<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: MonaRonaDona &#x22;virus&#x22;? in Security</title>
<link>http://www.dslreports.com/forum/r20087284</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 20:56:43 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 20:56:43 EDT</lastBuildDate>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20169344</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : - "Do not leave warm thoughts to the cooling influences of the world" -unknown<br><br>Thanks for the help! It worked perfectly! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20169344</guid>
<pubDate>Sat, 15 Mar 2008 12:40:01 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20159960</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  :)  Thank you ... Thank you ... Thank you.  This worked when nothing else did.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20159960</guid>
<pubDate>Thu, 13 Mar 2008 15:57:18 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20145135</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I LOVE YOU!!! this was so easy!!! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20145135</guid>
<pubDate>Tue, 11 Mar 2008 08:53:08 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20140774</link>
<description><![CDATA[<A HREF="/useremail/u/1536117"><b>Heather71</b></A> : Bill!   Thank you! Thank you! Thank you!  After many other attempts to remove the annoyance, your suggestion worked!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20140774</guid>
<pubDate>Mon, 10 Mar 2008 14:09:14 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20139192</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : bcastner  :)<br><br>Thanks for your earlier comments. I have now tried your "KillTrojan" prog., got the veryfast black-box happening, and then restarted my computer.<br>My OE andIE progs are running faster and I'm not "losing" keys on my keyboard, so I,m hopeful that all is well.(I replaced my Task manager using some previously gleaned information.)and it runs as normal, so I hope that all is well.<br>Thanks for your good help  :) :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20139192</guid>
<pubDate>Mon, 10 Mar 2008 08:31:49 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20132629</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : bcastner, I am sur eyou have heard it a million times already, but YOU ROCK!!! Thank you for the little removal program. It kicked A$$!!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20132629</guid>
<pubDate>Sat, 08 Mar 2008 19:26:43 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20129310</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Don't get the unigray anti-virus, since it sounds like they are the one to create the virus. Funny how they are the only virus removal software that can find the virus. Hum!<br><br>Anyway to remove the name from your taskbar after you remove it out of windows:<br>Run Regedit.exe (in Windows XP or later) for your registry editor and look for string HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main      (Then scroll down to window title and you will find the MonaRonaDona - DELETE IT!!!!!!!)<br>It should be gone next time you reboot your computer.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20129310</guid>
<pubDate>Sat, 08 Mar 2008 00:34:34 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20128956</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : &raquo;<A HREF="http://www.viruslist.com/en/weblog?done=vlpolls_resp207796935" >www.viruslist.com/en/weblog?done&middot;&middot;&middot;07796935</A><br><br>According to the virus list it wounds as thought unigray anti-virus created this virus. Sounds like a good conclusion  since they are the only program I can find that says they can remove it and according to the article this unigray has only been around 2 weeks (how convenient)!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20128956</guid>
<pubDate>Fri, 07 Mar 2008 23:04:07 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20125318</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Follow the instructions at the beginning of this post and you can't go wrong. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20125318</guid>
<pubDate>Fri, 07 Mar 2008 11:47:22 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20125173</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This worked fine for me. Thank you very much!!!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20125173</guid>
<pubDate>Fri, 07 Mar 2008 11:21:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20123305</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : If the fixes posted earlier in this thread are too difficult, and there is no shame in admitting this, then call the Tech Support department of your Antivirus vendor to start with.  They very likely are very aware of this virus and have some sort of easier remedy available for you.<br><br>The two "fixes" in this thread, only one of which need be done, are:<br><br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20123305</guid>
<pubDate>Thu, 06 Mar 2008 23:14:42 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20123289</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by HOLLY3RN :</small><br><br>HI, <br> I AM SO LOST, MY COMPUTER HAS THIS MONARONADONA VIRUS, i THOUGHT I CLEANED IT OFF WITH MY AVG, BUT I DONT UNDERSTAND HOW TO GET THE MONA DONA RONA OFF OF MY HEADER AT THE TOP OF MY SCREEN, I TRIED TO READ ONE OF THE SITES YOU POSTED, BUT I AM LOST AND AM AFRAID I WILL REALLY SCREW UP MY COMPUTER, COULD YOU SUGGEST AN EASIER SITE FOR COMPUTER DUMMIES. THANKS HOLLY</div>One option would be to download and install Spywareblaster.<br><br>There's an option within that app to change IE's title bar, among other things.<br>An added benefit would be the additional anti-spyware protection that it offers.<br><br>&raquo;<A HREF="http://javacoolsoftware.com/spywareblaster.html" >javacoolsoftware.com/spywareblaster.html</A><br><br>Though it's not going to remove any current or left-over MonaRonaDona crapola on your machine, beyond allowing you to make that one change.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20123289</guid>
<pubDate>Thu, 06 Mar 2008 23:12:00 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20121359</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : HI, <br> I AM SO LOST, MY COMPUTER HAS THIS MONARONADONA VIRUS, i THOUGHT I CLEANED IT OFF WITH MY AVG, BUT I DONT UNDERSTAND HOW TO GET THE MONA DONA RONA OFF OF MY HEADER AT THE TOP OF MY SCREEN, I TRIED TO READ ONE OF THE SITES YOU POSTED, BUT I AM LOST AND AM AFRAID I WILL REALLY SCREW UP MY COMPUTER, COULD YOU SUGGEST AN EASIER SITE FOR COMPUTER DUMMIES. THANKS HOLLY]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20121359</guid>
<pubDate>Thu, 06 Mar 2008 17:24:18 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20120866</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have the mother freaking MonaRonaDona virus. I am not very computer savy.  I tried the start, then programs, then next I have no clue. I also have no clue if this is a right method to use or if someones leading me into another virus trap. It's just a pain in the butt for this to be on my screen eventhough people say its harmless. Can someone pleaseeeee walk me through this? Many thanks 3-6-08 4 pm Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20120866</guid>
<pubDate>Thu, 06 Mar 2008 16:05:05 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20120718</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : The only issue the batch scripting solution might have is that it was unable to find Tsklist in the path.<br><br>If you have issues with the first fix, then use the second.  It has everything needed to remove the virus:<br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20120718</guid>
<pubDate>Thu, 06 Mar 2008 15:41:07 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20119223</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Go To Safemode then delete it]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20119223</guid>
<pubDate>Thu, 06 Mar 2008 12:10:21 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20119101</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This works fine until I reboot and then it's back]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20119101</guid>
<pubDate>Thu, 06 Mar 2008 11:54:28 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20118673</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : both of those are poor choices..<br><br>&raquo;<A HREF="http://en.wikipedia.org/wiki/NoAdware" >en.wikipedia.org/wiki/NoAdware</A><br><br>That is why this thread was begun.. you find the repairs that works at this link<br><br>&raquo;<A HREF="/forum/r20116147-">Re: MonaRonaDona "virus"?</A><br><br>and they are free. :D<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20118673</guid>
<pubDate>Thu, 06 Mar 2008 10:39:40 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20118610</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I AM JUST IN THE THORWS OF TRYING TO RID MYSELF OF THIS BUT UNIGRAY AS NOT COME UP AS AN OPTION, NOADWARE DID BUT DOESN'T REMOVE IT EITHER]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20118610</guid>
<pubDate>Thu, 06 Mar 2008 10:31:49 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20118124</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  :)happy as a lark!!! thanks for the clear instructions. worked like a charm.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20118124</guid>
<pubDate>Thu, 06 Mar 2008 08:51:37 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20118055</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Hmm...$10 a review post is not bad money if it's tax free. Wonder where you can sign up?<br>&raquo;<A HREF="http://img69.imageshack.us/img69/4629/familyguymoose2dr6.jpg" >img69.imageshack.us/img69/4629/f&middot;&middot;&middot;2dr6.jpg</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20118055</guid>
<pubDate>Thu, 06 Mar 2008 08:30:07 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20117601</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I am a little uncomfortable with the whole mug shot idea.  PREVX researchers, for example, have a completely different person they tracked down who admits to having written the infection: &raquo;<A HREF="http://www.prevx.com/blog/82/MonaRonaDona--We-might-be-in-the-AV-industry-but-atleast-we-arent-STUPID.html" >www.prevx.com/blog/82/MonaRonaDo&middot;&middot;&middot;PID.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20117601</guid>
<pubDate>Thu, 06 Mar 2008 04:12:44 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20117588</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Here's the mug shot of the guys that registered Unigray and possibly cerated the virus:<br>&raquo;<A HREF="http://graduates.com/ProfilePhotoView.aspx?i=2707638&t=Then&name=Rehan&lastName=Ashraf" >graduates.com/ProfilePhotoView.a&middot;&middot;&middot;e=Ashraf</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20117588</guid>
<pubDate>Thu, 06 Mar 2008 04:06:43 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20116888</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you very much for your very good tip how to delete <br>MonaRonaDona ugly virus. Its box was on my screen for 2 days and I was trying for many hours a day to delete it. But only your help was excellent. Thank you very much! :) :D And yes, I was using Registryfix2008 the night before that virus appeared on my screen. So that was the way I got it....And by the way I was able to do just the first part, the second part with moving and cleaning did not work. But the virus was cleaned anyway with HijackThis. Thank you again. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20116888</guid>
<pubDate>Wed, 05 Mar 2008 23:26:22 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20116761</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : just wanted to say thanks to bcaster. worked like a charm and easy to execute.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20116761</guid>
<pubDate>Wed, 05 Mar 2008 23:00:29 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20116147</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I know this thread is getting a little long to easily find anything.<br><br>There are two fixes, different only in that on uses native batch scripting only;  the other uses freeware utilities.  Try them in the order given below.  Using Safe Mode is a good idea for either:<br><br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20116147</guid>
<pubDate>Wed, 05 Mar 2008 21:25:05 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20115921</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I was on webmonkey.com and cliked the freedownload for registrycleanfix2008. well it cost me $68 to regiser it and it fixed nothing. two days later the mona window popped up and i cant get anything install after i download. tried hijack this and afix from the norton site.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115921</guid>
<pubDate>Wed, 05 Mar 2008 20:48:56 EDT</pubDate>
</item>

<item>
<title>MonaRonaDona revealed</title>
<link>http://www.dslreports.com/forum/remark,20115515</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I almost fell victim to the "space issue".  Here is my revised post.<br><br>Registryfix is the culprit in this social engineering scheme.  The "testimonial" of Jim Brown on the website, is from the same (no doubt) alias that is in the postings pointing to the bogus virusscanner.<br><br>The program is featured on a sponsored link on Google &raquo;<A HREF="http://pc-tools-review.com/" >pc-tools-review.com/</A><br><br>It now becomes very tricky to distinguish legit reviews from illegit reviews.  Also, on &raquo;<A HREF="http://pc-tools-review.com/" >pc-tools-review.com/</A> more products get reviewed.  I am now not sure that the registry scanner is the only dowload that will infect the computer with the MonaRonaDona problem.<br><br>You have to hand it to these guys: they did come up with a pretty elaborate, clever scam.<br><br>Type in "registryfix.com" in the google search box and you'll understand how elaborate and potentially widespread and dangerous this scam is.<br><br>The trick is in the space between registry and fix.  "Registry fix 2008" is a legitimate scanner by Registryfixer Inc.  "Registryfix" is the scam (ww.registryfix.com) and gets featured on numerous "comparison" sites, some may be legit (editor error by leaving out the space) and some may be part of the scam (like the link &raquo;<A HREF="http://pc-tools-review.com/" >pc-tools-review.com/</A>)<br><br>Hans Vredeling<br>New York, NY]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115515</guid>
<pubDate>Wed, 05 Mar 2008 19:42:52 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona revealed</title>
<link>http://www.dslreports.com/forum/remark,20115459</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Registry fix is the culprit in this social engineering scheme.  The "testimonial" of Jim Brown on the website, is from the same (no doubt) alias that is in the postings pointing to the bogus virusscanner.<br><br>The program is featured on a sponsored link on Google &raquo;<A HREF="http://pc-tools-review.com/" >pc-tools-review.com/</A><br><br>It now becomes very tricky to distinguish legit reviews from illegit reviews.  Also, on &raquo;<A HREF="http://pc-tools-review.com/" >pc-tools-review.com/</A> more products get reviewed.  I am now not sure that the registry scanner is the only dowload that will infect the computer with the MonaRonaDona problem.<br><br>You have to hand it to these guys: they did come up with a pretty elaborate, clever scam.<br><br>Type in "registryfix.co"m" in the google search box and you'll understand how elaborate and potentially widespread and dangerous this scam is.<br><br>The trick is in the space between registry and fix.  "Registry fix 2008" is a legitimate scanner by Registryfixer Inc.  "Registryfix" is the scam (ww.registryfix.com) and gets featured on numerous "comparison" sites, some may be legit (editor error by leaving out the space) and some may be part of the scam (like the link &raquo;<A HREF="http://pc-tools-review.com/" >pc-tools-review.com/</A>)<br><br>Hans Vredeling<br>New York, NY]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115459</guid>
<pubDate>Wed, 05 Mar 2008 19:34:14 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20115259</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by jubal :</small><br><br> Thanks for reply. When I try to download the OTMoveit2.exe page I get 404 Error<br> </div>if it helps..<br>did you click on the place to copy it to your clipboard then immediately paste that in a <b>new browser address bar</b> and then go to that link ? I do not get an error.<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115259</guid>
<pubDate>Wed, 05 Mar 2008 19:00:02 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20115253</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : It is a busy site.<br>I occasionally see the error as well due to this.<br><br>Wait a little while and try again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115253</guid>
<pubDate>Wed, 05 Mar 2008 18:59:10 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20115220</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  Thanks for reply. When I try to download the OTMoveit2.exe page I get 404 Error]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115220</guid>
<pubDate>Wed, 05 Mar 2008 18:54:46 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20115055</link>
<description><![CDATA[<A HREF="/useremail/u/1534717"><b>ez2cy</b></A> : As far as IE running slower and not responding.  You were right, I followed your advise and did all the things in the security clean forum?  and IE is back and running smoothly.<br><br>Thank you all so much for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20115055</guid>
<pubDate>Wed, 05 Mar 2008 18:27:52 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20114257</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Cheers Bill you helped me get rid of mona for good i hope! Thanks mate]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20114257</guid>
<pubDate>Wed, 05 Mar 2008 16:12:43 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20114120</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : After initially not having any luck with the removal, I tried again today.  It worked, but what I did different is that I checked the 04 - SRVSSPOOL.exe (it didn't say 'Global Startup) when I didn't before for the reason in parentheses.  I then did the MoveIt program.  It froze after it moved the info to the right side.  I had to do a hard boot but as of this writing everything seems back to normal.  Thank you for your help.  <br><br>As for how I got it:  My 12 y/o was using this computer and either checked an email or got it from a game site called Marapets that she plays at all the time.  I don't have an antivirus on this old computer but I guess I will need to now!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20114120</guid>
<pubDate>Wed, 05 Mar 2008 15:51:29 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20114068</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <div class="bquote"><small>said by jubal :</small><br><br> How do I "download to desktop"?<br> </div>To Windows, your Desktop is a folder like any other folder.  Start the download, when it comes to the section asking for the filename to be used for the saved files, on the left will be icons for common folders.  Such as Desktop. Choose this as the location to save the file.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20114068</guid>
<pubDate>Wed, 05 Mar 2008 15:44:33 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113722</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by jubal :</small><br><br> How do I "download to desktop"?</div>You don't have to download it to there, any place you choose will be fine.<br>When downloading any file, the Desktop folder (or My Documents) is normally the default choice in the dialogue box as to where to save it, and makes it easy to find, as it's right there in front of you on your Desktop.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113722</guid>
<pubDate>Wed, 05 Mar 2008 14:51:55 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113686</link>
<description><![CDATA[<A HREF="/useremail/u/658312"><b>danny9</b></A> : I don't have this virus but have been reading this thread with interest.<br>To me it's quite amazing the amount of knowledge the people here possess.<br>I've been around computers awhile now and have learned to do alot with them but reading some of the posts here I realize how much of a baby I am on the tech end. A long way to go.<br>But KUDOS to all of you with this knowledge and so willing to share it with us and help us.<br>Your time and efforts are truly appreciated.  <IMG SRC="http://bestsmileys.com/thumbs/7.gif">   :)<br>Thanks again,<br>Dan<br><small>--<br> VoicePulse 07/29/04</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113686</guid>
<pubDate>Wed, 05 Mar 2008 14:45:45 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113679</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  How do I "download to desktop"?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113679</guid>
<pubDate>Wed, 05 Mar 2008 14:45:09 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113512</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : My brand new lap top became infected with this two days after start up. I was unable to clear it with Norton 2008, or anything else I could figure out. I took it to my tech guys, and they have been fighting with this extortion ware for three days. They were able to clear it up, without wiping the HD, and apparently Norton now has an update to kill it, or at least most of it. DO NOT USE the unigrey anti virus, as this will worsen the infection, also do not use REISTRY CLEANER 2008, this will also worsen the effects. <br>Good luck if you have this brand new bug, it can be killed but with a little work.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113512</guid>
<pubDate>Wed, 05 Mar 2008 14:21:37 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113173</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Take it from a fellow Appalachian-American - the folks in the cleanup forum are top-notch people, many of whom are industry-recognized experts. Take the issue over there, follow the bouncing ball and you'll get rid of MRD and any other malware that may be infesting your system<br><br><small>Of course you could pay some big box store tech a couple hundred smackers to borrow your files to their USB dongles, wipe your drive and reinstall Windows :D</small> <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113173</guid>
<pubDate>Wed, 05 Mar 2008 13:31:01 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113033</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : You open notepad and copy the contents of what you highlighted and Copy'ed with your mouse.<br><br>You save the file with a CMD extension.  This tells XP or Vista that it is a batch file.<br><br>You double click the new file to execute the batch instructions it contains.<br><br>I do think in your case you would be better off with the second method provided:  &raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br><br>I note too, that MonaRonaDona does nothing to the keyboard.  I strongly suspect you have other issues.  Rather than do anything further at this point with MonaRonaDona, head to the "Security Cleanup" subForum, follow the instructins bannered in red at the top of the Main Page, and post a HijackThis log as a new topic.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113033</guid>
<pubDate>Wed, 05 Mar 2008 13:05:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20113004</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Re MonaRonaDona.<br>What does a layman do to try and rid himself of Mona..etc?<br>I have reinistated Task Manger, got rid of the screen problem, and now find that every so often my keyboard stops responding, my computer restarts and IE OE get blocked off.<br>I was using AVG but it didn't stop this virus.<br>If I copy the above suggestions  i.e. @echo off.. etc, what do I copy it into-just desktop?<br>Please advise.<br><br>Thanks  :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20113004</guid>
<pubDate>Wed, 05 Mar 2008 13:00:59 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112916</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : <div class="bquote"><small>said by  ez2cy <A HREF="/useremail/u/1534717"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I truly have to apoligize as I'm computer illetrate.<br><br>As I mentioned in earlier post, I tried the "KillTrojan" thing (see, don't even know what to call things..LOL) and it appeared to have worked from I can gather.  However, when I did a search for SRUSPOOL.EXE, it found a file, which I just deleted.  Does this mean it's gone?<br><br>Also, as I said, IE is running real slow and not responding now.  I know I read a post about it in this thread, but can not seem to find it.  I've been sitting in front of the computer for hours and I'm brain dead.<br><br>Can someone point in the right direction to get IE working properly again? <br><br>Thank you for your help and patience with a computer moron...LOL<br> </div>You are not a moron! This is how you (all of us) learn, sometimes the hard way.  :)<br><br>Did you try rebooting after the fix? If so, and that didn't help, hang in there, someone will probably have another suggestion. Edit: like  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> above.  :D<br><small>--<br><b><A HREF="http://www.thereligionofpeace.com/">10,675 DEADLY TERROR ATTACKS SINCE 9/11</a></b>~~<b><A HREF="/forum/disco">TEAM DISCOVERY</a></b><br><i>Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112916</guid>
<pubDate>Wed, 05 Mar 2008 12:45:22 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112899</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : MonaRonaDona is more annoyance than anything else.  I cannot see how it would be related to any slowness in IE.  One possibility that has surfaced in this long thread, is that it was not the only infection on the computer, just the most obvious.<br><br>Rather than spend hours in frustration, click on the "Security Cleanup" Forum, do the prerequisite steps bannered at the top of the Forum main page, and then submit a HijackThis log as a new reply.  The folks there can use various utilities to ensure that there are no other problems, and if so, that they are competently removed.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112899</guid>
<pubDate>Wed, 05 Mar 2008 12:42:31 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112893</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : <div class="bquote"><small>said by Glen M Borror :</small><br><br>Yeah, I just tried deleting it to, but it says access denied, and now I'm scared. I talked to my grandfather, who knows everything about computers and other stuff like that, says it's not a virus. Now I'm wondering, what does it really do then, if it is not a virus.<br> </div>You need to read the entire thread.<br><br>Did you try the two fixes? If one doesn't work, try the other one. Using safe mode might be a good idea also. <br><br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A><br><br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br><small>--<br><b><A HREF="http://www.thereligionofpeace.com/">10,675 DEADLY TERROR ATTACKS SINCE 9/11</a></b>~~<b><A HREF="/forum/disco">TEAM DISCOVERY</a></b><br><i>Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112893</guid>
<pubDate>Wed, 05 Mar 2008 12:41:31 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112803</link>
<description><![CDATA[<A HREF="/useremail/u/1534717"><b>ez2cy</b></A> : I truly have to apoligize as I'm computer illetrate.<br><br>As I mentioned in earlier post, I tried the "KillTrojan" thing (see, don't even know what to call things..LOL) and it appeared to have worked from I can gather.  However, when I did a search for SRUSPOOL.EXE, it found a file, which I just deleted.  Does this mean it's gone?<br><br>Also, as I said, IE is running real slow and not responding now.  I know I read a post about it in this thread, but can not seem to find it.  I've been sitting in front of the computer for hours and I'm brain dead.<br><br>Can someone point in the right direction to get IE working properly again? <br><br>Thank you for your help and patience with a computer moron...LOL]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112803</guid>
<pubDate>Wed, 05 Mar 2008 12:31:00 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112697</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : The fixes are generic.  You may not have all of the entries involved.<br><br>OTMOVEIT2 is not freezing (even if Explorer reports it not responding).  In that particular fix I scan the entire user profile directory.<br><br>In the "Killtrojan.cmd" version, I target only specific files in specific folders, and do not comprehensively scan.<br><br>The second was written in anticipation of the MRD virus possibly morphing over time.  (It has not to date done so.)<br><br><b><i>It is perfectly normal for either fix not to find all of the entries they look for.  This is to be expected and should not be any cause for alarm.  The fixes try to cover all bases.  Your particular case surely will have pieces that are missing.  This does not effect the fix.</i></b><br><br>Similarly, in the second fix you may not see with HijackThis all of the listed entries.  This too is perfectly normal and should not be any cause for alarm.<br><br>If MonaRonaDona is there, either fix will remove it.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112697</guid>
<pubDate>Wed, 05 Mar 2008 12:14:58 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112669</link>
<description><![CDATA[<A HREF="/useremail/u/1534717"><b>ez2cy</b></A> : Sorry, I did the KillTrojan horse thing and it appears to have worked.  Although IE is running very slow.  I'll look thru the posts to see if this is related.<br><br>Thank you]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112669</guid>
<pubDate>Wed, 05 Mar 2008 12:10:56 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112531</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Regular and free antivirus programs do not promise you that they will stop everything.<br><br>Remember this infection comes from a download a user willingly made, and the installation of the software from that download the user willingly made.<br><br>There is no Safe sex and there is no Safe hex.<br>The antivirus component that went temporarily missing here was between the ears of the user at the keyboard.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112531</guid>
<pubDate>Wed, 05 Mar 2008 11:53:15 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112510</link>
<description><![CDATA[<A HREF="/useremail/u/1534717"><b>ez2cy</b></A> : I just joined and sent my money.  Thank you to whomever is responsible for this site.<br><br>I got the MonaRonaDona virus this morning.<br><br>I tried the first fix, go to Programs, startup and delete.  When I go there it says the startup file is empty?<br><br>I next tried the other fix.  In the Highjack this, the only file that showed up was;  R1-HKCU\Software\Microsoft\Internet Explorer\Main Windows Title = MonaRonaDona.<br><br>I did the "OTmovie", when it's moving the files it freezes, "not responding".  Also on the right where the moved files are, it's saying SRVSPOOL.EXE and also UNIGAY not found.   <br><br>??????????]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112510</guid>
<pubDate>Wed, 05 Mar 2008 11:51:04 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112470</link>
<description><![CDATA[<A HREF="/useremail/u/594412"><b>TKJunkMail</b></A> : Shouldn't the regular free and purchased anti-virus scanners detect this and either prevent it or clean it from the computer?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112470</guid>
<pubDate>Wed, 05 Mar 2008 11:45:23 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112285</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : It is easily removed.  Two different and effective and simple methods exist in this thread:<br><br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112285</guid>
<pubDate>Wed, 05 Mar 2008 11:20:02 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112207</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Yes, I also downloaded that very program, and that's how MY MonaRonaDona appeared, and I can't deleat the SRVPOOL, because my access is denied, but I am the Administrator on my PC, and I don't know what to do. I would say try to do a disk de-fragment, and do a disk clean-up, and then do a virus scan. That should help a little bit. Try it, and if it doesn't help, then IO don't know.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112207</guid>
<pubDate>Wed, 05 Mar 2008 11:06:37 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112170</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Yeah, I just tried deleting it to, but it says access denied, and now I'm scared. I talked to my grandfather, who knows everything about computers and other stuff like that, says it's not a virus. Now I'm wondering, what does it really do then, if it is not a virus.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112170</guid>
<pubDate>Wed, 05 Mar 2008 11:00:48 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;? and one more ?</title>
<link>http://www.dslreports.com/forum/remark,20112089</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : mrd now clean... can you help me with this simple but annoying problem?   when internet explorer is open i can not roll up and down on page without long delays..seems like it reloads and just hangs for awhile.  thanks.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112089</guid>
<pubDate>Wed, 05 Mar 2008 10:45:53 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20112025</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : thank you soooo much.. tried other resolutions and only yours worked.. where was norton and mcaffee?  they did not have it even listed.. thaks again.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20112025</guid>
<pubDate>Wed, 05 Mar 2008 10:33:59 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20111570</link>
<description><![CDATA[<A HREF="/useremail/u/1534147"><b>classical62</b></A> : <div class="bquote"><small>said by  AB <A HREF="/useremail/u/1346679"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>All Hail  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, All Hail! <br><br>Hopefully, this thread and this experience will cause a bit of a light bulb to come on for some of the less computer-literate.</div>I'll double that "hail" and raise you a three cheers!<br>AB~ I agree with you on this actually "easy" lesson that was learned..I think my light bulb was having a bit of an electrical connection and that's why I did a dumb thing and downloaded that *^&$ virus...I KNOW better than to open email I don't recognize as well as be mindful of what I download...funny thing is I was scolding  myself for not listening to my intuitin the other day and then I went ahead and didn't listen and got a pain the the *** for my troubles. <br>Thank you all again for your time and I will behave myself from now on :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20111570</guid>
<pubDate>Wed, 05 Mar 2008 08:54:02 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20111081</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : From your description, MonaRonaDona was only one of several malware problems you have.<br><br>These other issues are not related to MonaRonaDona.  The best thing to do would be to follow the prerequisite steps here, and post a new log in the Security Cleanup Forum:<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20111081</guid>
<pubDate>Wed, 05 Mar 2008 03:23:55 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20111036</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : THANKS MATE, I HAVE GET RID OF THE MONARONADANA VIRUS BUT MY INTERNET EXPLORER IS STILL MESS UP. ONE I OPEN IE, ALOT OF WINDOWS COME UP LATER ASKING ME TO DOWNLOAD MALAWE, SOME OTHER CLEAN UP AND SO ON, THE IE TITTLE BAR READ ADD- ONS-DISABLE. RIGHT NOW ONCE I TRIED TO RESTART MY SYSTEM IT REFUSES TO SHORT DOWN WINDOW, ITS JUST SAYS WINDOW IS SHORTING DOWN FOR MORE THAN 5 HOURSE WITH OUT TURNING OFF AND THE NORTON GO BACK  SEEM NOT TO BE WORKING FINE AS WEEL. WHAT COULD BE THE PROBLEM. <br>DOES ANYONE KNOW WHAT I CAN DO. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20111036</guid>
<pubDate>Wed, 05 Mar 2008 02:56:35 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20111012</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Well AB this be the message..<br><br>&raquo;<A HREF="http://images.kaspersky.com/en/vlweblog/mona_1.png" >images.kaspersky.com/en/vlweblog/mona_1.png</A></div>True enough. Though I'm not sure I see much of a connection to a song in Spanish by an Hispanic composer, other than in possible sentiment-- but similar sentiments have no doubt been expressed in song, film, and writings in many different languages.<br>But-- it's a mere point of trivia anyway, regardless of what it may refer to, and I suspect those victimized by MonaRonaDona are not overly concerned with what the malware writer may have been thinking whilst composing his piece of . . . 'art'.  ;)<br><div class="bquote">And Mona does not live in Pakistan..so it must have been<br>Larry Williams.<br><br>&raquo;<A HREF="http://www.msu.edu/~buchan44/boney.html" >www.msu.edu/~buchan44/boney.html</A></div>Either that or "Mona" by Bo Diddley, I suppose, eh?<br><br>Or "Mona Mona" by Peter Cetera? Maybe "Mona Lisa" by Nat King Cole?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20111012</guid>
<pubDate>Wed, 05 Mar 2008 02:43:07 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110957</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : I have that <b>RemoveMonaRonaDona.exe</b>2856KB and the .rar in a folder..Internal name: FixMalware.exe  Version 1.0.0.1 since 2/29...will they be updating it soon? :D<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110957</guid>
<pubDate>Wed, 05 Mar 2008 02:10:20 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110927</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Well AB this be the message..<br><br>&raquo;<A HREF="http://images.kaspersky.com/en/vlweblog/mona_1.png" >images.kaspersky.com/en/vlweblog/mona_1.png</A><br><br>And Mona does not live in Pakistan..so it must have been<br>Larry Williams.<br><br>&raquo;<A HREF="http://www.msu.edu/~buchan44/boney.html" >www.msu.edu/~buchan44/boney.html</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110927</guid>
<pubDate>Wed, 05 Mar 2008 01:52:15 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110914</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Thank you.<br><br>I too found the "Sherlock Holmes" speculation by ThreatFire a bit over the top. But some of the other evidence is fairly strong as to some of the origin of this pest.<br><br>The clues of importance are that there is a great deal of commanality in the code for MonaRonaDona, Uni-Gray Antivirus, RegistryCleaner2008; and even odder or perhaps scarier, in a free remover offered at least twice in this thread and posted widely over the Internet for <b>MonaRonaDonaRemover.exe</b> or its packed RAR version.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110914</guid>
<pubDate>Wed, 05 Mar 2008 01:46:39 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110557</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>  <blockquote><small>quote:</small><hr>. . in the Sherlock Holmes style we can say that the author of these masterpieces is a male (possibly <b>Pakistani</b>), who lives in Netherlands and speaks Dutch, in his mid 30-ies, who is a freelance programmer in C++ (MFC/ATL), who is also a soccer fan, wants to study in the U.S. or <b>Pakistan</b> . . .<br><br>. . MonaRonaDona is likely a word-play with Maradona - M(on)ar(on)adona . . . .<hr></blockquote><br>&raquo;<A HREF="http://blog.threatfire.com/" >blog.threatfire.com/</A></div>(Bolding mine.)<br><div class="bquote"><small>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>. . The Monaronadona message was for human rights violation protest. So it is closer to someone who would follow thoughts of Morodo in the word of the song Querido Enemigo (wanted enemy) "Beloved Enemy in peace and let me already now, or <b>na na na</b>." . . .</div><div class="bquote"><small>said by  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>. . perhaps this Dutch speaking <b>Pakistani . . .</b></div>(Again, bolding mine.)<br><br>I believe you're both wrong (and/or threatfire.com), if it's a Pakistani who wrote it.<br><br>Rona-Dona, or Rhona Dhona, is some sort of Pakistani/Indian slang-- for what, I'm not exactly sure, but examples can be found here:<br><br>&raquo;<A HREF="http://www.apnicommunity.com/kasturi/31718-pity.html" >www.apnicommunity.com/kasturi/31&middot;&middot;&middot;ity.html</A><br><br>&raquo;<A HREF="http://entertainment.oneindia.in/television/top-stories/news/soap-operas-indian-screens-060706.html" >entertainment.oneindia.in/televi&middot;&middot;&middot;706.html</A><br><br>&raquo;<A HREF="http://forum.indya.com/showthread.php?t=56424" >forum.indya.com/showthread.php?t=56424</A><br><br>There are others.<br>So if in fact it was a Pakistani who wrote it, that would seem to fit more so than any 'Diego Maradona' thing or human rights violation message.<br><br>Just a point of trivia, as it would seem to have no actual bearing on anything.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110557</guid>
<pubDate>Wed, 05 Mar 2008 00:14:31 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110264</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Or, perhaps this Dutch speaking Pakistani just did not know how to spell the pop singer Madonna very well......]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110264</guid>
<pubDate>Tue, 04 Mar 2008 23:14:26 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110185</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br> <br><br>Clues?<br>MonaRonaDona is likely a word-play with Maradona - M(on)ar(on)adona, whose fans are likely to be in their mid 30-ies and older.<br><br> </div>And I of course do not agree with the footballer angle.  :D<br>The Monaronadona message was for human rights violation protest.  So it is closer to someone who would follow thoughts of <b>Morodo</b> in the word of the song Querido Enemigo (wanted enemy) "Beloved Enemy in peace and let me already now, or <b>na na na</b>." Those fans are alot younger.<br><br>&raquo;<A HREF="http://translate.google.com/translate?hl=en&sl=es&u=http://www.hhdirecto.net/letras/morodo-querido-enemigo-t884.html&sa=X&oi=translate&resnum=3&ct=result&prev=/search%3Fq%3DQuerido%2BEnemigo%2B%26hl%3Den%26sa%3DN" >translate.google.com/translate?h&middot;&middot;&middot;26sa%3DN</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110185</guid>
<pubDate>Tue, 04 Mar 2008 22:57:29 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110131</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Once you create the file in notepad, save it.<br>Rename the file "KillTrojan.bat"  (instead of CMD as the file extension.<br><br>Then double click the saved and renamed file.  <br><br>You may well have to manually remove the entry made to the IE Title Bar when finished:  &raquo;<A HREF="http://support.microsoft.com/kb/176497" >support.microsoft.com/kb/176497</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110131</guid>
<pubDate>Tue, 04 Mar 2008 22:49:47 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110121</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have tried the fixes suggested.  When I open the notepad named "KillTrojan.cmd" it does not do anything.  I have gone thru the whole sequence 3 times.   :huh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110121</guid>
<pubDate>Tue, 04 Mar 2008 22:47:43 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20110092</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Windows 98?<br><br>Hmmmm.<br>I am surprised it would have much effect other than change the IE Title bar.  The infection is not terribly well written, and seems very XP and Vista dependent on where it locates files.<br><br>There may have been some files or folders installed, but I doubt they would be active.  It is more likely the Title Bar you are noticing.<br><br>See:  &raquo;<A HREF="http://support.microsoft.com/kb/176497" >support.microsoft.com/kb/176497</A><br><br>Since in the general scheme of things this infection is more annoyance than danger, give it a day or so and manually update your antivirus program definitions, and then do a through scan.  It is likely in the next few days this infection will be in your antivirus program database.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20110092</guid>
<pubDate>Tue, 04 Mar 2008 22:43:01 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109953</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanx brian this worked great! Just think other anti virus will charge up to $100 to fix thanx again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109953</guid>
<pubDate>Tue, 04 Mar 2008 22:19:40 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109877</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : My brother has this malware on his computer but has Windows 98 ~ I know, old! How can you get rid of it with such an old version of windows? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109877</guid>
<pubDate>Tue, 04 Mar 2008 22:07:26 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109813</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : i'm wondering if it was from the registry clean fix 2008. That's when I noticed it and someone else mentioned that too.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109813</guid>
<pubDate>Tue, 04 Mar 2008 21:58:40 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109779</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Yep, I think I got the monaronadona from the registrycleanfix2008! And you have to pay for it, which is really what sux! But the registry does have a MBG nd I deleted the srvspool.exe but still have the monaronadona on my internet explorer toolbar! UGG!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109779</guid>
<pubDate>Tue, 04 Mar 2008 21:53:20 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109644</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Okay guys, my girls computer got this, and all we had to do was restore the computer to a date before the virus was created in your systems! WHOO HOOO free at last]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109644</guid>
<pubDate>Tue, 04 Mar 2008 21:34:47 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109515</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> :  <blockquote><small>quote:</small><hr>Well, as we research further into the so-called MonaRonaDona virus, Registry Cleaner 2008, and Unigray Antivirus, we find characteristics common to each executable binary, leading us to believe with a high level of confidence that not only are the binaries from the same group, but they were developed on the same machine.<br><br>We performed a forensic investigation of the binaries, and in the Sherlock Holmes style we can say that the author of these masterpieces is a male (possibly Pakistani), who lives in Netherlands and speaks Dutch, in his mid 30-ies, who is a freelance programmer in C++ (MFC/ATL), who is also a soccer fan, wants to study in the U.S. or Pakistan as a Fulbright scholar and likes looking at Maria Ford and Jordon Ladd. Our Mr. X has no permanent job, so he takes the projects from his bosses to build these rogue antivirus solutions and pay his rent. He wants better projects and wants to run his own business. It is his bosses who are the real masterminds behind Unigray Antivirus and MonaRonaDona - not this man himself.<br><br>Clues?<br><br>Well, the executable was compiled on a Windows box with the Netherlands regional settings using Microsoft Visual Studio 8 and MFC/ATL settings.<br>MonaRonaDona is likely a word-play with Maradona - M(on)ar(on)adona, whose fans are likely to be in their mid 30-ies and older.<br>An ELance trace leads us to the web portal where freelance programmers can be hired.<br>Multiple others litter the files.<br><br>It's Elementary, My Dear Watson!<br><hr></blockquote><br>&raquo;<A HREF="http://blog.threatfire.com/" >blog.threatfire.com/</A><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109515</guid>
