Results 1 to 6 of 6

Thread: spyware? microbillsys - mbslgn32.dll, msbmon32.exe, msbreg32.exe

  1. #1
    Junior Member
    Join Date
    Dec 2005
    Posts
    10

    Default spyware? microbillsys - mbslgn32.dll, msbmon32.exe, msbreg32.exe

    Greetings

    It has been over 10 months since I took the advice given in this forum, installed SBS&D and switched to Fx. Since then, touch wood, not a peek from any undesirable software. Many thanks to everybody who contributes.

    This is not a problem with my machine. A friend had this nuisance in his machine, running Win2000. A frameless IE window opens shortly after he connects to internet, impossible to minimize or close, also constantly stealing focus so there is no way to see any other programs. He is told he owes money and asked a payment for a service he says he did not knowingly subscribed. Window also states that it will stay there until he pays. The window is making a connection to the microbillsys.com, which seems a legitimate company, but the running program is straight out of hell. No un-installation facility, killing with task manager is pointless as it launches again. Several emails he sent to microbillsys went unanswered.

    I run a scan with S&D (and some others), latest definitions, but nothing was found. I pinpointed the problem to three files in winnt/system32/ folder:

    mbslgn32.dll
    mbsmon32.exe
    mbsreg32.exe

    which I have copies. Before I go ahead and delete them at startup I wanted to get your much valued advice as I can not find a mention of these in any where on web. Thanks.

  2. #2
    Expert-Emeritus illukka's Avatar
    Join Date
    Nov 2005
    Location
    The Pits Of Hell
    Posts
    1,289

    Default

    hi

    those are most likely malware.
    if you still have copies of them please could you send me samples?
    send as attachment to illukka AT malware-research.co.uk
    remove spaces from the addy and replace AT with @ of course

    any chance of gettin a hijackthis log from the infected computer ?
    I Am A Proud Member of ASAP Since 2004

    To Ride, Shoot Straight And Speak TheTruth

    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!

  3. #3
    Junior Member
    Join Date
    Dec 2005
    Posts
    10

    Default

    Many thanks for the prompt response
    Quote Originally Posted by illukka View Post
    ...
    if you still have copies of them please could you send me samples?
    ...
    any chance of gettin a hijackthis log from the infected computer ?
    Files are on their way, log may be a while until I see him next. Thanks

  4. #4
    Expert-Emeritus illukka's Avatar
    Join Date
    Nov 2005
    Location
    The Pits Of Hell
    Posts
    1,289

    Default

    hi

    take your time
    thanks for the samples, i will keep this thread open until you return

    edit: 2 of the 3 files are confirmed malware!!
    but very porrly detected by different scanners. working on that issue..
    thanks again
    Last edited by illukka; 2006-10-17 at 21:08. Reason: added info
    I Am A Proud Member of ASAP Since 2004

    To Ride, Shoot Straight And Speak TheTruth

    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!

  5. #5
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,964

    Default

    How is it going neurotran
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  6. #6
    Expert-Emeritus illukka's Avatar
    Join Date
    Nov 2005
    Location
    The Pits Of Hell
    Posts
    1,289

    Default

    As the problem appears to be resolved this topic has been archived.

    If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.


    glad we could help
    I Am A Proud Member of ASAP Since 2004

    To Ride, Shoot Straight And Speak TheTruth

    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •