|
|
#1 (permalink) |
|
New Member
![]() Join Date: Jan 2007
Posts: 6
|
Alright heres whats going on.
Alright, so a few years ago i had a paypal account, i used it for 2 years with my ebay account. I stopped using it, i canceld it, and now i tired opening a new one. So i go to open a new account, everything is going fine, then i had to "confirm" my account threw my email. In the email i got, it said to click on the link, and sign in......wait a minute? i thought paypal and ebay never ask you to click a link and sign in? This was a email account i opened 5 mins ago, so its not spam. I noticed the link is to a site thats www.paypal.com/row.... etc... I was like shit!..im getting screwed here. so i open a new browser, type in www.paypal.com and press enter. I make a compleatly new paypal account and hotmail account. Right when i press confirm on my paypal registration, "row" pops up in the URL ![]() i didnt know what to do from there... in that browser i went to their help section and clicked on "paypal spam emails" ... and i got this. I knew something was up when i saw what it said. ![]() I got a friend to go to www.paypal.com on their comptuer and go to the same help section. and this is what he sees on the REAL paypal website. ![]() If i go www.paypal.com or www.paypal.com/row...its the same thing. i even tried something other then row and it still works? (i dont know if thats normal or not) ![]() I followed Golks advice and getting some spyware software like Spybot and Ad-aware (found alot, go rid of it, some came back...uninstalled limewire and deleted some torent download programs...did the spyware check again, and non returned. I ran the spyware software in SAFEMODE) thanks golks, got rid of some stuff i never even knew was there, but not my problem. Can someone help me out and tell me whats going on here? |
|
|
|
|
|
#2 (permalink) |
|
Diamond Member
![]() Join Date: Nov 2005
Location: Nor Cal
Age: 19
Posts: 7,864
|
It definitly is a fake. I would get a live cd of linux and create a paypal account with that.
Wait for buzz to come around and help you clean up your computer.
__________________
http://www.cherokeetalk.com Sometimes life just seems to shatter Like we're made of glass If I could, I'd hold this moment If I could, I'd make it last |
|
|
|
|
|
#3 (permalink) |
|
Diamond Member
![]() Join Date: Aug 2004
Location: Oahu
Age: 28
Posts: 6,273
|
just right click the side and check out their verisign thingy.
__________________
QX9650@4.2 swiftech |9600@3.0 9700 nt 780i | 790fx 8gb ddr1200 | 8gb ddr1200 2x150gb 3x1tb |2x250gb 3x8800gtx |3x2900xt 1gb 2x20xdvdrw |2x20xdvdrw 15in1 card reader |15in1 card reader ng15/g9 |ng15/g9 1200w psu |1200w psu 2x28" LCD |2x28" LCD |
|
|
|
|
|
#4 (permalink) |
|
Digaredd
![]() Join Date: May 2005
Location: Melbourne AU
Posts: 7,582
|
It's a phishing scam (and a very good one). There's an article here.
http://www.antiphishing.org/phishing...05_Paypal.html My first guess would be that something has altered your hosts file. Post a Hijackthis log. Hijackthis Logs
__________________
Son of Glyndwr Mae hen wlad fy nhadau yn annwyl i mi |
|
|
|
|
|
#5 (permalink) |
|
New Member
![]() Join Date: Jan 2007
Posts: 6
|
Logfile of HijackThis v1.99.1
Scan saved at 3:32:45 PM, on 1/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\ScanSoft\OmniPageSE\opware32.exe C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe C:\Program Files\palmOne\Hotsync.exe C:\Program Files\OpenOffice.org 2.0\program\soffice.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN C:\WINDOWS\system32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\roman\Local Settings\Temporary Internet Files\Content.IE5\C5YRK5U7\hijackthis_sfx[1].exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.co...s/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1154546653790 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1154547558359 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: winkve32 - winkve32.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe |
|
|
|
|
|
#6 (permalink) |
|
New Member
![]() Join Date: Jan 2007
Posts: 6
|
i am taking a complete GUESS as this... but here it goes haha:
012 could this be something? 018 i couldnt just take 1 guess... so im adding in these also 018 020 020 (files missing) ?? im guessing thats no my problem, but would that be a concern? was i at least close??
|
|
|
|
|
|
#7 (permalink) |
|
New Member
![]() Join Date: Jan 2007
Posts: 6
|
oh, and i dont know if this has anything to do with it, but i highly doubt it, but you never know. This is the other problem i am having right now.
Computer keeps shutting down, serious ERROR |
|
|
|
|
|
#8 (permalink) |
|
New Member
![]() Join Date: Jan 2007
Posts: 6
|
Alright. This isnt right at all. I tried signed up for new accounts on paypal at 2 friends house's. BOTH friends URL changes to www.paypal.com/row..... when i confirm my information.
At friend number 1 house: I sign up, and it changes to row, and it stays on the row website. Have a 6 month old computer with payed anti-virus and anti-spyware software on his computer (all up to date reguarly). At friend number 2 house: I sign up, it changes to row when i press confirm, then if i go anywhere else on the website, row isnt in the URL anymore. 3 year old computer, with no anti virus or spyware software for the last year. Whats going on? |
|
|
|
|
|
#9 (permalink) |
|
Diamond Member
![]() Join Date: Aug 2004
Location: Oahu
Age: 28
Posts: 6,273
|
just to be sure, format a computer and just go there and see if it is still row
__________________
QX9650@4.2 swiftech |9600@3.0 9700 nt 780i | 790fx 8gb ddr1200 | 8gb ddr1200 2x150gb 3x1tb |2x250gb 3x8800gtx |3x2900xt 1gb 2x20xdvdrw |2x20xdvdrw 15in1 card reader |15in1 card reader ng15/g9 |ng15/g9 1200w psu |1200w psu 2x28" LCD |2x28" LCD |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|