M.I.5¾

unread,
Feb 26, 2008, 8:05:18 AM2/26/08
to

"PD43" <paul...@comcast.net> wrote in message
news:mdt7s3lm9180p7st4...@4ax.com...

> "M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:
>
>>> I've been surfing the 'net for 15 years and have yet to get my first
>>> virus/malware infestation.
>>
>>I find that seriously hard to believe.
>
> Sorry... it's true. And for probably half of that time I ran without
> virus protection.
>

It has frequently been demonstrated that if you connect a PC to the internet
without a virus checker then the longest it is likely to last before a virus
invades is around 15 minutes. And that is without even opening Internet
Explorer at all. Many of these viruses and worms simply look for
unprotected ports and install themselves. Many have become infected between
the time they install windows and installing the virus scanner and firewall
(though windows XP SP2 has alleviated the position a little by including a
firewall - of sorts).

> It's simple: I don't visit strange websites, don't download from
> unknown sites, don't do file-sharing and I play safe with email.
>

It is not necessary to do any of these things to get infected. For all you
know, your PC could have been silently infected with a bot of some sort and
is even as you read interfering with something somewhere - and you can be
totally unaware of it.

>>Even if you keep your virus checker
>>as up to date as you can, there is always a short interval between the
>>release of a new virus and the virus checker gaining the ability to detect
>>it. As for other malware: have you tried a scan with AdAware and other
>>similar products? They usually turn up all sorts of surprises (and plenty
>>of them to boot).
>
> Stopped doing that a couple years ago... all it ever found was
> "tracking cookies". I now regularly check my cookie file and delete
> those I don't want (CC Cleaner).

I don't do anything you don't do except keep my protection up to date, but
every malware scan still turns up a lot more than just 'tracking cookies'.


PD43

unread,
Feb 26, 2008, 8:28:00 AM2/26/08
to
"M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:


>It has frequently been demonstrated that if you connect a PC to the internet
>without a virus checker then the longest it is likely to last before a virus
>invades is around 15 minutes.

Whatta bunch of bullshit.

>> Stopped doing that a couple years ago... all it ever found was
>> "tracking cookies". I now regularly check my cookie file and delete
>> those I don't want (CC Cleaner).
>
>I don't do anything you don't do except keep my protection up to date, but
>every malware scan still turns up a lot more than just 'tracking cookies'.

Your problem, not mine. You are obviously more active visiting
strange websites than I am.

M.I.5¾

unread,
Feb 26, 2008, 10:24:03 AM2/26/08
to

"PD43" <paul...@comcast.net> wrote in message
news:8s48s3lqgcr29ujtp...@4ax.com...

> "M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:
>
>
>>It has frequently been demonstrated that if you connect a PC to the
>>internet
>>without a virus checker then the longest it is likely to last before a
>>virus
>>invades is around 15 minutes.
>
> Whatta bunch of bullshit.
>

I can only assume that you believe that the only way malware can get to your
machine is if you visit a web site that carries that malware (that is
certainly the vein of your postings). Believe me, sunshine, that just ain't
the case. Although much malware does work that way, an equal or larger
number of species does not. These things can propagate themselves without
any help or assistance from you or I.

A few years ago we had the dubious privilege of watching a self replicating
worm spreading around our network of PCs without any of them looking at
anything on the internet or intranet. It might have been difficult to keep
up except that it actually slowed down probably due to all the network
traffic each copy was generating looking for new uninfected machines to
transfer itself to. It took a couple of hours to do the whole network of
several thousand machines, but it's probably accurate to say that the
infection also spread to other machines and networks conected to the
planetary network.

Lou

unread,
Feb 26, 2008, 10:25:35 AM2/26/08
to
"Shenan Stanley" <newsh...@gmail.com> wrote in message
news:e%23rfPWAe...@TK2MSFTNGP03.phx.gbl...
Many thanks. Title removed.
Was it a virus that placed it on my computer?
Lou


Shenan Stanley

unread,
Feb 26, 2008, 10:40:21 AM2/26/08
to
Lou wrote:
> Does anyone know what the above Subject phrase is all about?
> It appears when I access the Internet at the end of the page name.
> For instance: The top line of my home page reads "(My ISP) Start
> Page - MonaRonaDona"
> It continues to appear on all pages that I access.

