ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 01-08-2007, 05:36 AM   #1 (permalink)
New Member
 
Join Date: Jan 2007
Posts: 6
Default Paypal scam? whats going on. NEED HELP

Alright heres whats going on.

Alright, so a few years ago i had a paypal account, i used it for 2 years with my ebay account. I stopped using it, i canceld it, and now i tired opening a new one. So i go to open a new account, everything is going fine, then i had to "confirm" my account threw my email. In the email i got, it said to click on the link, and sign in......wait a minute? i thought paypal and ebay never ask you to click a link and sign in? This was a email account i opened 5 mins ago, so its not spam. I noticed the link is to a site thats www.paypal.com/row.... etc... I was like shit!..im getting screwed here.

so i open a new browser, type in www.paypal.com and press enter. I make a compleatly new paypal account and hotmail account. Right when i press confirm on my paypal registration, "row" pops up in the URL





i didnt know what to do from there... in that browser i went to their help section and clicked on "paypal spam emails" ... and i got this. I knew something was up when i saw what it said.





I got a friend to go to www.paypal.com on their comptuer and go to the same help section. and this is what he sees on the REAL paypal website.





If i go www.paypal.com or www.paypal.com/row...its the same thing. i even tried something other then row and it still works? (i dont know if thats normal or not)





I followed Golks advice and getting some spyware software like Spybot and Ad-aware (found alot, go rid of it, some came back...uninstalled limewire and deleted some torent download programs...did the spyware check again, and non returned. I ran the spyware software in SAFEMODE) thanks golks, got rid of some stuff i never even knew was there, but not my problem.

Can someone help me out and tell me whats going on here?
raboyto2 is offline   Reply With Quote


Old 01-08-2007, 05:39 AM   #2 (permalink)
Diamond Member
 
Motoxrdude's Avatar
 
Join Date: Nov 2005
Location: Nor Cal
Age: 19
Posts: 7,864
Default

It definitly is a fake. I would get a live cd of linux and create a paypal account with that.
Wait for buzz to come around and help you clean up your computer.
__________________
http://www.cherokeetalk.com
Sometimes life just seems to shatter
Like we're made of glass
If I could, I'd hold this moment
If I could, I'd make it last
Motoxrdude is offline   Reply With Quote
Old 01-08-2007, 05:55 AM   #3 (permalink)
Diamond Member
 
kof2000's Avatar
 
Join Date: Aug 2004
Location: Oahu
Age: 28
Posts: 6,273
Default

just right click the side and check out their verisign thingy.
__________________
QX9650@4.2 swiftech |9600@3.0 9700 nt
780i | 790fx
8gb ddr1200 | 8gb ddr1200
2x150gb 3x1tb |2x250gb
3x8800gtx |3x2900xt 1gb
2x20xdvdrw |2x20xdvdrw
15in1 card reader |15in1 card reader
ng15/g9 |ng15/g9
1200w psu |1200w psu
2x28" LCD |2x28" LCD
kof2000 is offline   Reply With Quote
Old 01-08-2007, 05:56 AM   #4 (permalink)
Digaredd
 
Buzz1927's Avatar
 
Join Date: May 2005
Location: Melbourne AU
Posts: 7,582
Default

It's a phishing scam (and a very good one). There's an article here.
http://www.antiphishing.org/phishing...05_Paypal.html

My first guess would be that something has altered your hosts file. Post a Hijackthis log.
Hijackthis Logs
__________________
Son of Glyndwr
Mae hen wlad fy nhadau yn annwyl i mi
Buzz1927 is offline   Reply With Quote
Old 01-08-2007, 10:34 PM   #5 (permalink)
New Member
 
Join Date: Jan 2007
Posts: 6
Default

Logfile of HijackThis v1.99.1
Scan saved at 3:32:45 PM, on 1/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\roman\Local Settings\Temporary Internet Files\Content.IE5\C5YRK5U7\hijackthis_sfx[1].exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1154546653790
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1154547558359
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winkve32 - winkve32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
raboyto2 is offline   Reply With Quote


Old 01-08-2007, 10:39 PM   #6 (permalink)
New Member
 
Join Date: Jan 2007
Posts: 6
Default

i am taking a complete GUESS as this... but here it goes haha:

012 could this be something?

018 i couldnt just take 1 guess... so im adding in these also
018
020
020 (files missing) ?? im guessing thats no my problem, but would that be a concern?

was i at least close??
raboyto2 is offline   Reply With Quote
Old 01-08-2007, 11:09 PM   #7 (permalink)
New Member
 
Join Date: Jan 2007
Posts: 6
Default

oh, and i dont know if this has anything to do with it, but i highly doubt it, but you never know. This is the other problem i am having right now.

Computer keeps shutting down, serious ERROR
raboyto2 is offline   Reply With Quote
Old 01-09-2007, 01:18 AM   #8 (permalink)
New Member
 
Join Date: Jan 2007
Posts: 6
Default

Alright. This isnt right at all. I tried signed up for new accounts on paypal at 2 friends house's. BOTH friends URL changes to www.paypal.com/row..... when i confirm my information.

At friend number 1 house: I sign up, and it changes to row, and it stays on the row website. Have a 6 month old computer with payed anti-virus and anti-spyware software on his computer (all up to date reguarly).

At friend number 2 house: I sign up, it changes to row when i press confirm, then if i go anywhere else on the website, row isnt in the URL anymore. 3 year old computer, with no anti virus or spyware software for the last year.

Whats going on?
raboyto2 is offline   Reply With Quote
Old 01-09-2007, 01:21 AM   #9 (permalink)
Diamond Member
 
kof2000's Avatar
 
Join Date: Aug 2004
Location: Oahu
Age: 28
Posts: 6,273
Default

just to be sure, format a computer and just go there and see if it is still row
__________________
QX9650@4.2 swiftech |9600@3.0 9700 nt
780i | 790fx
8gb ddr1200 | 8gb ddr1200
2x150gb 3x1tb |2x250gb
3x8800gtx |3x2900xt 1gb
2x20xdvdrw |2x20xdvdrw
15in1 card reader |15in1 card reader
ng15/g9 |ng15/g9
1200w psu |1200w psu
2x28" LCD |2x28" LCD
kof2000 is offline   Reply With Quote
Old 01-09-2007, 06:18 PM   #10 (permalink)
Gold Member
 
Jonyboy's Avatar
 
Join Date: Dec 2006
Posts: 313
Default

Its strange that they managed to get it on paypals domain, hats off, that is clever. (unless someone can explain how they did it.)
Jonyboy is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:26 AM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.