Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » MonaRonaDona "virus"?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Already Covered - Ignore »
« The tendency of (pre-checked) toolbars  
AuthorAll Replies


bcastner
Premium,VIP,MVM
join:2002-09-25
Chevy Chase, MD
clubs:
·Verizon Online DSL


1 edit
reply to bcastner
Re: MonaRonaDona "virus"?

Where does MonaRonaDona come from?

quote:
"We’re still researching this", says Joel Schouwenberg of Kaspersky Labs, who calls the MonaRonaDona Trojan of the past week to be "among the most elaborately orchestrated scams" he’s seen.
See if these help:
»blog.threatfire.com/
»blog.washingtonpost.com/security···_ex.html
»www.networkworld.com/news/2008/0···cam.html


jefe
Premium
join:2001-05-19
Northport, NY
"We're still researching this" doesn't add much. I was hoping that one or more of the posters in this thread who have been infected might report how they suspect they got bitten.


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC


4 edits
said by jefe See Profile :

"We're still researching this" doesn't add much. I was hoping that one or more of the posters in this thread who have been infected might report how they suspect they got bitten.
you could start reading here as to what classical62 posted and then the rest of the thread where two others posted how they were infected.

»Re: MonaRonaDona "virus"?
here is another post by Wayonmyway
»Re: MonaRonaDona "virus"?

Then you can read these links

Monday, March 3, 2008
MonaRonaDona Mystery Solved

Some of these users unfortunately were persuaded over the past week or so to run a version of "RegistryCleaner2008.exe" (afec3d0f13b8f866f2c2eec122024165 for you researchers out there), as can be seen here:

Along with a particular version of "RegistryCleaner2008.exe", came a little friend by the name of "srvspool.exe" and friends. Some of the infection symptoms are somewhat simple and silly compared to other threats we've been researching -- "MonaRonaDona" appears in the Internet Explorer title bar, the "DisableTaskManager" key in the registry is set so users cannot use Ctl+Alt+Del to kill the threat on their system, and "srvspool.exe" appears in the All Users startup folder.

»blog.threatfire.com/

What we know about REGISTRYCLEANER2008.EXE:
»www.prevx.com/filenames/X2024140···EXE.html

--
Gladiator Security Forum »www.gladiator-antivirus.com/
Missing Kids
»www.missingkids.com/
Forums » Up and Running » Security » SecurityAlready Covered - Ignore »
« The tendency of (pre-checked) toolbars  


Thursday, 26-Nov 15:13:04 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [106] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [69] TiVo Sees Record Customer Losses
· [57] In-Flight Internet Headed For Bumpy Landing?
· [37] ICANN Slams DNS Redirection
· [36] Thanksgiving Open Thread
· [34] Senators Want ACTA Made Public
· [34] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· SSD [Computer Hardware Discussion/Reviews]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Ottawa South Highspeed - WOW! [Canadian Broadband]
· Rogers Rocket Stick [Rogers]
· Windows 7 boot manager editing questions [Microsoft Help]