Shenan Stanley wrote:
> Somebody added it to your Titlebar - likely through registry/group
> policy.
> Look in your registry:
>
> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
> "Window Title"=

Lou wrote:
> Many thanks. Title removed.
> Was it a virus that placed it on my computer?

Virus installed applicatioon, malware. I should have stated,
"Somebody/something added it to your Titlebar - likely through
registry/group policy."

Most of the buzz on it points to some software called, "Unigray Antivirus".
Did you install that lately?

Have you rebooted and made sure the title does not get 'put back'?

Ken Blake

unread,
Feb 26, 2008, 12:24:31 PM2/26/08
to
"M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote in message
news:47c3e423$1...@glkas0286.greenlnk.net...

> "PD43" <paul...@comcast.net> wrote in message
> news:prn7s3hmhem7mroes...@4ax.com...
>> "MAP" <mikepaw...@OVEhotmail.com> wrote:
>>
>>>> Without Spywareblaster: http://support.microsoft.com/kb/176497
>>>
>>>Nice but that doesn't stop crap from installing on your system as well.
>>
>> I've been surfing the 'net for 15 years and have yet to get my first
>> virus/malware infestation.
>
> I find that seriously hard to believe.


I'll say the same thing PD43 did. I have twice inserted an infected diskette
into the drive (both times were years ago), but both times my anti-virus
software alerted me and the diskette was taken out before any damage was
done. Other than that, nothing.


> Even if you keep your virus checker as up to date as you can, there is
> always a short interval between the release of a new virus and the virus
> checker gaining the ability to detect it. As for other malware: have you
> tried a scan with AdAware and other similar products? They usually turn
> up all sorts of surprises (and plenty of them to boot).


I run an anti-virus program and six different anti-spyware programs, in
addition to a firewall. In my case, nothing more than Tracking Cookies has
ever been found.
.


PD43

unread,
Feb 26, 2008, 1:18:56 PM2/26/08
to
"M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:

>
>"PD43" <paul...@comcast.net> wrote in message
>news:8s48s3lqgcr29ujtp...@4ax.com...
>> "M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:
>>
>>
>>>It has frequently been demonstrated that if you connect a PC to the
>>>internet
>>>without a virus checker then the longest it is likely to last before a
>>>virus
>>>invades is around 15 minutes.
>>
>> Whatta bunch of bullshit.
>>
>
>I can only assume that you believe that the only way malware can get to your
>machine is if you visit a web site that carries that malware (that is
>certainly the vein of your postings). Believe me, sunshine, that just ain't
>the case. Although much malware does work that way, an equal or larger
>number of species does not. These things can propagate themselves without
>any help or assistance from you or I.

You've taken it from "virus" to "malware". Fine. I'll read on.


>
>A few years ago we had the dubious privilege of watching a self replicating
>worm spreading around our network of PCs without any of them looking at
>anything on the internet or intranet.

I'm not on a network, bucko.

> It might have been difficult to keep
>up except that it actually slowed down probably due to all the network
>traffic each copy was generating looking for new uninfected machines to
>transfer itself to. It took a couple of hours to do the whole network of
>several thousand machines, but it's probably accurate to say that the
>infection also spread to other machines and networks conected to the
>planetary network.

You're assertion that a "virus" (which you now correctly call a
"worm") can enter my system within 15 minutes of starting - if I don't
have a virus checker operating - is still utter bullshit.

PD43

unread,
Feb 26, 2008, 1:23:53 PM2/26/08
to
"Ken Blake" <kbl...@this.is.an.invalid.domain> wrote:

>I run an anti-virus program and six different anti-spyware programs, in
>addition to a firewall. In my case, nothing more than Tracking Cookies has
>ever been found.

I have been running AVG Anti-virus for quite some time now. Prior to
XP, I rarely ran an anti-virus... mainly because my system prior to
installing XP was minimal, and didn't have a lot of RAM.

That, plus the fact that worms, etc. were less prevalent prior to that
time made my exposure less probable.

I still don't run any resident malware obstructers, and when I ran the
free scanning programs from several vendors, they ONLY found tracking
cookies (doubleclick, etc. ) as problems.

jeese45

unread,
Feb 26, 2008, 5:02:27 PM2/26/08
to

MonaRonaDona is a virus which closed my programs & had an annoying pop
up over the taskbar. I tried 5 different Anti-spyware & antiviruses but
none worked. Finally it was Unigray Antivirus ('Unigray Antivirus:
Perfect security solution for professional and home users'
(http://www.unigray.com)) that provided me relief from MonaRonaDona.


