spyware? microbillsys - mbslgn32.dll, msbmon32.exe, msbreg32.exe

Status
Not open for further replies.

neurotran

New member
Greetings

It has been over 10 months since I took the advice given in this forum, installed SBS&D and switched to Fx. Since then, touch wood, not a peek from any undesirable software. Many thanks to everybody who contributes.

This is not a problem with my machine. A friend had this nuisance in his machine, running Win2000. A frameless IE window opens shortly after he connects to internet, impossible to minimize or close, also constantly stealing focus so there is no way to see any other programs. He is told he owes money and asked a payment for a service he says he did not knowingly subscribed. Window also states that it will stay there until he pays. The window is making a connection to the microbillsys.com, which seems a legitimate company, but the running program is straight out of hell. No un-installation facility, killing with task manager is pointless as it launches again. Several emails he sent to microbillsys went unanswered.

I run a scan with S&D (and some others), latest definitions, but nothing was found. I pinpointed the problem to three files in winnt/system32/ folder:

mbslgn32.dll
mbsmon32.exe
mbsreg32.exe

which I have copies. Before I go ahead and delete them at startup I wanted to get your much valued advice as I can not find a mention of these in any where on web. Thanks.
 
hi

those are most likely malware.
if you still have copies of them please could you send me samples?
send as attachment to illukka AT malware-research.co.uk
remove spaces from the addy and replace AT with @ of course ;)

any chance of gettin a hijackthis log from the infected computer ?
 
Many thanks for the prompt response
...
if you still have copies of them please could you send me samples?
...
any chance of gettin a hijackthis log from the infected computer ?
Files are on their way, log may be a while until I see him next. Thanks
 
hi

take your time :)
thanks for the samples, i will keep this thread open until you return ;)

edit: 2 of the 3 files are confirmed malware!!
but very porrly detected by different scanners. working on that issue.. :)
thanks again
 
Last edited:
As the problem appears to be resolved this topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.


glad we could help
 
Status
Not open for further replies.
Back
Top