PDA

View Full Version : spyware? microbillsys - mbslgn32.dll, msbmon32.exe, msbreg32.exe



neurotran
2006-10-17, 17:52
Greetings

It has been over 10 months since I took the advice given in this forum, installed SBS&D and switched to Fx. Since then, touch wood, not a peek from any undesirable software. Many thanks to everybody who contributes.

This is not a problem with my machine. A friend had this nuisance in his machine, running Win2000. A frameless IE window opens shortly after he connects to internet, impossible to minimize or close, also constantly stealing focus so there is no way to see any other programs. He is told he owes money and asked a payment for a service he says he did not knowingly subscribed. Window also states that it will stay there until he pays. The window is making a connection to the microbillsys.com, which seems a legitimate company, but the running program is straight out of hell. No un-installation facility, killing with task manager is pointless as it launches again. Several emails he sent to microbillsys went unanswered.

I run a scan with S&D (and some others), latest definitions, but nothing was found. I pinpointed the problem to three files in winnt/system32/ folder:

mbslgn32.dll
mbsmon32.exe
mbsreg32.exe

which I have copies. Before I go ahead and delete them at startup I wanted to get your much valued advice as I can not find a mention of these in any where on web. Thanks.

illukka
2006-10-17, 18:19
hi

those are most likely malware.
if you still have copies of them please could you send me samples?
send as attachment to illukka AT malware-research.co.uk
remove spaces from the addy and replace AT with @ of course ;)

any chance of gettin a hijackthis log from the infected computer ?

neurotran
2006-10-17, 19:29
Many thanks for the prompt response


...
if you still have copies of them please could you send me samples?
...
any chance of gettin a hijackthis log from the infected computer ?
Files are on their way, log may be a while until I see him next. Thanks

illukka
2006-10-17, 20:28
hi

take your time :)
thanks for the samples, i will keep this thread open until you return ;)

edit: 2 of the 3 files are confirmed malware!!
but very porrly detected by different scanners. working on that issue.. :)
thanks again

tashi
2006-10-30, 16:37
How is it going neurotran :)

illukka
2006-11-06, 07:20
As the problem appears to be resolved this topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.


glad we could help