MBS / Platte Media Victims' Forum
February 07, 2012, 12:14:29 pm *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: ***** NORWAY TAKES ACTION AGAINST PLATTE ***** *** See latest post on the Forum
 
   Home   Help Search Calendar Login Register  
Pages: 1 [2] 3   Go Down
  Print  
Author Topic: infection research  (Read 7401 times)
helpplz
Guest
« Reply #15 on: October 03, 2007, 09:27:08 pm »

so the mbs program is acting just like a trojen then ?
If so , wouldnt this be good evidence for trading standards ?
Logged
ForumFriend
Ms Admin
Administrator
Platinum Member
*****

Karma: 22
Offline Offline

Posts: 350


« Reply #16 on: October 03, 2007, 09:34:55 pm »

Thanks for that, Jon.
Logged

"Dedicated to creating a safer internet"
helpplz
Guest
« Reply #17 on: October 03, 2007, 09:41:40 pm »

You asked about if it can run on other os. There has been a few window vista cases out there but mbs has to send out a cd to you to get mbs off a vista pc. And am sure you can't get mbs on mac's.
Logged
jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #18 on: October 03, 2007, 10:01:42 pm »

so the mbs program is acting just like a trojen then ?
If so , wouldnt this be good evidence for trading standards ?

hmmm tbh buddy its hard to say as you do have to agree to installing it, feel free to use anything in this thread as evidence or watever to any authority if you please i truly dont mind,all i ask is that if you need to contact me, you use the envolope symbol on the side to email me and tell me lol

Thanks for that, Jon.

no probs buddy, hope to have some more info by the morning, been busy this evening preparing for my trip lol

You asked about if it can run on other os. There has been a few window vista cases out there but mbs has to send out a cd to you to get mbs off a vista pc. And am sure you can't get mbs on mac's.

il look into this, cant see how different it would be on vista, what i am thinking though is that on synematic website, it states there are several different versions of the installed being used, best guess is that the site runs a script to see which o/s you are using (pre-made scripts that do this are easily found on the net.)

i think the next step i will be taking is to create a new VM (virtual machine) to cross check the logs and hashes

after that ill be trying to manually delete the files jsut to see the effect, wether the files come back by themselves

i also intend to run a week long test. Basicly ill use a fresh VM and start the folder monitor, ill be leaving this running for an entire week so i can see if any ither files are created/modified/deleted, this should solve the question on wether this "software" does act like trojan, sadly though this experiment will have to wait untill i come home from my trip as i dont think im going to be able to keep my laptop on all day for a week as i dnt think ill be near a power source to often lol

thanks for your interest and questions, make mre feel like im doing something worthwhile lol
Logged


ForumFriend
Ms Admin
Administrator
Platinum Member
*****

Karma: 22
Offline Offline

Posts: 350


« Reply #19 on: October 03, 2007, 10:35:46 pm »

Yes, you are! Grin
Logged

"Dedicated to creating a safer internet"
jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #20 on: October 03, 2007, 10:45:53 pm »

thanks lol

anyway, right i did another quick little test, cancelling my "membership"
even doing so left all the files created on my system, which makes me wonder if in fact even by canceling a membership will get rid of the pop upp bill, we shall see,also i noticed that even after cancelling membership, i can still access the "members" section of there crappy website
Logged


helpplz
Guest
« Reply #21 on: October 04, 2007, 07:17:45 pm »

i saw on the desktop the mbs icon but also the sexpassport icon now people who haven't been on any of the porn sites do they get the porn site icon ?
Logged
jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #22 on: October 04, 2007, 09:17:39 pm »

well that icon appeared after MBS installed, so no matter how MBS was installed the icon would appear.
Logged


zeebu
Bronze Member
**

Karma: 1
Offline Offline

Posts: 8


« Reply #23 on: October 04, 2007, 09:46:59 pm »

My pc became infected after a spate of those serial popup adverts for sex sites, close one and another pops up. I checked for the presence of some of the teltale files mentioned in forums but nothing, I wonder if there are several flavors of the billing malware doing the same thing but using different sets of filenames?
Call me cynical but I saw no 3 day offer and no conditions I wonder if there are popup close buttons out there that trigger software tranfer. It cant be long before there are phoney Tesco pages originating in Nigeria with ransom buttons.   
Zeebu
Logged
jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #24 on: October 05, 2007, 05:23:40 am »

well it is know that there are several different names for the installer, here is a list of what the installer could also be called, i dont know how they work it though, wether its a different installer for a different site or a different installer per operating system, i just aint sure yet


    * MBSAuthenticate.exe
    * MBSAuthenticate_19.exe
    * MBSAuthenticate_39.exe
    * setup1_1003.exe
    * setup1_1004.exe
    * setup1_1005.exe

*soure was the symantec website
Logged


jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #25 on: October 05, 2007, 01:42:57 pm »

sorry for the lack of updates on this the past few days, been REALLY busy, but hope to get some more work on this done in the van on the way down to dover ferry terminal tonight lol, i doubt ill be able to get access so ill keep a log on my laptop of what i do and what happens etc, im expecting the pop up to be on today so we'll see tonight lol
Logged


ForumFriend
Ms Admin
Administrator
Platinum Member
*****

Karma: 22
Offline Offline

Posts: 350


« Reply #26 on: October 05, 2007, 01:54:12 pm »

Thanks Jon, and bon voyage!
Logged

"Dedicated to creating a safer internet"
jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #27 on: October 05, 2007, 02:16:04 pm »

im still geting calls about this in work you know, i send em all here lol
Logged


jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #28 on: October 15, 2007, 07:41:20 am »

back again lol, im acually on ferry on my way home, anyway, thought it may be a good time to do some more work on this,

i read elsewhere here that somebody had paid the bill but his browser was still calling home to mbs, well, there are .php files dropped into the teemp internet files folder, ill try and locate them now but i think a complete delete of the temp internet files may solve this.

as im on a 20 hour ferry trip i imagine ill be able to do quite a bit of work on this lol,

Logged


jonlewi5
Administrator
Gold Member
*****

Karma: 9
Offline Offline

Posts: 176


« Reply #29 on: November 01, 2007, 08:57:41 am »

ok, been a while but i have been doing some work on this, it seems after creating a fresh virtual machine and going through the installation of this shit, i get the exact same files crreated, so all i need to do now is make another VM then install then while my folder watcher is running, remove my membership so it uninstalls, that way i can see whats being removed in the uninstall and create a program to remove them, also i do have the bill on one of my VM's so ill get a screeny of that,

note that iv had mbs installed for over a month now so my bill is WAYY over due

also an email has just gone thru work (i work in isp tech spport) telling us if a customer calls about MBS, to send them here lool
« Last Edit: November 01, 2007, 11:43:33 am by jonlewi5 » Logged


Pages: 1 [2] 3   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.8 | SMF © 2006-2008, Simple Machines LLC Sponsored by PMK admission-psychoanalysts Valid XHTML 1.0! Valid CSS!