<pubDate>Tue, 04 Mar 2008 21:12:52 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109337</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  jefe <A HREF="/useremail/u/393752"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>"We're still researching this" doesn't add much.   I was hoping that one or more of the posters in this thread who have been infected might report how they suspect they got bitten.<br> </div>you could start reading here as to what classical62 posted and then the rest of the thread where two others posted how they were infected.<br><br>&raquo;<A HREF="/forum/r20099206-">Re: MonaRonaDona "virus"?</A><br>here is another post by Wayonmyway<br>&raquo;<A HREF="/forum/r20105092-">Re: MonaRonaDona "virus"?</A><br><br>Then you can read these links<br><br>Monday, March 3, 2008<br>MonaRonaDona Mystery Solved <br><br>Some of these users unfortunately were persuaded over the past week or so to run a version of "RegistryCleaner2008.exe" (afec3d0f13b8f866f2c2eec122024165 for you researchers out there), as can be seen here:<br><br>Along with a particular version of "RegistryCleaner2008.exe", came a little friend by the name of "srvspool.exe" and friends. Some of the infection symptoms are somewhat simple and silly compared to other threats we've been researching -- "MonaRonaDona" appears in the Internet Explorer title bar, the "DisableTaskManager" key in the registry is set so users cannot use Ctl+Alt+Del to kill the threat on their system, and "srvspool.exe" appears in the All Users startup folder.<br><br>&raquo;<A HREF="http://blog.threatfire.com/" >blog.threatfire.com/</A><br><br>What we know about REGISTRYCLEANER2008.EXE:<br>&raquo;<A HREF="http://www.prevx.com/filenames/X2024140380500743603-0/REGISTRYCLEANER2008.EXE.html" >www.prevx.com/filenames/X2024140&middot;&middot;&middot;EXE.html</A><br><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109337</guid>
<pubDate>Tue, 04 Mar 2008 20:43:04 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109282</link>
<description><![CDATA[<A HREF="/useremail/u/393752"><b>jefe</b></A> : "We're still researching this" doesn't add much.   I was hoping that one or more of the posters in this thread who have been infected might report how they suspect they got bitten.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109282</guid>
<pubDate>Tue, 04 Mar 2008 20:36:18 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20109071</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : jefe,<br><br>See:  &raquo;<A HREF="/forum/r20103199-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20109071</guid>
<pubDate>Tue, 04 Mar 2008 20:02:22 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20108903</link>
<description><![CDATA[<A HREF="/useremail/u/393752"><b>jefe</b></A> : I've scanned through this thread and one thing that hasn't popped out is...how did those that got infected do so?<br><br>If I missed it...sorry.  But it would be interesting to know how the bad guy wound up on infected machines so others won't make the same mistake.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20108903</guid>
<pubDate>Tue, 04 Mar 2008 19:32:04 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20108806</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Use the script solution, as nothing needs to be downloaded:<br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20108806</guid>
<pubDate>Tue, 04 Mar 2008 19:14:56 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20108746</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : My comp has this virus and it has gotten so bad that it has disabled EVERYTHING!!  I can't even get online with it....is there any way to get rid of it without having to access the internet??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20108746</guid>
<pubDate>Tue, 04 Mar 2008 19:05:24 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20108312</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Your fix worked.  thank you so much.  got the link from the Washington Post.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20108312</guid>
<pubDate>Tue, 04 Mar 2008 17:49:31 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20108279</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I did all the steps and it worked until the OTMoveIT, it keeps freezing me as well. I am going to wait awhile and try again. i am going to back up all my files still tho as I am having other issues.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20108279</guid>
<pubDate>Tue, 04 Mar 2008 17:42:08 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20108127</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : IT WORKED!!! Thank You!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20108127</guid>
<pubDate>Tue, 04 Mar 2008 17:15:50 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107866</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have this virus as we speak. I am going to try and follow your response in safe mode. No I haven't gotten any messages from "UniGray Antivirus".]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107866</guid>
<pubDate>Tue, 04 Mar 2008 16:28:14 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107853</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Either of the two fixes in this thread (first page) should work on Windows ME.  The first method is likely a better choice for ME  (only because I cannot test the second method under ME ahead of time for you.):<br><br>See the two links here to access the choices directly:  &raquo;<A HREF="/forum/r20104085-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107853</guid>
<pubDate>Tue, 04 Mar 2008 16:25:52 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107842</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by ME user :</small><br><br>I have an old laptop with Windows ME and got that blamed mona thing.  Is there a fix for this OS?<br> </div><b>Bill Responded to you in the next post..</b> edit<br><br>But it is still a good suggestion to head to this forum section and follow the instruction to then post a hijacthis log..someone will help you there.<br><br>&raquo;<A HREF="/forum/cleanup">Security Cleanup</A><br><br>you will be asked first to do these steps..<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A><br><br>But it will be worth it since those experts will then give you other suggestions on how to keep you system safe.  ;)<br><br>And I suggested that to anyone else that got whacked with this monaronadona..since chances are you could have other bad boys on your PC and they will help you clean them off and get your system running smoother and faster in many cases.<br><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107842</guid>
<pubDate>Tue, 04 Mar 2008 16:24:28 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107804</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have an old laptop with Windows ME and got that blamed mona thing.  Is there a fix for this OS?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107804</guid>
<pubDate>Tue, 04 Mar 2008 16:19:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107698</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : THANK YOU!!!!!  I could kiss you full on the lips for posting this cure.  I would have been one of those people who bought the antivirus software... after searching and getting frustrated... I was willing to try anything.  You saved me $40 and restored my faith in the kindness of total strangers.  Today, you are my hero.<br><br>Thanks again, <br>Elissa]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107698</guid>
<pubDate>Tue, 04 Mar 2008 16:04:22 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107486</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Cool man You are the coolest person on earth. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107486</guid>
<pubDate>Tue, 04 Mar 2008 15:26:46 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107437</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Want to say thak you very much for the advice!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107437</guid>
<pubDate>Tue, 04 Mar 2008 15:19:53 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107430</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks Thanks Thanks   Yes, this solution really<br>does work.. Some of the virus software folks haven't<br>even found it  -- their software does not identify or<br>do anything to help.   Your article is the best solution.<br><br>Larry Gorin]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107430</guid>
<pubDate>Tue, 04 Mar 2008 15:19:11 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107264</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : It has already been posted..but here is the link again on other methods to use <b>(with screenshots)</b><br>&raquo;<A HREF="http://www.bleepingcomputer.com/tutorials/tutorial61.html#winxo" >www.bleepingcomputer.com/tutoria&middot;&middot;&middot;ml#winxo</A><br><br>To use the System Configuration Utility method <br><br>Close all open programs. <br>Click Start, Run and type MSCONFIG in the box and click OK <br>The System Configuration Utility appears, On the BOOT.INI tab, Check the "/SAFEBOOT" option, and then click OK and Restart your computer when prompted. <br>The computer restarts in Safe mode. <br>Perform the troubleshooting steps for which you are using Safe Mode. <br>When you are finished with troubleshooting in Safe mode, open MSCONFIG again, on the BOOT.INI tab,  uncheck "/SAFEBOOT" and click OK to restart your computer <br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107264</guid>
<pubDate>Tue, 04 Mar 2008 14:50:21 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107241</link>
<description><![CDATA[<A HREF="/useremail/u/1534403"><b>omputeretard</b></A> : guys this is going to sound really quite dumb, but how do i boot in safe mode? i have a gateway desktop with XP and when i turn it off and try pressing f8 it just boots regularly... anyone know what the deal is? im stumped, but that doesnt take much.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107241</guid>
<pubDate>Tue, 04 Mar 2008 14:44:54 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20107174</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : cut 'svrspool' from start up menu and past on desktop. then delete. do a search for svrspool and delete.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20107174</guid>
<pubDate>Tue, 04 Mar 2008 14:34:05 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106927</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : MonaRonaDona (and its "fix") come nowhere near any setting that would effect your ability to do a shutdown normally.<br><br>I think it best you raise this as a new issue in the Security Cleanup Forum.  Be sure to follow the prerquisite steps in large letters at the top of the Forum prior to posting.<br><br>We will run some diagnostic tests to see what is up.<br><br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106927</guid>
<pubDate>Tue, 04 Mar 2008 13:55:00 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106634</link>
<description><![CDATA[<A HREF="/useremail/u/1534403"><b>omputeretard</b></A> : well yeah i have learned a few things. but when i found errorsmart i was on the microsoft download site. what are they thinking? i mean its not very professinal of them to go screwing people out of money. yay to corperate wool over my blind and unintelligent eyelids. it must have been an add or something that i assumed was from microsuck.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106634</guid>
<pubDate>Tue, 04 Mar 2008 13:11:39 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106618</link>
<description><![CDATA[<A HREF="/useremail/u/1534403"><b>omputeretard</b></A> : well yeah i have learned a few things. but when i found errorsmart i was on the microsoft download site. what are they thinking? i mean its not very professional of them to go screwing people out of money. yay to corporate wool over my blind and unintelligent eyelids. it must have been an add or something that i assumed was from microsuck.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106618</guid>
<pubDate>Tue, 04 Mar 2008 13:08:32 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106518</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : it worked thank you so much you will be in my prayers tonight :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106518</guid>
<pubDate>Tue, 04 Mar 2008 12:51:39 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106444</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks for the info to get Mona off, but now I can't shutdown my comp.  However, after reboot, my task manager was enabled.   I have to pull the power to shut down.  It hangs when I go to Start/Shutdown.  How can I fix this?  I hope they shoot the b___stards that did this.<br><br>MM]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106444</guid>
<pubDate>Tue, 04 Mar 2008 12:41:10 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106411</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : All Hail  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, All Hail!<br><br>Hopefully, this thread and this experience will cause a bit of a light bulb to come on for some of the less computer-literate.<br><br>This infection is pure social engineering.<br><br>Don't believe everything you see in a pop-up on your screen, in an e-mail, etc.<br>In fact, don't even open unrecognized e-mails. Simply delete them.<br><br>You have no unknown benefactor in Nigeria who has died and willed you a large amount of money, if only you could send the cash for the process to be transacted.<br><br>You have no virus or other issue with your computer simply because some random and unrecognized pop-up says so, with the "guaranteed cure right here at this link".<br>Etc.<br><br>And when in doubt, don't do it.<br><br>Learning from mistakes is a positive experience.<br>Ignoring mistakes and continuing to make the same ones is strictly a dead-end street, and potentially a ticket to a financial nightmare or identity theft merry-go-round.<br><br>It does keep folks busy in this forum, though.  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106411</guid>
<pubDate>Tue, 04 Mar 2008 12:37:27 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20106292</link>
<description><![CDATA[<A HREF="/useremail/u/1371265"><b>daveinpoway</b></A> : Here's another article about this: &raquo;<A HREF="http://www.techworld.com/security/news/index.cfm?newsid=11604&email" >www.techworld.com/security/news/&middot;&middot;&middot;04&email</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20106292</guid>
<pubDate>Tue, 04 Mar 2008 12:15:26 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105499</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : And thank you for your time..it will help other  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105499</guid>
<pubDate>Tue, 04 Mar 2008 10:08:16 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105478</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Originally got rid of it in safe mode. It has gotten rid of the pop up message, header in IE, etc.<br><br>The GOOD NEWS is I got an error message which told me: "An error occurred while trying to uninstall RegistryCleanFix2008. It may have already been uninstalled.<br>Would you like to remove RegistryCleanFix2008 from the Programs and Features List?" - I responded yes. It deleted the name from there.<br>I restarted my computer and went back to the start icon and manually will delete the directories in the programs directory. Hopefully I will not see any reference to this anymore. Thx.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105478</guid>
<pubDate>Tue, 04 Mar 2008 10:04:39 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105372</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Yes try that first and see if it works. The other thing you could try is do Bill's repair again in the SAFE MODE..did you do it that way in the first place ?<br><br>It could be that the program was running and could not be deleted in the Window mode.<br>Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105372</guid>
<pubDate>Tue, 04 Mar 2008 09:44:51 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105354</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I went to the "control panel" icon on my desktop (I am writing with detail to be helpful to others). I then went to the icon "programs and features" which is used to uninstall, change or repair.<br><br>Unfortunately even after Bill's method (which worked), the program is still listed there as RegistryCleanFix2008  with my other programs, although the problems do seem to be resolved other than the program seemingly still in my computer. At this point should I just continue and delete this program using the control panel route?<br>I certainly don't need the RegistryCleanFix2008 program.<br>BTW, thanks for the help on this one.<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105354</guid>
<pubDate>Tue, 04 Mar 2008 09:42:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105270</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Do you see it also in your add/remove prgrams in the control panel ?<br>If your search for files on your PC and can you find RegistryCleaner2008.exe or RegistryCleanFix2008?<br><br><b>I would not think so.. therefore yes..just delete them there with the right click context menu.</b><br><br>Since there is an "UninstallRegistryCleanFix2008" in that area..if you click on it..does it then say files can not be found ?<br><br>this is good also since that proves the repair Bill gave you does work.<br><br>BTW; you can also navigate with your explorer to your Progam File folder. In that folder..do you find another folder for this RegistryCleanFix2008 and if so what are the contents of that folder?<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105270</guid>
<pubDate>Tue, 04 Mar 2008 09:24:15 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105247</link>
<description><![CDATA[<A HREF="/useremail/u/1534403"><b>omputeretard</b></A> : i wish i found this website about a week ago. i just spent 30 bucks on the errorsoft software that is a total sham. I'm quite mad. anyways i did a live update for symantec and your correct. it will pick it up now. they should have some sort of "hey idiot" button that tells me before i buy something stupid. i feel like a computer moron.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105247</guid>
<pubDate>Tue, 04 Mar 2008 09:16:50 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105213</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : It is showing me it is a resident program: What I mean is I<br>Clicked on lower left icon windows vista start, brought my cursor up to programs to see if the program was still shown. Moved my cursor to my program directories and see directory for "RegistryCleanFix2008", within this directory I see three files, "RegistryCleanFix2008 on the web", "RegistryCleanFix2008" and "UninstallRegistryCleanFix2008".<br><br>Do I just click on my start icon, move my cursor over the program directory of "RegistryCleanFix2008" and hit delete. I have already run Bill's fixes and they cleaned up the IE header etc. and my computer seems to be running ok, albeit a little slower.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105213</guid>
<pubDate>Tue, 04 Mar 2008 09:08:10 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105149</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : <div class="bquote"><small>said by computeretarded :</small><br><br>also, why does my Norton or Errorsmart find this trojan? more so, why did they allow it to find it's way onto my computer in the first place?<br> </div>if you meant it didn't find it before it does now<br>&raquo;<A HREF="http://www.symantec.com/enterprise/security_response/weblog/2008/03/monaronadona_the_pure_social_e.html" >www.symantec.com/enterprise/secu&middot;&middot;&middot;l_e.html</A><br><br>Cudni<br><small>--<br>"Mercifully, he hit him with the soft end of the pistol." <br>Help yourself so God can help you.<br>Microsoft MVP,  2006-2007</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105149</guid>
<pubDate>Tue, 04 Mar 2008 08:45:07 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105122</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Which one do you see there ?<br><br>RegistryCleanFix2008 or RegistryCleaner2008.exe ?<br><br>The repair removes..<br>rd /s/q "C:\Program Files\RegistryCleanFix2008">nul<br><br>If it is just a matter of seeing the entry in your start button area..you can right click on it and remove it from the list. It is just listed there because it was a recently used program.<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105122</guid>
<pubDate>Tue, 04 Mar 2008 08:38:13 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20105092</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Dear Bill,<br>I was hit with the MonaRonaDona last night. RegistryCleanFix2008 is the culprit. It is not just an innocent hijack from what I've seen, it will start to delete newly loaded software and will try to block your ability to access the Internet which gets in the way of being able to copy the file paths below. I was able to get it done in windows "safe mode" - I am running Vista. My computer seems to be running ok now but I still see the RegistryCleanFix2008 programs in a directory tree along with my other programs if I click my start key. Can they sit there harmlessly now?<br>Thanks for your help from all whom might have picked this piece of garbage up. Much appreciated. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20105092</guid>
<pubDate>Tue, 04 Mar 2008 08:28:34 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104828</link>
<description><![CDATA[<A HREF="/useremail/u/1534403"><b>omputeretard</b></A> : you are the man. i am primadona free thanks to you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104828</guid>
<pubDate>Tue, 04 Mar 2008 06:43:39 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104790</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks, It Helped]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104790</guid>
<pubDate>Tue, 04 Mar 2008 06:18:43 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104763</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : also, why does my Norton or Errorsmart find this trojan? more so, why did they allow it to find it's way onto my computer in the first place?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104763</guid>
<pubDate>Tue, 04 Mar 2008 05:58:00 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104757</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : by live one, what do you mean? if you meant "some idiot that got the stupid monaronadona and doesn't know how to follow the directions you all have posted to fix it themselves" then i am totally your man! <br><br>email is up in the anonymizer... please respond.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104757</guid>
<pubDate>Tue, 04 Mar 2008 05:54:10 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104710</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : There are two versions of a complete fix for this virus on the first page of this thread.<br><br>No other site need be considered, particularly as you are asked to download a blind .RAR executable, which does not handle the Task Manager issues, the removal of the origianl dropper application, or the corruption in the IE and OE Header.  You can read the reports in this thread from those who tried that fix who will attest to this.<br><br>The fixes at the beginning page of this thread are open to so that they can be read by all, and comprehensively remove MonaRonaDona.  From todays <b>Washington Post</b>:  &raquo;<A HREF="http://blog.washingtonpost.com/securityfix/2008/03/the_411_on_the_monaronadona_ex.html" >blog.washingtonpost.com/security&middot;&middot;&middot;_ex.html</A><br><br><b>Direct links (You only need to use one):</b><br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A><br><br>These fixes have been used by thousands; the unique page view on this thread has exceeded 17,000 in two days. <br><br>Bill Castner<br> <br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104710</guid>
<pubDate>Tue, 04 Mar 2008 05:05:52 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104700</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Fantastic... That seemed to work!  Thank-you Cudni and Thanks again to Bill... Much appreciated!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104700</guid>
<pubDate>Tue, 04 Mar 2008 04:56:41 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104672</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : <div class="bquote"><small>said by Oricat :</small><br><br> I try to move the files; they move to the results screen then the programe stops responding???  Any ideas????  This is new Laptop, running Vista, Please Help!!!   <br> </div>try<br>"...<br>If you have any issues, run the steps in Safe Mode...."<br><br>edit: safe mode howto link<br>&raquo;<A HREF="http://www.bleepingcomputer.com/tutorials/tutorial61.html#vista" >www.bleepingcomputer.com/tutoria&middot;&middot;&middot;ml#vista</A><br><br>Cudni<br><small>--<br>"Mercifully, he hit him with the soft end of the pistol." <br>Help yourself so God can help you.<br>Microsoft MVP,  2006-2007</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104672</guid>
<pubDate>Tue, 04 Mar 2008 04:15:14 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104659</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hi... Thank-you for your help with this. I have followed you instructions and all has worked very well, until the last step!  After clicking "MoveIt" all results were displayed in the right hand panel as "not found" I then exited and reopened OTMoveIt, when I clicked on CleanUp a message was displayed stating "&Auml;ccess Denied"???  I tried to repeat the second step, and each time I try to move the files; they move to the results screen then the programe stops responding???  Any ideas????  This is new Laptop, running Vista, Please Help!!!   ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104659</guid>
<pubDate>Tue, 04 Mar 2008 03:53:13 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20104085</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by kate k :</small><br><br>Please help. i think i removed all of monaronadona but icant change my header. i tried searching yahoo answers but nothng was useful.  I also tried typing it manually Do u do that in the address box or where. somone please help me<br> </div>Use this method<br>&raquo;<A HREF="/forum/r20087495-">Re: MonaRonaDona "virus"?</A><br><br>or this one<br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A><br><br>to clean everything off and get rid of the header.<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20104085</guid>
<pubDate>Tue, 04 Mar 2008 00:14:19 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20103875</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Please help. i think i removed all of monaronadona but icant change my header. i tried searching yahoo answers but nothng was useful.  I also tried typing it manually Do u do that in the address box or where. somone please help me]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20103875</guid>
<pubDate>Mon, 03 Mar 2008 23:28:49 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20103808</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Be really careful as unigray says that they have the answer<br>to this malware,but Its a ruse,First no aunthenticity cert.<br>Second The product does not completely remove MRD-virus until unigray sends you a patch (monadonarona.exe)to remove<br>the virus and again...no authenticity certificate and It seems that I got the virus right after I had downloaded<br>the google tool bar,As with everyone else I seem to have recieved it through the browser it all started happening<br>on Febuary 29/2008]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20103808</guid>
<pubDate>Mon, 03 Mar 2008 23:14:29 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20103726</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This worked great : )  I was able to do it in safe mode but if I tried otherwise it had disabled my administration rights.  My virus scan still didn't pick it up but it seems to be gone : )  Thanks so much for the information, I was at the end of my rope with this thing!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20103726</guid>
<pubDate>Mon, 03 Mar 2008 22:57:08 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20103570</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks so much for the help.  It worked and thank goodness it is gone.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20103570</guid>
<pubDate>Mon, 03 Mar 2008 22:30:27 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20103368</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hey I did this to fix the virus and it worked for me! Nothing else did. Thank you so much.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20103368</guid>
<pubDate>Mon, 03 Mar 2008 21:57:12 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20103199</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b>Where does MonaRonaDona come from?</b><br><br> <blockquote><small>quote:</small><hr>"We&#146;re still researching this",  says Joel Schouwenberg of Kaspersky Labs, who calls the MonaRonaDona Trojan of the past week to be "among the most elaborately orchestrated scams" he&#146;s seen.<hr></blockquote><br><br>See if these help:  <br>&raquo;<A HREF="http://blog.threatfire.com/" >blog.threatfire.com/</A><br>&raquo;<A HREF="http://blog.washingtonpost.com/securityfix/2008/03/the_411_on_the_monaronadona_ex.html" >blog.washingtonpost.com/security&middot;&middot;&middot;_ex.html</A><br>&raquo;<A HREF="http://www.networkworld.com/news/2008/030308-monaronadona-scam.html" >www.networkworld.com/news/2008/0&middot;&middot;&middot;cam.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20103199</guid>
<pubDate>Mon, 03 Mar 2008 21:35:08 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20102876</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This was succesful in removing Monaronadona virus for me. Thankyou!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20102876</guid>
<pubDate>Mon, 03 Mar 2008 20:47:47 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20102623</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : On norton..did you try to force a manual update or try to get their daily ><br><br>&raquo;<A HREF="/forum/r20099628-">Re: Security Software Updates  -  03 Mar 2008</A><br>Daily Updates   Learn More<br><br>&raquo;<A HREF="http://www.symantec.com/business/security_response/definitions.jsp" >www.symantec.com/business/securi&middot;&middot;&middot;ions.jsp</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20102623</guid>
<pubDate>Mon, 03 Mar 2008 20:06:02 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20102524</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  :) Thanks too to B Castner. Your batch file "killtrojan.cmd" worked well. WinXP environment. <br><br> :( How come Norton asleep?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20102524</guid>
<pubDate>Mon, 03 Mar 2008 19:51:31 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20102468</link>
<description><![CDATA[<A HREF="/useremail/u/1534276"><b>BigMinge</b></A> : Thanks for this. I to found this when i turned my comp on.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20102468</guid>
<pubDate>Mon, 03 Mar 2008 19:43:13 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20102127</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : thank you, thank you for the help removing monaronadona and then the subsequent help with the task manager issue.  I am self-employed and use my computer for my lifelihood as a daytrader, however, am completely non-tech savvy.  Your instructions were excellent and worked perfectly.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20102127</guid>
<pubDate>Mon, 03 Mar 2008 18:44:14 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20102022</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Try starting in safe mode(F8) you should then be able to delete it.<br>Don't know how to re-start the task manager though.<br>Best of luck.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20102022</guid>
<pubDate>Mon, 03 Mar 2008 18:23:52 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101705</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  lordstarfyre <A HREF="/useremail/u/1534243"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Hi, I ran the KillTrojan.CMD, and now my Task Manager is disabled.<br><br>How do I turn it back on?<br><br>It appears the Trojan is gone, thanks for that, BTW!!!<br> </div>You could try the .reg file here if the OS is XP.<br><br>&raquo;<A HREF="http://www.kellys-korner-xp.com/xp_tweaks.htm" >www.kellys-korner-xp.com/xp_tweaks.htm</A><br><br>download it at #51 called <b>Enable the Task Manager</b><br><br>put it on the desktop..double click on it to install..then you might have to reboot.<br><br><b>Also</b> if by chance there are other reasons your's does not work then see this link and scroll down to Task Manager and see all the situations and fixes since there are three ways to bring it up.<br><br>&raquo;<A HREF="http://www.kellys-korner-xp.com/xp_t.htm" >www.kellys-korner-xp.com/xp_t.htm</A><br><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101705</guid>
<pubDate>Mon, 03 Mar 2008 17:38:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101669</link>
<description><![CDATA[<A HREF="/useremail/u/1534243"><b>lordstarfyre</b></A> : Hi, I ran the KillTrojan.CMD, and now my Task Manager is disabled.<br><br>How do I turn it back on?<br><br>It appears the Trojan is gone, thanks for that, BTW!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101669</guid>
<pubDate>Mon, 03 Mar 2008 17:31:29 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101661</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : unigray antivirus analysis <br><br>&raquo;<A HREF="http://securitynewsfromthenet.blogspot.com/2008/03/unigray-analysis.html" >securitynewsfromthenet.blogspot.&middot;&middot;&middot;sis.html</A><br><br>and as already posted earlier in this thread..<br><br><b>We detect MonaRonaDona as Trojan.Win32.Monagrey.a and Unigray Antivirus as not-a-virus:FraudTool.Win32.Unigray.a.</b><br><br>&raquo;<A HREF="http://www.viruslist.com/en/weblog?weblogid=208187485" >www.viruslist.com/en/weblog?webl&middot;&middot;&middot;08187485</A><br><br>Copyright &copy; 1996 - 2008<br>Kaspersky Lab<br>Industry-leading Antivirus Software<br>All rights reserved]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101661</guid>
<pubDate>Mon, 03 Mar 2008 17:30:11 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101654</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you soooooo much!  I was completely panicked!!!  Your instructions were easy to follow and I VERY MUCH appreciate your help!!!  (XP User)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101654</guid>
<pubDate>Mon, 03 Mar 2008 17:28:34 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101607</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><small>said by ChasG :</small><br><br>... What these guys did was perpetrate a fraud. Thanks again. </div> And somehow, I don't think that troubles them in the least. Where we may think in terms of right and wrong, others may think in terms of getting away with it or not... and how best to get away with it, at that.<br><small>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101607</guid>
<pubDate>Mon, 03 Mar 2008 17:18:36 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101579</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Well Bill, I used your fix over the weekend for a friend of mine. In his case we had to go in using Safe Mode to delete the entry from the Startup folder, but once we did that everything was fine.<br><br>Thanks for posting the fix - surprising that this is not getting more attention on the main AV sites. Even if all they did was post an advisory it would be nice, but even today if you do a google search you come up with yahoo, cnet and dslreports...<br><br>Having been in the software support and development industry for years, as soon as I saw the post regarding UniGray I felt my spidey-senses go off. For the money they pay at Symantec, McAfee, TrendMicro and others, it is rare enough that none of them had anything to say about a new virus - but then to have some unknown company show up from nowhere and claim they were the only software available to deal with the threat ... well, it was pretty obvious something was not right. I hope all the people reading this contact their credit card companies immediately to protest the fraudulent charges, and take whatever other action they can to make sure whoever is behind UniGray is prosecuted. What these guys did was perpetrate a fraud.<br><br>Thanks again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101579</guid>
<pubDate>Mon, 03 Mar 2008 17:12:28 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20101045</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  :)Thanks so much for ur info keep up the good work]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101045</guid>
<pubDate>Mon, 03 Mar 2008 15:39:41 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20100711</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  classical62 <A HREF="/useremail/u/1534147"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>That sounds about right.<br>Is this passed through Emails I have sent to people? Is this Unigray anti-virus hoping I will want to buy their "protection" and that's why I got it?<br> </div>Don't know about the email but I do not think so..on the other..It is not the first time some group stocked a lake..made you use their fishingpole then charged you by the inch to catch them.  :(<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100711</guid>
<pubDate>Mon, 03 Mar 2008 14:44:24 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20100389</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks to "BCASTNER", I removed MonaRonaDona. IT WORKS!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100389</guid>
<pubDate>Mon, 03 Mar 2008 13:49:37 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20100158</link>
<description><![CDATA[<A HREF="/useremail/u/1534147"><b>classical62</b></A> : That sounds about right.<br>Is this passed through Emails I have sent to people? Is this Unigray anti-virus hoping I will want to buy their "protection" and that's why I got it?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100158</guid>
<pubDate>Mon, 03 Mar 2008 13:15:17 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20100144</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> :  Thanks for the detail classical62. Do you recall if the name was this..RegistryCleanFix2008 for the RegistryCleaner2008.exe<br><br>&raquo;<A HREF="http://www.prevx.com/filenames/X2024140380500743603-0/REGISTRYCLEANER2008.EXE.html" >www.prevx.com/filenames/X2024140&middot;&middot;&middot;EXE.html</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100144</guid>
<pubDate>Mon, 03 Mar 2008 13:12:42 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20100028</link>
<description><![CDATA[<A HREF="/useremail/u/1384595"><b>ctrlaltdelet</b></A> : &raquo;<A HREF="http://www.viruslist.com/en/weblog?weblogid=208187485" >www.viruslist.com/en/weblog?webl&middot;&middot;&middot;08187485</A><br><br>....A comparison of the code of MonaRonaDona and Unigray Antivirus show that there are many, many similarities. This leaves very little doubt that the same group is behind both MonaRonaDona and Unigray......]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100028</guid>
<pubDate>Mon, 03 Mar 2008 12:54:59 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20100023</link>
<description><![CDATA[<A HREF="/useremail/u/1534147"><b>classical62</b></A> : <div class="bquote"><small>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Can you tell us what website you had problems with and where you got the suggestion or though to download that registry fix.. if it is not too personal..it would really help us all to understand how or where people are getting whacked with this one in the first place. And do I then understand your first noticed the MonaRonaDona when you rebooted your PC or first turned it on the next day ?</div>I was trying to make a homepage on the Shelfari.com website. Rural living only enables us to have dial-up so there are some sites, like YouTube that don't work here and that's ok, but I kept getting an "Ajax Toolkit is undefined" and "Internet Script Error" so I typed into the Netscape search engine "Ajax Toolkit" and up came Registry Fix as oneof the choices. It took a few minutes and then "scanned" my computer, showed a bunch ofviruses, corrupt files, blah, blah, blah and said to fix, click here and buy the program to fix them....I already have a anti-virus, scanny thing, so I went to remove the program and couldn't find it anywhere in the PC's files. I went to ASP.Net ( I think, my head is fairly spinnig right now) to download the Ajax Toolkit, thought I did, can't find it anywhere either, shut the computer down about three times thinking it would fix the problem on Shelfari, but it didn't. Since it wasn't something I had to have, I just left the site. That was Friday. Last night I shut the computer down instead of simply letting it hibernate and when I rebooted it this morning, I found the nasty little note, about 3x5 inch size in the lower right hand side of the computer. Hope this helps you find out what or who it's from. <br><br>Thanks  <br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100023</guid>
<pubDate>Mon, 03 Mar 2008 12:53:54 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20099890</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This worked great!  I tried the "Who Lock Me" program and that was unsuccessful.  I also had difficulty figuring out how to start my computer in safe mode.  However, what you posted above worked perfectly and was so easy to follow!<br><br>THANK YOU SO MUCH!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20099890</guid>
<pubDate>Mon, 03 Mar 2008 12:27:34 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20099557</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks for the help!! I, too, woke up to this on my 'puter. I 'may' have used the registryfix2008, but don't know for sure. I was trying to clean out another problem. Your help and tutorials cured more than this one problem and my 'puter is running much bettr now! Thank you again (can I say it too much?) for your 'good fight'!!<br><br>Sincerely,<br><br>Conestogaman]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20099557</guid>
<pubDate>Mon, 03 Mar 2008 11:24:50 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20099477</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Can you tell us what website you had problems with and where you got the suggestion or though to download that registry fix.. if it is not too personal..it would really help us all to understand how or where people are getting whacked with this one in the first place. And do I then understand your first noticed the MonaRonaDona when you rebooted your PC or first turned it on the next day ?<br><br>Thanks  <br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20099477</guid>
<pubDate>Mon, 03 Mar 2008 11:10:13 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20099206</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you for posting all of the information on fixing this virus. I am a complete novice when it comes to doing this, but the steps were easy to follow and it appears that the issue is resolved.<br>I woke up to this virus "announcement" before my eyes were barley open! I had been having trouble with a website and was trying to find a way to fix it...I, too, downloaded "RegistryFix2008" about Thursday or Friday. It said I had all sorts of viruses and corrupt files ( I DO have a anti-virus program) and then wanted $ to buy the program to fix it.....but when I went to find the file so I could delete it, it was no where to be found...until this morning? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20099206</guid>
<pubDate>Mon, 03 Mar 2008 10:18:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20098965</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : There is a simple fix already posted in this thread that requires no external hard drive, no Safe Mode, and no tricks.  See:  &raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20098965</guid>
<pubDate>Mon, 03 Mar 2008 09:21:35 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20098338</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I couldn't do it following your directions but my grandson told me how. It does require an external harddrive.<br>Create a shortcut to the hard drive on your desktop. <br>Do an advanced search for SYSPRO including hidden files<br>Drag the files found on the search to the shortcut<br>Open the external harddrive and delete<br><br>Worked great! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20098338</guid>
<pubDate>Mon, 03 Mar 2008 02:06:21 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20098335</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I did this in XP by selecting safe mode /dos prompt & it allowed the necessary deletions that Windows won't allow.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20098335</guid>
<pubDate>Mon, 03 Mar 2008 02:03:31 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20096316</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> :   <blockquote><small>said by MDReferee :</small><hr>That seems a bit more complicated, doesn' it.<hr></blockquote><br><br>Dunno.<br>Certainly the OP came here for MonaRonaDona.<br>Other issues are not suitable for handling in the Security subForum, and the post would get killed if I attempted to do so.<br><br>Anything that appears to be a one-to-one malware removal must be done only in the Security Cleanup Forum.  The fixes I posted earlier raised some objections by some already;  the fact that they were generic and not directed to a specific individual allowed them to stay.<br><br>One-on-one removal, or any other Trojan issue, would start with this:  &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20096316</guid>
<pubDate>Sun, 02 Mar 2008 18:13:43 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20096308</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : The black box should appear and then disappear.<br>The file you created should disappear as well.<br>Reboot and test.<br>You should be done with MonaRonaDona.<br><br>If you think it did not work, use the second fix method:<br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20096308</guid>
<pubDate>Sun, 02 Mar 2008 18:11:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20096234</link>
<description><![CDATA[<A HREF="/useremail/u/500966"><b>MDReferee</b></A> : <div class="bquote"><small>said by  bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>All the text in the Quote box.</div>I think he's looking for something a little more in depth... you might not have caught this little statement...<br><br><div class="bquote"><small>said by Mato :</small><br><br>...but to kill all Trojan in my system...</div>That seems a bit more complicated, doesn't it. ;)<br><small>--<br>If I didn't see it... it didn't happen!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20096234</guid>
<pubDate>Sun, 02 Mar 2008 17:52:08 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20096019</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hay, i got the text and i save it.<br>When i run it a black box came up and goes off.<br>Wat should i do next?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20096019</guid>
<pubDate>Sun, 02 Mar 2008 17:13:01 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095975</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Bcastner,<br>I still don't get it, can u copy the text that i need here<br>Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095975</guid>
<pubDate>Sun, 02 Mar 2008 17:03:42 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095919</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : All the text in the Quote box.<br>There are horizontal lines to mark the beginning and end of the Quote box.<br><br>The easier fix is a few posts below it.  It uses HijackThis and a free utility called OTMOVEIT2 by Old Timer.<br><br><b>MonaRonaDona Remover</b><br>&raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095919</guid>
<pubDate>Sun, 02 Mar 2008 16:52:35 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095911</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks for your info, I have been able to delete this MonaRonaDona virus from my system and enable task manager but to kill all Trojan in my system, what is the code should i type in notepad before saving as "KillTrojan.cmd"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095911</guid>
<pubDate>Sun, 02 Mar 2008 16:50:34 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095757</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Removed srvspool.exe as suggested. Nice one !! Disappeared completely.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095757</guid>
<pubDate>Sun, 02 Mar 2008 16:12:23 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095648</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : thanx for your info on monaronadona virus.I'm a novice with computers, couldn't have gotten rid of it without all of you]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095648</guid>
<pubDate>Sun, 02 Mar 2008 15:41:01 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095354</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  DevilFrank <A HREF="/useremail/u/839734"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I have not a problem with this malware and I do know that "my community" is informed (&raquo;<A HREF="http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=2928561&SiteID=2" >forums.microsoft.com/WindowsOneC&middot;&middot;&middot;SiteID=2</A>). ;-)<br><br>But I think it is important to know which way is this malware using. Prevention is better than detection - I think.<br> </div>Yup..seems it is really getting deep out there with the UniGrapes... :D<br><br>&raquo;<A HREF="http://forums.microsoft.com/windowsonecare/showpost.aspx?siteid=2&postid=2928561&sb=0&d=1&at=7&ft=11&tf=0&pageid=1" >forums.microsoft.com/windowsonec&middot;&middot;&middot;pageid=1</A><br><br>If you want a theory in Spanish try this link..<br><br>&raquo;<A HREF="http://www.psicofxp.com/forums/seguridad-informatica.47/648696-nuevo-virus-y-su-solucion-monaronadona.html" >www.psicofxp.com/forums/segurida&middot;&middot;&middot;ona.html</A><br><br>If you want another vector theory..seems people who have downloaded and installed something  called REGISTRYCLEANFIX2008.. a crack keygen thing..  also shows  in many  highjack logs along with MonaRonaDona. It might be a connection <small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095354</guid>
<pubDate>Sun, 02 Mar 2008 14:45:51 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20095290</link>
<description><![CDATA[<A HREF="/useremail/u/839734"><b>DevilFrank</b></A> : I have not a problem with this malware and I do know that "my community" is informed (&raquo;<A HREF="http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=2928561&SiteID=2" >forums.microsoft.com/WindowsOneC&middot;&middot;&middot;SiteID=2</A>). ;-)<br><br>But I think it is important to know which way is this malware using. Prevention is better than detection - I think.<br><small>--<br>Regards from Germany. Please excuse my stumbling English</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20095290</guid>
<pubDate>Sun, 02 Mar 2008 14:32:32 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20094926</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : It will likely stay open as a question for at least a while.  The practice in the anti-malware research community is not to discuss the gory details.<br><br>It is a very safe bet that this infection, (as is the case with most) are actively researched.  However, for good reason the results are not always publicly disclosed.  Every Forum post, every AV software that detects the anomalous file, every online scanner that was used, .etc feeds into several common pools of identified questionable files and heuristic behaviors, and action is taken.<br><br>Which is why if your antivirus or other anti-malware tool has a "Community" or "Net" of some kind you have the option to join, please do so.  In addition, letting the AV vendors know in their Forums about an issue that is not resolved with current definitions helps immensly.  Some anti-malware programs will automatically submit over the internet questionable files for anlaysis if so configured.  It is in your interest to use these resources to fight the good fight.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20094926</guid>
<pubDate>Sun, 02 Mar 2008 13:31:58 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20094857</link>
<description><![CDATA[<A HREF="/useremail/u/839734"><b>DevilFrank</b></A> : <div class="bquote"><small>said by  NanDog <A HREF="/useremail/u/921899"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>So has anyone yet figured out what the infection vector is?  In googling about I can read about lots of folks with the issue but can't find any info about how they think they contracted this POS.  :uhh:<br> </div>This question is still open. Do we know the way?<br><small>--<br>Regards from Germany. Please excuse my stumbling English</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20094857</guid>
<pubDate>Sun, 02 Mar 2008 13:19:06 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20094338</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : The only entry that I have seen effecting the Task Manager is the one reverted by the two fixes mentioned earlier in this thread. It may be that there is now an entry in the HKLM hive as well as HKCU for the policy item effecting Task Manger.<br><br>Please do either of the following:<br><br>&#8226; I revised both earlier scripts to include the HKLM hive.  You can safely rerun any of the earlier fixes in order to handle this additional registry area.<br><br><b>-- OR --</b><br><br>&#8226; Download <u>to your Desktop</u> <b>FixPolicies.exe</b>, a self-extracting ZIP archive  from here:<br><textarea name="code" class="text" cols=50 rows=10>http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe&#012;</textarea><!--end code block--><br>&#8226; Double-click <b>FixPolicies.exe</b><br>&#8226;  Click the <b>"Install"</b> button on the bottom toolbar of the box that will open.<br>&#8226; The program will create a new Folder called <b>FixPolicies</b><br>&#8226;  Double-click to Open the new Folder, and then double-click the file within:  <b>Fix_Policies.cmd</b>.<br>&#8226; A black box will briefly appear and then close.  This will enable your Control Panel,  Task Manager and stop any Administrative warnings.<br> <br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20094338</guid>
<pubDate>Sun, 02 Mar 2008 11:25:39 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20094326</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :   :mad:Help Me IM new. I just bought a Dell Computer one month  Two days ago I have the MonaRonaDona Virus. I had been accually installing MSN and their version of messenger. I have been reading your message forum but don't know what I should do.  PLEASE HELP, <br><br>new]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20094326</guid>
<pubDate>Sun, 02 Mar 2008 11:24:29 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20094125</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : i did that and my task manger is still not working...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20094125</guid>
<pubDate>Sun, 02 Mar 2008 10:40:50 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20093989</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I wrote two seperate fixes for this issue, including fixing the task manager, earlier in this thread.  Either one will ensure that the virus is gone and your Task Manager and Title bars on IE and OE are repaired.  See the first page of discussion in this thread.  If you have removed the file, it will not harm things to do the full fix steps given earlier.  They will repair Task Manager access among other things.  Both will delete the active infector file if it still exists as well.  The second one, using a freeware utility OTMOVEIT, would be the best choice, as it includes a first step using HijackThis that will ensure that no access denied errors are an issue for you.  OTMOVEIT will unregister the file prior to deletion, and then schedules the actual deletion for the next restart, so it would not have access denied errors in deleting the file.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093989</guid>
<pubDate>Sun, 02 Mar 2008 10:10:00 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20093750</link>
<description><![CDATA[<A HREF="/useremail/u/233614"><b>Rxdoxx</b></A> : <div class="bquote"><small>said by jimschoe :</small><br><br>I just Tried to delete the Srvspool and it says access denied. Anyone else have any new news??<br> </div>If you were registered here I could have sent you this in a message and not have to "mess" the thread discussion a little :)<br>A freebie <A HREF="http://ccollomb.free.fr/unlocker//A"> Unlocker</a> should free something so you can delete. <br><small>--<br>Was a Cruise Fanatic, one cruise on Princess cured me. Bleah</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093750</guid>
<pubDate>Sun, 02 Mar 2008 09:04:42 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20093582</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : hi i am trying to find task manger trooble shooting..can't find it..how do i get my task manger to work please]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093582</guid>
<pubDate>Sun, 02 Mar 2008 08:00:11 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20093541</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : how do i get my task mangerto work]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093541</guid>
<pubDate>Sun, 02 Mar 2008 07:40:54 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20093266</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : TOO get rid of the MonaRondaDona virus,use key F8, go into Safe mode find the startup program an DELETE Srvspool.exe then restart your computer.It should be gone.....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093266</guid>
<pubDate>Sun, 02 Mar 2008 03:43:23 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20093170</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : THANK!!  That did the trick.  I am very thankful! I was not sure there to go after Nortons did not find the virus!  But this worked.  Thanks again!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093170</guid>
<pubDate>Sun, 02 Mar 2008 02:38:21 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20092365</link>
<description><![CDATA[<A HREF="/useremail/u/921899"><b>NanDog</b></A> : So has anyone yet figured out what the infection vector is?  In googling about I can read about lots of folks with the issue but can't find any info about how they think they contracted this POS.  :uhh:<br><small>--<br>See ya across the Rainbow Bridge, my good and faithful friend!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20092365</guid>
<pubDate>Sat, 01 Mar 2008 22:26:26 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20092348</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : okay ya'll I got this virus feb. 29th at 4:39am. I'm not a comp. newbie. I know comps. I couldn't find anything on this virus so I called the geek squad and they sent me here. I read everything and copied and pasted SRVSPOOL.EXE to search and found the file. I deleted it from search. Now let me tell ya'll everything I did prior to that.<br>I have 3 different profiles on this one comp. I went to another profile and deleted the profile but saved the major files to another profile. The virus wasn't on it. I then went back to the infected profile and tried to find out what in the heck happened and why virus protector didn't go off. Now finding out that it is a hijacking and made into a anti-virus scam. I must say this is very intelligent! I couldn't find the main file it had made so I just did a system restore. My comp. was running okay but still something wasn't right. I was still losing files and things weren't working. After I found the main file and deleted it and deleted the files that wasn't working correctly any longer and I am still going to delete the infect profile and make another. This is the simplest way I know if you are not very computer knowledge; most people can run search and right click a mouse and scroll down to delete.<br><br>Best wishes to anyone seeking help with this pain the butt virus.<br><br>Sincerely, <br>Sassy ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20092348</guid>
<pubDate>Sat, 01 Mar 2008 22:22:42 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20091908</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by Kas :</small><br><br>Thank you for the removal tool, bcastner.<br>For Windows Vista it worked from safe mode.<br>I installed Spotmau WinCare 2008 on the same date SRVPOOL was created on my computer. I'm wondering if there is any connection between them. Did anybody who had Spotmau installed got this problem? <br> </div>Can you tell us the reasons and steps that led you to even download and install Spotmau WinCare 2008 in the first place ?<br><br>Thanks<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20091908</guid>
<pubDate>Sat, 01 Mar 2008 20:48:12 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20091763</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you for the removal tool, bcastner.<br>For Windows Vista it worked from safe mode.<br>I installed Spotmau WinCare 2008 on the same date SRVPOOL was created on my computer. I'm wondering if there is any connection between them. Did anybody who had Spotmau installed got this problem? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20091763</guid>
<pubDate>Sat, 01 Mar 2008 20:12:08 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20090444</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : My previous post should have read 1st Mar 2008 as the date. Hope this solution works for you. Again, I did a system restore and this rid me of the problem. 20:15pm]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20090444</guid>
<pubDate>Sat, 01 Mar 2008 15:17:01 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20090424</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Having tried unsuccessfully some of the recommendations here, I did a system restore and this seems to have worked(touch wood) 1st Feb 2008 UK 21:10pm]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20090424</guid>
<pubDate>Sat, 01 Mar 2008 15:12:37 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20088377</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I guess we should be nicer to our Vista users.  The following <b>MonaRonaDona</b> removal will work for either Windows XP or Windows Vista, Windows 2003 and Windows 2008:<br><br>1. Download </b>HijackThis</b>:<br><textarea name="code" class="text" cols=50 rows=10>http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe&#012;</textarea><!--end code block--><br>&#8226; Save HJTinstall.exe to your desktop. <br>&#8226; Double-click on the desktop icon for <b>HJTinstall.exe</b>. <br>&#8226; By default it will install to C:\Program Files\Trend Micro\HijackThis. It will also create a Desktop icon.<br>&#8226; Double click the HijackThis icon on your Desktop to start the Program.  Select "System scan only".<br><br>Checkmark these items (<b>if found</b>):<br><br><b>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MonaRonaDona<br>O4 - HKLM\..\Run: [.NET.] \FUD.exe<br>O4 - Global Startup: SRVSPOOL.exe<br>O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleanFix2008\RegistryCleaner2008.exe</b><br><br>Click "<b>Fix checked</b>", and when it finishes exit HijackThis.<br><br>2. Please download  to your Desktop <b>OT_MOVEIT2.exe</b>:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>Please double-click OTMoveIt2.exe to run the utility.<br><b>{Vista users -- right click and "Run as Administrator"}</b><br>Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy); or click on the little highlighted text on the top right of the Code box that says "<i>copy to clipboard</i>":<br><br><textarea name="code" class="text" cols=50 rows=10>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr&#012;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr&#012;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Window Title&#012;HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Window Title&#012;HKEY_CURRENT_USER\Software\Microsoft\Outlook Express\\Window Title&#012;C:\Program Files\RegistryCleanFix2008&#012;C:\Program Files\UniGray Antivirus &#012;C:\Documents and Settings\All Users\SRVSPOOL.EXE /S /D&#012;C:\Users\SRVSPOOL.EXE /S /D&#012; &#012;</textarea><!--end code block--><br>Return to OTMoveIt2, right click in the <b>"Paste List Of Files/Patterns To Search For and Move"</b> window.<br><b><i> IMPORTANT -- </i></b> Paste only into the <u>bottom</u> input panel (under the <b>Yellow </b>bar),  The top panel will not help you.<br>Right-click and choose <b>Paste</b>.<br><br>Click the red <b>Moveit</b> button.<br>This will take several minutes as a guess, as I am scanning the user profile folder completely.<br>When it has finished, look in the the large right-hand panel that shows Results.  You should see at least the principal infector files are deleted, and whatever applicable registry changes were made.  (Not all might apply in your case.)<br>Close OTMoveIt2 when it has finished.<br><br>Note:  If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose <b>Yes.</b><br><br>Now, Double click to open <b>OTMOVEIT2</b> again.<br>Click the green button, "<b>CleanupUp!</b>" at the top.<br>{Note:  it will need to access the internet to download a small script file.  Please allow your Firewall to do so.}<br><br>When it finishes it will have deleted all of its qauarantines, as well as the OTMOVEIT2 program and all created folders.<br><br><b>Reboot.</b><br><br>Best wishes,<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088377</guid>
<pubDate>Sat, 01 Mar 2008 05:00:28 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20088225</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This fix worked!  I have Vista and had to go into safe mode to delete it.  I had Microsoft tech support logged into my pc and they followed the posted directions and it worked with a little work.  They had no record of the virus as of yet and they copied the file to submit it.  My One Care software did not catch it.  I also searched Symantec. Kaspersky and Trend Micro sites for help and none had anything to offer.  I could not find any damage to my pc from it.  I did notice that the install date was 2-23-08.  The file properties said that it was a file from Microsoft.  The Microsoft Tech support person I worked with in the virus department was very good.  He did a search on the file name and determined that is NOT a Microsoft File!!!<br><br>The tech went into the registry to change the setting for the task manager and also had to go there to give permissions in order to delete the file.<br><br>Good luck to everyone and thanks for the tip listed above!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088225</guid>
<pubDate>Sat, 01 Mar 2008 03:01:20 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087495</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b><i>MonaRonaDona Removal Tool</i></b><br><br><b>~~~ EDIT:  You would be better doing the more comprehensive fix posted further below for Vista, XP, Windows 2003 and Windows 2008.  If you have any issues, run the steps in Safe Mode.</b><br><br><b><i>Important Note:</i></b>  This fix version is likely best done in <b>Safe Mode</b> after creating the actual script below.  The second "fix"  (<b>below</b>): &raquo;<A HREF="/forum/r20088377-">Re: MonaRonaDona "virus"?</A>  does not have this requirement, and is likely the best overall choice.<br><br>Using your mouse, <b>Highlight</b> and then Right-click | <b>Copy</b> the <i>entire</i> contents of the Quote box below, including blank lines:<br>          <blockquote><small>quote:</small><hr>@echo off<br>cd %~dp0<br><br>REM :)  Quick cleanup  - Restores Task Manager, <br>REM :)  Fixes the IE Header, and <b>Removes the Trojan</b> <b>MonaRonaDona</b>.<br>REM :)  DSLR Security Forum, Bill Castner<br>REM :)  If you find this file, go ahead and delete it<br><br>TSKILL SRVSPOOL /A >nul<br>del /a/f/q "%systemdrive%\Documents and Settings\All Users\Start Menu\Programs\Startup\SRVSPOOL.EXE"<br>rd /s/q "C:\Program Files\UniGray Antivirus">nul<br>rd /s/q "C:\Program Files\RegistryCleanFix2008">nul<br><br>(<br>echo.REGEDIT4<br>echo.<br>echo.[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]<br>echo."DisableTaskMgr"=dword:00000000<br>echo.<br>echo.[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]<br>echo."DisableTaskMgr"=dword:00000000<br>echo.<br>echo.[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]<br>echo."Window Title"=-<br>echo.<br>echo.[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]<br>echo."Window Title"=-<br>echo.<br>echo.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Outlook Express]<br>echo."Window Title"=-<br>echo.<br>echo.<br>)>checkit.reg<br><br>regedit /s checkit.reg<br>del checkit.reg<br>del %0<br>exit<br><br><hr></blockquote><br><br>Open a new Notepad session (Do not use a Word Processor or WordPad).  Click "Format" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b>Save as...</b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"KillTrojan.cmd"</b> .  Exit.<br><br>Double click the new file <b>"KillTrojan.cmd"</b> to run the program.  There is a black box that will open but there are no user prompts, and this will take only moments to complete.<br><br>Best wishes,<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087495</guid>
<pubDate>Fri, 29 Feb 2008 23:10:03 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087351</link>
<description><![CDATA[<A HREF="/useremail/u/944528"><b>jrmarto</b></A> : <br>This is fascinating to me as a co-worker of my husband's called me this morning complaining of this very infection, on a laptop I just helped her buy last week.  She was using the Verizon subscription antivirus product. She told me she had "cured" it by creating another adminstrator account, moving her files over, and deleting her one week old account - but asked me if I had any suggestions.  Never having heard of MondRonaDona I advised her to run an online scan at Trend Micro, download spybot and adaware, and keep an eye on what was going on with her computer.  I would be happy to (on Monday) walk her through creating a HJT log if anybody is interested in seeing what is on her computer.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087351</guid>
<pubDate>Fri, 29 Feb 2008 22:36:28 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087328</link>
<description><![CDATA[<A HREF="/useremail/u/921899"><b>NanDog</b></A> : MysteryFCM said: "hehe nope, my reply was to jimschoe  (I'm already familiar with BC )"<br><br>Sorry!  My bad!  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087328</guid>
<pubDate>Fri, 29 Feb 2008 22:33:41 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087319</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : If I get a live one I will do a capture and post at MR.<br><br>Just read this "review" of Unigray Antivirus.  <br> <blockquote><small>quote:</small><hr>Re: unigray antivirus <br>by Kees Bakker  - 2/27/08 5:20 AM<br>In reply to: monadonarona by Kees Bakker  <br>I donwloaded their program and installed it (after Norton found it was virus-free). I must say it's amazing.<br><br>All it installs:<br>- the program itself, some 6 Mb <br>- an uninstall dat and exe<br>- an icon<br>- some shortcuts and pifs<br>- NO virus definitions<br><br>Then I ran it. It said:<br>Virus definition version: 02.73.88 (Februari 15, 2008)<br>DB version: 4.34/2008<br>Protecting against 679871 threads<br>That's fairly impressive for a company that's only on the web for 6 days.<br><br>Then (after disabling the real-time protection it offers, which is amazing on its own given the components it installed) I used it to scan my clean (according to Norton) system. It found:<br>- 240 viruses<br>- 48 malware<br>- 43 adware<br>Most of them were in Microsoft programs (like Visual Studio). And I'm sure they don't contain those viruses and malware. So these are false positives. I preferred not to run the Repair, for obvious reasons.<br><br>Then I checked for updated definitions. Couldn't harm, as I had none. So the program contacted their website (or so it said) and reported I already had the latest version (those of Februari 15, remember). Then I went to their (rather unimpressive) website and found out that they added detection for monaronadona on Februari 22. <br>Which leaves me wondering why so many of our new members report it cleaned it off their systems if it's a version one week older.<br><br>I'm uninstalling the program now, and still feel rather safe behind my firewall.<br><br>Somehow, I keep thinking this is a scam. <br><br>Kees<br><hr></blockquote><br>&raquo;<A HREF="http://forums.cnet.com/5208-6132_102-0.html?forumID=32&threadID=285491&messageID=2715970" >forums.cnet.com/5208-6132_102-0.&middot;&middot;&middot;=2715970</A><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087319</guid>
<pubDate>Fri, 29 Feb 2008 22:31:41 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087306</link>
<description><![CDATA[<A HREF="/useremail/u/1398947"><b>MysteryFCM</b></A> : hiya dude :)<br><br>Been trying to find a sample of this that I can analyse but haven't been successful thus far]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087306</guid>
<pubDate>Fri, 29 Feb 2008 22:28:35 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087284</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Steve and I are known to each other.<br>Here and elsewhere.<br><br>What I was hoping is that someone victimized by this would tell us if you get messages from "UniGray Antivirus".  That is the part that bothers me at the moment.<br><br>(If you have this infection, I would be happy to remove it in the Cleanup subForum.  It should go pretty easily.)<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087284</guid>
<pubDate>Fri, 29 Feb 2008 22:25:36 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087271</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : How to Change the Internet Explorer Window Title<br>&raquo;<A HREF="http://support.microsoft.com/kb/176497" >support.microsoft.com/kb/176497</A><br>Yup Bill,<br>Seems to be pretty well orchestrated. <br>Besides the UniGray Antivirus scam going on with it and the Youtube video..<br>Others are now posting special (untested and unknown) tools to remove it. :(<br><br>J Hilton postings:<br><br>&raquo;<A HREF="http://www.howtofixcomputers.com/forums/windows-xp/monaronadona-134759-4.html" >www.howtofixcomputers.com/forums&middot;&middot;&middot;9-4.html</A><br><br>&raquo;<A HREF="http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=2931673&SiteID=2" >forums.microsoft.com/WindowsOneC&middot;&middot;&middot;SiteID=2</A><br><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087271</guid>
<pubDate>Fri, 29 Feb 2008 22:24:18 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087265</link>
<description><![CDATA[<A HREF="/useremail/u/1398947"><b>MysteryFCM</b></A> : hehe nope, my reply was to jimschoe ;) (I'm already familiar with BC ;))]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087265</guid>
<pubDate>Fri, 29 Feb 2008 22:22:42 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20087230</link>
<description><![CDATA[<A HREF="/useremail/u/921899"><b>NanDog</b></A> : <div class="bquote"><small>said by  MysteryFCM <A HREF="/useremail/u/1398947"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>You really should post in the infection help forums<br><br>&raquo;<A HREF="/forum/cleanup">Security Cleanup</A><br> </div>If your suggestion was to the OP it's a bit misguided.<br><br>bcastner is one of the accredited helpers on the Security Cleanup forum: &raquo;<A HREF="/faq/seclean/1.2_SCU_Helpers">Security Cleanup FAQ</A><br><br>He knows what he's doing.  :)<br><small>--<br>See ya across the Rainbow Bridge, my good and faithful friend!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087230</guid>
<pubDate>Fri, 29 Feb 2008 22:17:07 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20086952</link>
<description><![CDATA[<A HREF="/useremail/u/1398947"><b>MysteryFCM</b></A> : You really should post in the infection help forums<br><br>&raquo;<A HREF="/forum/cleanup">Security Cleanup</A><br><br>But to get rid of this specific file;<br><br>1. Either log into Safe Mode and delete it there or<br>2. Download the following, right click the file you want to delete and select "Who Lock Me", then kill the process locking it (will then allow you to delete it)<br><br>&raquo;<A HREF="http://freeware.it-mate.co.uk/?Editors_Choice&pid=170" >freeware.it-mate.co.uk/?Editors_&middot;&middot;&middot;&pid=170</A><br><br>or ... <br><br>3. Use MoveOnBoot<br><br>&raquo;<A HREF="http://www.snapfiles.com/get/moveonboot.html" >www.snapfiles.com/get/moveonboot.html</A><br><br>Or ....<br><br>4. See the following;<br><br>&raquo;<A HREF="http://www.aumha.org/a/stubborn.php" >www.aumha.org/a/stubborn.php</A><br><small>--<br>Regards<br><br>Steven Burn<br>Ur I.T. Mate Group<br>www.it-mate.co.uk<br><br>Keeping it FREE!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20086952</guid>
<pubDate>Fri, 29 Feb 2008 21:29:34 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20086852</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I just Tried to delete the Srvspool and it says access denied. Anyone else have any new news??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20086852</guid>
<pubDate>Fri, 29 Feb 2008 21:10:13 EDT</pubDate>
</item>

<item>
<title>Re: MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20086093</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Despite lack of information on the Internet, I was able to pinpoint the culprit that was causing my machine to start acting up due to the MonaRonaDona virus.<br><br>I was able to fix the problem and here is how.<br><br>The virus installs an executable SRVSPOOL.EXE in the startup folder of the all users account. Click Start/Programs/Startup, right click the SRVSPOOL.EXE entry and delete it. How to fix the header of your Internet explorer and how to re-enable taskmanager, is posted in numerous postings online.<br><br>Re-enable Task Manager: Troubleshooting Windows XP, Tweaks and Fixes for Windows XP<br>Go to this page and try #51 from the right column. Click on "enable the task<br>manager."<br><br>Modify header of Internet explorer: How do i get rid of monaronadona on top bar of my homepage? - Yahoo! Answers<br>(optionally, you can manually type "Microsoft Internet Explorer" to replace the string "MonaRonaDona".<br><br>After that, reboot your machine.<br><br>The virus puts a message on the screen. Aside from that, the task manager is disabled, the header of Internet Explorer is modified and when trying to open programs, those programs are shut down immediately.<br><br>Whatever you do, do NOT download and install the virus scanner named UniGray. That "scanner" is a scam, a non-working piece of software. The website tries to get you to register and pay for something that does nothing.<br><br>Hope this info helps those who come across this virus. It seems to be a brand new occurence given the lack of solutions found on the Internet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20086093</guid>
<pubDate>Fri, 29 Feb 2008 18:55:47 EDT</pubDate>
</item>

<item>
<title>MonaRonaDona &#x22;virus&#x22;?</title>
<link>http://www.dslreports.com/forum/remark,20082590</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : What is up with this new one that seems to have hit many in the last week:  &raquo;<A HREF="http://groups.google.com/groups/search?q=monaronadona&start=0&scoring=d&hl=en" >groups.google.com/groups/search?&middot;&middot;&middot;=d&hl=en</A><br><br>It looks like you could use HijackThis to stop this one:<br><b>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MonaRonaDona<br>O4 - Global Startup: SRVSPOOL.exe</b><br><br>It appears to be linked somehow with "UniGray Antivirus", but in what way is unclear.  It is clearly extortion-ware, offering on the user's screen:  "Welcome to MonaRonaDona; hi, my name is Mona RonaDona. i am a virus& i am here to Wreck Your PC."<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20082590</guid>
<pubDate>Fri, 29 Feb 2008 08:44:48 EDT</pubDate>
</item>

</channel>
</rss>