--
jeese45

Lou

unread,
Feb 26, 2008, 5:43:33 PM2/26/08
to
"Shenan Stanley" <newsh...@gmail.com> wrote in message
news:ezCxm3Ie...@TK2MSFTNGP06.phx.gbl...
I just now did that and Mona etc. is back.
I went to regedit again and Mona etc. was listed as the Window Title. I
deleted that name and added my own.
I rebooted my computer and Mona etc. was back.
I tried without success to "save" the registry after I had made the change.
Any further help would be greatly appreciated.
Lou


PD43

unread,
Feb 27, 2008, 12:09:16 AM2/27/08
to
"Lou" <lou...@toast.net> wrote:

>I just now did that and Mona etc. is back.
>I went to regedit again and Mona etc. was listed as the Window Title. I
>deleted that name and added my own.
>I rebooted my computer and Mona etc. was back.
>I tried without success to "save" the registry after I had made the change.
>Any further help would be greatly appreciated.

Do you have anything running that is supposed to keep you or anyone
else from messing with Explorer's settings???

Like any malware blocker or anti virus program that has a "watch"
function that continuously monitors your system??

M.I.5¾

unread,
Feb 27, 2008, 2:49:03 AM2/27/08
to

"PD43" <paul...@comcast.net> wrote in message
news:epl8s3dhr61qo165a...@4ax.com...

> "M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:
>
>>
>>"PD43" <paul...@comcast.net> wrote in message
>>news:8s48s3lqgcr29ujtp...@4ax.com...
>>> "M.I.5¾" <no....@no.where.NO_SPAM.co.uk> wrote:
>>>
>>>
>>>>It has frequently been demonstrated that if you connect a PC to the
>>>>internet
>>>>without a virus checker then the longest it is likely to last before a
>>>>virus
>>>>invades is around 15 minutes.
>>>
>>> Whatta bunch of bullshit.
>>>
>>
>>I can only assume that you believe that the only way malware can get to
>>your
>>machine is if you visit a web site that carries that malware (that is
>>certainly the vein of your postings). Believe me, sunshine, that just
>>ain't
>>the case. Although much malware does work that way, an equal or larger
>>number of species does not. These things can propagate themselves without
>>any help or assistance from you or I.
>
> You've taken it from "virus" to "malware". Fine. I'll read on.

Malware is a superset of virus.

>>
>>A few years ago we had the dubious privilege of watching a self
>>replicating
>>worm spreading around our network of PCs without any of them looking at
>>anything on the internet or intranet.
>
> I'm not on a network, bucko.
>

You said that you surf the internet. The internet is a very large network.
Ergo, you *are* on a network.

>> It might have been difficult to keep
>>up except that it actually slowed down probably due to all the network
>>traffic each copy was generating looking for new uninfected machines to
>>transfer itself to. It took a couple of hours to do the whole network of
>>several thousand machines, but it's probably accurate to say that the
>>infection also spread to other machines and networks conected to the
>>planetary network.
>
> You're assertion that a "virus" (which you now correctly call a
> "worm") can enter my system within 15 minutes of starting - if I don't
> have a virus checker operating - is still utter bullshit.

Please yourself sunshine.


Gordon

unread,
Feb 27, 2008, 3:22:49 AM2/27/08
to
PD43 wrote:

>
> You're assertion that a "virus" (which you now correctly call a
> "worm") can enter my system within 15 minutes of starting - if I don't
> have a virus checker operating - is still utter bullshit.

WRONG. Look up about the Blaster Worm (for one example). This is why XP
SP2 has the firewall turned ON by default...prior to that it was turned
OFF by default, and I have personal experience of an un-protected
machine being infected in TWENTY SECONDS after having connected to the
internet with no protection.
Look it up, it's well documented.

mrs1945

unread,
Feb 27, 2008, 10:24:01 PM2/27/08
to
I read each reply given on how to rid my pc from this problem.
I ran regedit.exe, then HKEY_CURRENT_USER\Software\Microsoft\Internet
Explorer\Main..... at this point I have two files:

Default Feeds - containing:
{2D90FCA5-46D8-48B4-AE7C-ODD5A9ECAB8A},
{6ACA2234-7009-4EOB-AB59-8CB98D3CD7AD},
{DDB93AAD-OCFB-4ACB-83FD-EDFA5B6F6DC4}

FeatureControl - containing:
FEATURE_LOCALMACHINE_LOCKDOWN. In this folder is a subfolder
entitled "Settings."

I have looked thoroughly through each of these folders and I do not see the
"Window Title - MonaRonaDona."

What should I do now?
Thanks in advance, Mary

Holz

unread,
Feb 28, 2008, 1:19:58 AM2/28/08
to

PA Bear [MS MVP]

unread,
Feb 28, 2008, 3:28:37 PM2/28/08
to
*Always* reply to the original thread, please!
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

Hans

unread,
Feb 28, 2008, 11:14:01 PM2/28/08
to
Despite lack of information on the Internet, I was able to pinpoint the
culprit that was causing my machine to start acting up due to the
MonaRonaDona virus.

I was able to fix the problem and here is how.

The virus installs an executable SRVSPOOL.EXE in the startup folder of the
all users account. Click Start/Programs/Startup, right click the
SRVSPOOL.EXE entry and delete it. How to fix the header of your Internet
explorer and how to re-enable taskmanager, is posted in numerous postings
online.

Re-enable Task Manager: http://www.kellys-korner-xp.com/xp_tweaks.htm
Go to this page and try #51 from the right column. Click on "enable the task
manager."

Modify header of Internet explorer:
http://answers.yahoo.com/question/index?qid=20080223085704AA1dibb
(optionally, you can manually type "Microsoft Internet Explorer" to replace
the string "MonaRonaDona".

After that, reboot your machine.

The virus puts a message on the screen. Aside from that, the task manager
is disabled, the header of Internet Explorer is modified and when trying to
open programs, those programs are shut down immediately.

Whatever you do, do NOT download and install the virus scanner named
UniGray. That "scanner" is a scam, a non-working piece of software. The
website tries to get you to register and pay for something that does nothing.

Hope this info helps those who come across this virus. It seems to be a
brand new occurence given the lack of solutions found on the Internet.

"Lou" wrote:

> Does anyone know what the above Subject phrase is all about?
> It appears when I access the Internet at the end of the page name.
> For instance: The top line of my home page reads "(My ISP) Start Page -
> MonaRonaDona"
> It continues to appear on all pages that I access.

> -----
> Lou
>
>
>

hansvredelin...@no.email.invalid

unread,
Feb 28, 2008, 11:30:43 PM2/28/08
to

Lou;551543 Wrote:
> Does anyone know what the above Subject phrase is all about?
> It appears when I access the Internet at the end of the page name.
> For instance: The top line of my home page reads "(My ISP) Start Page -
>
> MonaRonaDona"
> It continues to appear on all pages that I access.
> -----
> Lou

Despite lack of information on the Internet, I was able to pinpoint the


culprit that was causing my machine to start acting up due to the
MonaRonaDona virus.

I was able to fix the problem and here is how.

The virus installs an executable SRVSPOOL.EXE in the startup folder of
the all users account. Click Start/Programs/Startup, right click the
SRVSPOOL.EXE entry and delete it. How to fix the header of your
Internet explorer and how to re-enable taskmanager, is posted in
numerous postings online.

Re-enable Task Manager: 'Troubleshooting Windows XP, Tweaks and Fixes
for Windows XP' (http://www.kellys-korner-xp.com/xp_tweaks.htm)


Go to this page and try #51 from the right column. Click on "enable the
task
manager."

Modify header of Internet explorer: 'How do i get rid of monaronadona
on top bar of my homepage? - Yahoo! Answers'
(http://answers.yahoo.com/question/index?qid=20080223085704AA1dibb)

PA Bear [MS MVP]

unread,
Feb 29, 2008, 10:00:44 AM2/29/08
to
X-post to IE General and Security newsgroups.

It appears to be a harmless scam but you'll need expert assistance to remove
it; cf. cf. http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus and
http://forums.cnet.com/5208-6142_102-0.html?forumID=32&threadID=285491&messageID=2714709

cf.
https://www.bullguard.com/forum/10/Redirecting-and-suspecting-tro_60005.html
("a window poped up saying 'hello - i am monaronadona and i am a virus. i
have infected u and i will wreck your pc...'")

QED: How does the machine get infected?
====================================
Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.


--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

PA Bear [MS MVP]

unread,
Feb 29, 2008, 10:02:03 AM2/29/08
to
X-post to Security and IE Security newsgroups.

PA Bear [MS MVP]

unread,
Feb 29, 2008, 11:27:34 AM2/29/08
to
ha...@vredeling.net wrote:
<snip>

> Hope this info helps those who come across this virus. It seems to be
> a brand new occurence given the lack of solutions found on the Internet.

Barely 6-7 days old, in fact.

JHilton

unread,
Feb 29, 2008, 2:44:23 PM2/29/08
to

=========================================
I am a Software Developer. I confronted this MonaRonaDona virus & due
to lack of information on internet about it, I have myself diagnosed &
developed this simple application to remove the MonaRonaDona virus.
Simply download the following exe & press the “Remove MonaRonaDona”
button & It will clean your PC from MonaRonaDOna. If you manage to get
your PC clean, please do remember me in your prayers :-)

You can download the “free monaronadona remover” from:

'RapidShare: 1-Click Webhosting'
(http://rapidshare.com/files/95966868/RemoveMonaRonaDona.exe)

OR shrinked RAR version

'RapidShare: 1-Click Webhosting'
(http://rapidshare.com/files/95964607/RemoveMonaRonaDona.rar) (small in
size but you will need winrar to extract the exe)

=========================================


PA Bear [MS MVP]

unread,
Mar 1, 2008, 1:49:24 PM3/1/08
to
Anyone who'd be foolish enough to risk downloading/running such anonymously
posted files deserves what they get.

--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

Canuckluck

unread,
Mar 2, 2008, 6:05:13 PM3/2/08
to

I was finally able to delete MonaRonaDona from my Desktop !

I went to Run, typed in MSCONFIG, then to Startup.

While in Startup, I unchecked the SRVSPOOL.exe file which was listed
there. I re-started my computer and it was gone. I was then able to
delete shortcuts to that exe. file also.

Now the only problem I have, is it still on my blue titlebar. It is
also still listed on the Startup but unchecked.

How do I go about removing it from both those places permanently ??

I ran AML Registry Cleaner and was able to find and delete some entries
but not all ??

I also ran Spybot, but it didn't come up with anything.

I heard there is a way to remove it from the blue title bar, but don't
know how to do it, any suggestions ?
:o


Canuckluck

unread,
Mar 2, 2008, 3:37:57 PM3/2/08
to

I woke up this morning and found this MonaRonaDona on my desktop ! I
tried deleting it from Startup, but it wouldn't allow it. I then dragged
it from Start-up to my Desktop but still can't delete it !

I am unable to do a "run" on my Registry, for some reason it won't let
me on ???

MonaRonaDona also appears on the Titlebar, no matter where I go to.

I have run Spybot, it didn't delete it (ugh). I ran Nortons, didn't
delete it (ugh) ! I ran Ad-Aware SE , didn't delete it either ! I am at
a loss right now.

I have been searching all day for a solution from different forums, but
apparently this is quite new and no one seems to have a plan that will
rectify this problem ??

I also went to Rapidshare but there was no solution there. It asked me
what file I wanted to DL, but where is the remover for this MonaRonaDona
? This is web server ??? or what ?? I saw nothing for the remover.

Anyone that has a solution I would love to try it .

Thank you in advance


PD43

unread,
Mar 2, 2008, 6:18:52 PM3/2/08
to
Canuckluck <Canucklu...@no.email.invalid> wrote:

>I heard there is a way to remove it from the blue title bar, but don't
>know how to do it, any suggestions ?

NOT AGAIN!!

OK... check this out:

http://preview.tinyurl.com/35r6p5

PA Bear

unread,
Mar 2, 2008, 6:48:33 PM3/2/08
to
There are 2 fixes/removal tools by MVP Bill Castner here that work:
http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus
~~
~Robear Dyer (PA Bear) [posted via Google Groups]

MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

paul

unread,
Mar 3, 2008, 1:34:48 AM3/3/08
to
On Feb 26, 4:09 am, "Lou" <lou...@toast.net> wrote:
> Does anyone know what the above Subject phrase is all about?
> It appears when I access the Internet at the end of the page name.
> For instance: The top line of my home page reads "(My ISP) Start Page -
> MonaRonaDona"
> It continues to appear on all pages that I access.
> -----
> Lou

How to remove the monaronadona virus/spyware
http://securitynewsfromthenet.blogspot.com/2008/03/how-to-remove-monaronadona-virusspyware.html

click start>click Run >type in msconfig [press enter]>goto the Start-
up tab

...uncheck SRVSPOOL.exe click ok
...restart computer

PA Bear [MS MVP]

unread,
Mar 3, 2008, 3:20:18 AM3/3/08
to

You'll need to do more than that. See
http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus


--
~Robear Dyer (PA Bear)

PA Bear [MS MVP]

unread,
Mar 3, 2008, 8:36:36 PM3/3/08
to
cf.
http://blog.washingtonpost.com/securityfix/2008/03/the_411_on_the_monaronadona_ex.html

PA Bear [MS MVP] wrote:
> X-post to IE General and Security newsgroups.
>
> It appears to be a harmless scam but you'll need expert assistance to
> remove
> it; cf. cf. http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus
> and
> http://forums.cnet.com/5208-6142_102-0.html?forumID=32&threadID=285491&messageID=2714709
> cf.
> https://www.bullguard.com/forum/10/Redirecting-and-suspecting-tro_60005.html
> ("a window poped up saying 'hello - i am monaronadona and i am a virus. i
> have infected u and i will wreck your pc...'")
>
> QED: How does the machine get infected?

<snip>

Canuckluck

unread,
Mar 2, 2008, 7:15:35 PM3/2/08
to

After downloading Spywareblaster I was able to change the Blue Titlebar
to Microsoft Internet Explorer instead of it saying MonaRonaDona !!!
Hurrraaayyy !!!!!

Thank you Spywareblaster !

My computer should be free of this virus, trojan, worm, whatever it
was.

I now have extra protection with Spywareblaster.

It took alot of searching and thought but I am finally free of it, I
hope ??

The steps I took were easy;

Disable System Restore , restore later when done.

Start in Safe mode if preferred,

Run > Msconfig > Start-up

..uncheck SRVSPOOL.exe
..restart computer

MonaRonaDona should be gone !!!

To change blue title bar:

Download Spywareblaster and follow directions, very easy !

Make sure you remove/delete any shortcuts it left on your computer
also.
Check your Startup menu on the Start/Programs and delete from there as
well.
Delete from your Recycle Bin as well.

This should solve your problem with MonaRonaDona


PA Bear [MS MVP]

unread,
Mar 4, 2008, 1:37:44 AM3/4/08
to
I very much doubt that enabling all SpywareBlaster protections and disabling
SRVSPOOL.EXE from loading at boot has left the macine in a clean state. See
http://www.dslreports.com/forum/r20082590-MonaRonaDona-virus

--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

PA Bear [MS MVP]

unread,
Mar 4, 2008, 8:08:50 PM3/4/08
to
Removal Tool for MonaRonaDona Infection
http://aumha.net/viewtopic.php?t=32239
--
~PA Bear

Canuckluck

unread,
Mar 4, 2008, 11:49:36 AM3/4/08
to

Yes, it is true, I know the Srvspool is still there, but it is disabled.
I cannot just delete it, only disable it from the Start-up.

I have not seen the MonaRonaDona appear on any window since I did
this.

With all the tools I have, you would think I could, but, alas, I cannot
completely get rid of it.

I have read the articles from Castner, but, they are too technical for
me.

The only problem I have is the constant Malware that re-routes my
Search pages, but only when I use Google on IE. , which is my home page.
It doesn't happen on MSN search.

Another annoying problem I have is other windows showing up with AVS
System Scanners, etc. , wanting me to DL their programs. This happens
only when I first click on one of my icons on the desktop, example:
Hotmail

I do spyware scans everyday , I have virus protection with Nortons, I
do registry checks, the whole nine yards, but, they keep coming back !

I feel at this time the only option left for me is to reformat my
computer!

I have HijackThis, Spybot, Spywareblaster, Ad-Aware SE, AML Registry
Cleaner & Nortons, how much more do I need to protect my computer ???

They all list the malware that I am having problems with, but none seem
to remove it completely ! Very frustrating !


0 new messages