MonaRonaDona

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bowks, Mar 3, 2008.

  1. bowks

    bowks Private First Class

    I can't believe I got this virus one week after I got rid of Vundo and downloaded all the protection, as per Majorgeeks "How to protect yourself from Malware".
    I am trying to go through the process of the Malware Removal Guide to get rid of this Virus. I have run SuperAntiSpyware and am running the Spybot Search and Destroy. When I was disabling the Teatimer, and unchecking the boxes in the IEtweaks I noticed that under "Internet Explorer custom title," Current user: MonaRonaDona. I tried to delete it but it keeps coming back. Also now that I look at the settings in IE tweaks again, I see there is a check in "lock hosts file read only as protection against hijackers" again.

    Should I try to uncheck the box and run Spybot again? What shall I do with the Current User?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on thru all steps in the READ & RUN ME and attach the logs when you finish. As long as Teatimer is disabled, you should be OK. The hosts file protection feature added in the 1.5.x versions of Spybot can be helpful but it is also not necesary and it is up to you whether you want to enable it or not.
     
  3. bowks

    bowks Private First Class

    3 hrs sleep and I finally finished and the pop up screen as left the screen. What a b*tch!

    Do you think you could look at the logs and see if everything looks OK?

    I would be very grateful. Thanks a lot.
     

    Attached Files:

  4. bowks

    bowks Private First Class

    Nope. She's back! At least the Information box is back on my screen (must be after I start Mozilla) telling me how its going to stuff up my computer to raise my concern about human rights violations.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because the srvspool.exe file that is responsible for the problem was still in your startup folder.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 3
    SpywareBlaster v3.5.1 <-- old version! We will install the new version down below.
    Viewpoint Media Player (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SRVSPOOL.exe
    C:\WINDOWS\system32\CF49.exe
    C:\WINDOWS\Temp\GUHBOKGUMUBIH
    C:\WINDOWS\Temp\HKUJINNIUUUNH
    C:\WINDOWS\Temp\JBBFMULCBKVLG
    C:\WINDOWS\Temp\UHOBCGOBUGNOO
    C:\WINDOWS\Temp\UIGLOGNBNFIOF
    C:\WINDOWS\Temp\UJHFJOBNOIOGO
    C:\WINDOWS\Temp\UKIBUUOOVOIIO
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now install this:SpywareBlaster 4.0


    Now delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Gail Bowker\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. bowks

    bowks Private First Class

    Chaslang I think its fixed.:D Thank you very much. You guys are the best! I really wish I could do something to return the favour. I am sooooo grateful and I think you are very cool:cool

    Please find attached logs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  8. bowks

    bowks Private First Class

    I have been using Mozilla and tonight I opened up Internet Explorer only to find that every page has MonaRonaDona at the end of it. eg this page:
    MonaRonaDona - MajorGeeks Support Forums - MonaRonaDona
    or
    MSN.com - MonaRonaDona

    Does that mean it has come back?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure. If you still have the MGtools folder, do the below. If you already deleted C:\MGtools, redownload it and run the MGtools.exe like you did in the READ ME but do not attach a log yet. First do the below.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MonaRonaDona

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:

    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. bowks

    bowks Private First Class

    Hi Chaslang

    Please find attached the requested log.

    It seems to be fixed now. Thanks.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean and you should complete all of my final instructions given in message # 7 now if you have not already done so.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds