ok, i have just infected my virtual machine and have got a log of what was changed and created, iv also taken screenshots along the way, here are my results so far
SCREENIES
sexxxpassport terms and condition (may include some xxx pics)
http://img254.imageshack.us/img254/6775/passporttandcgm1.jpgAfter clicking that i agreed, i got this
http://img401.imageshack.us/img401/2031/mbsinstallqy7.jpgas im using firefox, the downloaded files appear on my dekstop, it seems this isnt "auto-running" ie it has to be clicked to start.
http://img524.imageshack.us/img524/8766/desktopmd5.jpgon my xp machine, im next asked if i do want to install the program
http://img401.imageshack.us/img401/9550/askbeforeinstalleq2.jpgand finally, my desktop AFTER the install
http://img373.imageshack.us/img373/8860/screenafterinstallvh1.jpgMY LOG
this log was created using my folder watcher tool, i set the program to watch my ENTIRE root directory (c:\) so some of the first few entries have nothing to do with MBS
File C:\WINDOWS\system32\mshtmler.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\plugin.ocx has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mydocs.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mydocs.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\explorer.exe has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\explorer.exe has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Media\Windows XP Error.wav has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Tasks has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\SECURITY.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\cryptnet.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\vgaoem.fon has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\dosapp.fon has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\ega40woa.fon has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\cga80woa.fon has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\cga40woa.fon has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\olepro32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\Sexxxpassport.ico has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\Sexxxpassport.ico has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\181ECE0B.inf has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\181ECE0B.inf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\UBSauthenticateAXC.ocx has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\UBSauthenticateAXC.ocx has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\sserife.fon has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\winiconmon.ico has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\winiconmon.ico has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mbssm32.exe has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mbssm32.exe has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mbsrm32.exe has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mbsrm32.exe has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File system32\winiconmon.ico has been renamed to C:\WINDOWS\system32\winiconmon.ico.bak0 by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\winiconmon.ico.bak0 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\winiconmon.ico has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\winiconmon.ico has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\INS6.TMP-0E074B7C.pf has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\INS6.TMP-0E074B7C.pf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\psapi.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\Sexxxpassport.ico has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\Sexxxpassport.ico has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\MBSAUTHENTICATE_39.EXE-11197F82.pf has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\MBSAUTHENTICATE_39.EXE-11197F82.pf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\shell32.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\url.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\url.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mshtml.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mshtml.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mshtml.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\mshtml.dll has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udc has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udc has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udc has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udc has been deleted by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udcIISGCDKHBCYWJQTLCSMDS.udc has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udcIISGCDKHBCYWJQTLCSMDS.udc has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udcIISGCDKHBCYWJQTLCSMDS.udc has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\VIQYJRUKNGNWDJUDXPMTV.udcIISGCDKHBCYWJQTLCSMDS.udc has been deleted by jon from JON-2FAD10340D6
File C:\WINDOWS\system32 has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\inetcpl.cpl has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Fonts\verdanai.ttf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\config\software.LOG has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\MBSSM32.EXE-0CF4F0DB.pf has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\MBSSM32.EXE-0CF4F0DB.pf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\MBSRM32.EXE-1B1BD55F.pf has been created by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\MBSRM32.EXE-1B1BD55F.pf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf has been changed by jon from JON-2FAD10340D6
File C:\WINDOWS\system32\netcfgx.dll has been changed by jon from JON-2FAD10340D6