Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Mbs Billing


  • Please log in to reply
5 replies to this topic

#1 wiseman

wiseman

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:39 PM

Posted 25 July 2007 - 04:00 AM

Hello every one, this is my first time please advise if I have done it wrong. Thanks. My problem is MBS billing anyone know how to get rid of it. I am being billed for a SEX SITE that I did not register with, and the bill appears on the desktop every time I load the internet. Thanks in anticipation :thumbsup: :flowers: :trumpet:

BC AdBot (Login to Remove)

 


#2 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:02:39 PM

Posted 25 July 2007 - 01:58 PM

Please download Merijn's Brute Force Uninstaller

Once you have done that extract(unzip) the program to a separate folder, such as C:\BFU.

run notepad, Copy all the text in the code box and paste into notepad.

click file, save as, for file type select all files, name the file mbs.bfu

make sure the file is in the same folder as the Brute Force Uninstaller.

Double click to run bfu, then navigate and select mbs.

then click execute.
# For use with Merijn's Brute Force Uninstaller
# available from http://www.merijn.org/
#
# Script Name: MBS.BFU
# Author: Pieter Arntz aka Metallica
# Original idea: John McKenna

OptionUseRecycleBin

OptionStatusOn
OptionSetStatus Stopping processes

ProcessKill %SYSDIR%\mbssm32.exe|1
ProcessKill %SYSDIR%\mbsrm32.exe|1
ProcessKill %SYSDIR%\mbsmon32.exe|1 
ProcessKill %SYSDIR%\mbsreg.exe|1
ProcessKill %SYSDIR%\mbsreg32.exe|1
ProcessKill %SYSDIR%\rmvalid.exe|1
ProcessKill %SYSDIR%\smvalid.exe|1
ProcessKill %SYSDIR%\winregmon32.exe|1
ProcessKill %SYSDIR%\winsysmon32.exe|1
 
OptionSetStatus Cleaning registry
RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|mbssm32
RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|mbsmon32
RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winsys32mon

RegDeleteKey HKCR\UBSauthenticateAXC.UBSauthenticate
RegDeleteKey HKCR\UBSInstallerProj1.UBSInstaller

RegDeleteKey HKCR\CLSID\{03BEED0D-08D3-4F8A-B1FC-1125FD9CA2CA}
RegDeleteKey HKCR\CLSID\{0AC31BDF-3BEF-40FD-B465-706C97AF54CC}
RegDeleteKey HKCR\CLSID\{32C57299-0969-44EB-9430-B9581A2EBC78}
RegDeleteKey HKCR\CLSID\{D2FAC024-92C0-42E5-A75B-7B4E3915CC50}
RegDeleteKey HKCR\Interface\{03A1C2D7-7C55-4249-AE94-6A1D0BF30916}
RegDeleteKey HKCR\Interface\{128C578A-5E8D-4C8E-900B-235E490D3FA9}
RegDeleteKey HKCR\Interface\{48C41D21-723A-4B41-A869-6C84326E219C}
RegDeleteKey HKCR\Interface\{B3F57865-9034-483D-92D3-6DA16E0670E6}
RegDeleteKey HKCR\TypeLib\{66DC2223-B839-4E7B-A11D-62D7770FABCE}
RegDeleteKey HKCR\TypeLib\{C554BC41-3CBC-4074-AC8B-B2C0E4C04C06}
RegDeleteKey HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0AC31BDF-3BEF-40FD-B465-706C97AF54CC}
RegSetDwordValue HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0AC31BDF-3BEF-40FD-B465-706C97AF54CC}|Compatibility Flags|1024


OptionSetStatus Deleting files

FileDelete %SYSDIR%\mbssm32.exe
FileDelete %SYSDIR%\mbsrm32.exe
FileDelete %SYSDIR%\mbsmon32.exe
FileDelete %SYSDIR%\mbsreg.exe
FileDelete %SYSDIR%\mbsreg32.exe
FileDelete %SYSDIR%\rmvalid.exe
FileDelete %SYSDIR%\smvalid.exe
FileDelete %SYSDIR%\winregmon32.exe
FileDelete %SYSDIR%\winsysmon32.exe
FileDelete %SYSDIR%\u2g.f
FileDelete %SYSDIR%\UBSauthenticateAXC.ocx
FileDelete %SYSDIR%\UBSauthenticateAXC1.ocx
FileDelete %SYSDIR%\winiconmon.ico
FileDelete %SYSDIR%\winiconmon.ico.bak0
FileDelete %SYSDIR%\winiconmon.ico.bak1
FileDelete %SYSDIR%\winiconmon.ico.bak2
FileDelete %SYSDIR%\icon_mb014.ico
FileDelete %SYSDIR%\icon_mb014.ico.bak0
FileDelete %SYSDIR%\Sexxxpassport*.ico
FileDelete %SYSDIR%\Sexxxpassport.ico
FileDelete %SYSDIR%\axaccessctr.ocx

FileDelete %DESKTOP%\Sexxxpassport.lnk
FileDelete %DESKTOP%\SexxxPassport Members.lnk


SystemEmptyInternetCache
SystemEmptyTempFolder

Edited by oldf@rt, 25 July 2007 - 03:04 PM.

The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage

#3 TMacK

TMacK

  • Members
  • 4,672 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:B.C. Canada
  • Local time:02:39 PM

Posted 25 July 2007 - 02:24 PM

Welcome to Bleeping Computer wiseman,

It may be a good idea to contact your local Law Enforcement Agencies and provide them with any documentation you have.
Also let your financial institutions be aware of this.
Chaos reigns within.
Reflect, repent, and reboot.
Order shall return.

aaaaaaaa a~Suzie Wagner

#4 wiseman

wiseman
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:39 PM

Posted 25 July 2007 - 03:01 PM

thank you oldf@rt, I am a novice on computers, so not quite sure what to do with your solution, but will have a go

#5 wiseman

wiseman
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:39 PM

Posted 25 July 2007 - 03:03 PM

Welcome to Bleeping Computer wiseman,

It may be a good idea to contact your local Law Enforcement Agencies and provide them with any documentation you have.
Also let your financial institutions be aware of this.


thanks for your reply thought of calling in the police

#6 oldf@rt

oldf@rt

  • Members
  • 2,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Avondale, Arizona USA
  • Local time:02:39 PM

Posted 25 July 2007 - 03:05 PM

forgot to add :thumbsup: to bleeping computer, and let us know the results.
The name says it all -- 59 and holding permanently

**WARNING** Links I provide might cause brain damage




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users