microbillsys

Currently reading:
microbillsys

Ffoxy

Telford's Own...
Joined
Apr 26, 2007
Messages
13,617
Points
2,161
I know I know... surf safe etc... it was the kids lol! :)

Anyway, PC keeps popping up what I think is a Spyware infection, auth.microbillsys.com :mad:

Any easy free way to remove or is it tough as I suspect it may be? :confused:

Bloody persistent and annoying! (n)
 
Who's been browsing dodgy XXX rated sites then??? :p

It's a well known peice of Spyware that certain Adult sites use when you select a "free trail". ;)

Don't ask how I know all this. :eek:

Here's what you want to do...

You will need to use a program called "Hijack This" - you can get it from this link. >>> http://www.merijn.org/files/HiJackThis_v2.exe

Run the program, and post ALL of what it comes up with on here and I will help you from there on. :)
 
Who's been browsing dodgy XXX rated sites then??? :p

It's a well known peice of Spyware that certain Adult sites use when you select a "free trail". ;)

Don't ask how I know all this. :eek:

Here's what you want to do...

You will need to use a program called "Hijack This" - you can get it from this link. >>> http://www.merijn.org/files/HiJackThis_v2.exe

Run the program, and post ALL of what it comes up with on here and I will help you from there on. :)

:D Cool thanks Soap-Dodger! Browsing dodgy sites indeed lmao! :eek:

OK will do, off to the home of the GP tomorrow for a week but I will post in when I get back.

Cheers n beers... (y)
 
just done a quick google :)

http://uk.answers.yahoo.com/question/index?qid=20070424141422AAOyxy4

You have a Trojan that is installed without your permission:

Trojan.Ruins.B, Trojan.Win32.Agent.afi

MicroBillSys is a program used for processing payments for websites, typically sites with adult content. The program displays bills in the form of pop-ups that cover a large portion of the screen and demand payment.

Add. Description MicroBillSys has no uninstaller and does not appear in the Control Panel's Add/Remove applet. The files are installed in a system folder, typically System32 in Windows XP. The processes mbssm32.exe and mbsrm32.exe appear to guard each other and cannot be terminated by normal means. MicroBillSys modifies the Windows registry to ensure that its processes start each time Windows boots up. MicroBillSys has been installed by dubious means without user knowledge and consent in some cases. The website sexxxpassport.com uses MicroBillSys for payment, but the the behavior of the software is not fully disclosed and no EULA is displayed during installation. MicroBillSys processes frequently attempt to contact auth.MicroBillSys.com using port 1003.

Try using these programs when the procedure below instructs. Be sure they are updated prior to doing the procedure. You can use other programs like your Antivirus or Antispyware you have on your computer.

Download and Update Ewido (now called the AVG Antispyware). Do not run:

http://www.ewido.net/en/download/...


AVG Anti-Rootkit

http://www.grisoft.com/doc/download-free...



TEMPORARILY SHOW HIDDEN FILES AND FOLDERS.

1. Click Start, and then click Control Panel.

2. Click Appearance and Themes, and then click Folder Options.

3. On the View tab, under Hidden files and folders, click "Show hidden files and folders", and clear(uncheck) the "Hide protected operating system files" check box.

IMPORTANT: Files are hidden by Windows for a very good reason. It is not wise to experiment with these files. Unfortunately, to successfully remove modern spyware we must turn this protection off temporarily. Please turn the protection back on when you have finished cleaning your system.


EMPTY INTERNET EXPLORER BROWSER CACHE:

1. On the Internet Explorer Tools menu, click Internet Options.

2. On the General tab, in the Temporary Internet Files section, click the Delete Files button. Select the Delete all offline content check box in the confirmation dialogue box that appears, click OK. Click OK again.

RESTART IN SAFE MODE:

To do this you need to hold down or repeatedly tap the F8 key while the computer is booting (when the computer is displaying a black screen with white text). When the boot menu appears, use your keyboard arrows to select "Safe Mode."

Safe Mode can look quite ugly. The color may look bad, and all of your desktop icons will be very large. This is normal.



START THE SCAN WITH YOUR PROGRAM(S).



When the scan and removal are completed REBOOT COMPUTER. This will restart you in normal mode.

RESET HIDDEN FILES AND FOLDERS.

The RESTORE POINTS may be infected with the Malware and cannot be used. Delete the old one(s) and make a new one.

CLEAR OLD RESTORE POINT(S). HERE'S HOW:

1. Click Start, and then click Control Panel.

2. Click Performance and Maintenance, click System, and then click on the System Restore tab.

3. Select the Turn Off System Restore check box, click Apply, then restart your computer.

4. Return to the System Restore Tab and turn System Restore back on.


TO SET A NEW RESTORE POINT:

1. Click the Start button.

2. Point to Programs, then navigate to Accessories, then System Tools, then click System Restore.

3. Choose Create a restore point, and then click Next.

4. In the Restore point description box, type a name for your restore point, and then click Next.

5. Click OK.

NOTE: If you are using Windows XP Service Pack 2 (SP2) and are unable to access the Internet after removing Malware, there is a command that may fix the problem. It works by resetting the winsock catalogue. Click on Start, then Run and type CMD in the box. Click OK. Type "netsh winsock reset" (no quotes)into the DOS window that appears.
 
Jeez thanks for that Herps, even worse than I feared.

Wait till I find out which daughter or which daughters boyfriend did that!!
 
:) Good news! Microbillsys is gone thanks guys!

:( Bad news, cant access t'internet now, tried inputting the DOS command for Winsock... can use MSN though....

I even tried downloading and starting IE 7 but when I click to open the screen goes black and then comes back on at my Start page...

Wierd, I guess something I need to get internet access got infected and deleted?

I got XP Home Ed, can I remove and re-load Windows does anyone know? Or do I bin the PC and buy a Ploptop?

Doh....
 
Reinstall Windows if you have a Windows CD or BootDisc.

Thanks Trancendental. :) Thats the next move, so far I have got everything now working again, except oddly, Mozilla/Google... :mad: when I download that, all ok, when I try to use it the screen blanks and goes back to the Windows screen. :bang: Anyway, I can get access to t'internet via IE 7.0 now so urgency gone. Maybe I will wait a few months then upgrade the chuggy desktop to a ploptop and convert the PC room back to a bedroom and use wireless to access the modem.

Thanks for your help guys... Good Stuff as usual! (y)
 
Back
Top