<% if Request.querystring("retry") = "member" or Request.cookies("logged") <> "" then %>

        <%= Request.cookies("logged")%> <%else Response.Redirect "../default.asp" end if %>

         
         

 

Virus Name Risk Assessment
Monagrey Low
 
Discovery Date Min DAT
04/03/2008 5245
 
Type SubType
Trojan Win32
 
Virus Characteristics
 

Monagrey is a trojan which modifies IE start page and prevents common applications from running.

It will modify the following registry key to run at startup:
HKEY_LOCAL_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows: "%LOCATION%\SRVSPOOL.exe"

(where %LOCATION % is the location of the folder where it resides e.g. C:\)

Upon reboot, the trojan will display a pop up window.

 

It will change IE start page to point to the following URL:
 

  • http://en.wikipedia.org/wiki/Human_rights

and also prevent applications with the following names in their title bar from running:

  • Date And Time
  • Windows Task Manager
  • Registry Editor
  • Irfanview
  • Google Talk
  • Macromedia
  • Adobe
  • Microsoft Visual
  • Windows Media Player
  • Winamp
  • Microsoft Office
  • Microsoft Excel
  • Microsoft Word
  • Messenger
Symptoms
 
  • Unexpected termination of previously mentioned applications
  • Modification of IE start page to previously mentioned URL.
 
Method Of Infection
 
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include email, IRC, peer-to-peer networks, newsgroup postings, etc.

 

Removal Instructions
 
Use specified engine and DAT files for detection and removal. This threat will be cleaned if you have this combination.
 

 

     1386 Shabakeh Gostar Eng

 

|      كشخصات نیرنس ما    |     مشدار نیرنس جدید     |