money stolen from p...
 

MegaSack DRAW - This year's winner is user - rgwb
We will be in touch

[Closed] money stolen from paypal again......

21 Posts
10 Users
0 Reactions
70 Views
Posts: 0
Free Member
Topic starter
 

in the summer i had my skype account hacked and they bought £80 worth of credit (most of which i got back). I changed the passwords on everything i could possibly think of and though that would solve the problem

I've now had an account created with aeriagames.com and $50 worth of vouchers bought through paypal on my credit card. I have cancelled my credit card and once again changed my paypal and email password.

I have AVG internet security on my PC and have never used the accounts hacked on any other PC, just scanned machine and found a trojan which it has deleted but i'm not 100% sure that this is what was presumably providing keylogs for someone, i've had no firewall warnings or malware indications from AVG.

I used a 'ahem' borrowed version of symantec corporate for years and have never had a problem. is AVG all it's cracked up to be, i'm a bit pissed off that i've actually paid for an antivirus and it's clearly failed.

Is there anything else i should do

I have the address and phone number of aeriagames.com so nukes are standing by in space, i'm not sure i can wee as far as california but there shoes had better watch out.


 
Posted : 11/10/2010 2:28 pm
Posts: 0
Free Member
 

TBH - after 2 incidents like that, I'd be formatting the drive & starting again


 
Posted : 11/10/2010 2:31 pm
Posts: 0
Free Member
Topic starter
 

thing is it's a new laptop, i'm pretty sure i'd never been online with this machine when my skype was hacked.

looking at it, the email account that they have used to create the account was the only thing that still shared a password with skype, paypal however used a new password


 
Posted : 11/10/2010 2:35 pm
Posts: 0
Free Member
 

what kind of sites are you visiting? do you often click things that say "scan my PC for free online now"?


 
Posted : 11/10/2010 2:37 pm
Posts: 0
Free Member
Topic starter
 

never, i'm not that foolish


 
Posted : 11/10/2010 2:45 pm
Posts: 0
Free Member
 

you dont have to be that foolish, loads of us got a trojan off here last week.


 
Posted : 11/10/2010 2:53 pm
Posts: 0
Free Member
Topic starter
 

AVG picked that one up, assuming you mean that link that was dodgy


 
Posted : 11/10/2010 3:23 pm
Posts: 77699
Free Member
 

Malwarebytes for a start off.

AVG used to be the best, but it's got progressively worse from version 8 onwards. I run MSE these days and haven't looked back.


 
Posted : 11/10/2010 4:02 pm
Posts: 34076
Full Member
 

download malwarebytes
and superantispywear
(free) update and scan with both
bet they find loads of stuff the mse and avg will miss

worrying thing is they will both find different things

seems 3 sets of antispywear isnt enough these days?!


 
Posted : 11/10/2010 4:09 pm
Posts: 0
Free Member
 

I had that happen to me 3 times and one time they took about £500 out and made me go overdrawn. Was some American firm taking the money out but paypal refunded it. No idea what happend but even after changing password it happened again and no virus or spyware found. I changed password to more complicated one and its been ok so far.


 
Posted : 11/10/2010 4:32 pm
 j_me
Posts: 0
Free Member
 

Are you choosing sensibly strong passwords?

Nothing that's in a dictionary, mix case, numbers and digits with a few characters in for good measure.


 
Posted : 11/10/2010 4:43 pm
Posts: 0
Free Member
Topic starter
 

currently scanning with the above, the trojans that AVG found were on the contents i ripped off an external drive onto the new machine so could have been on old machine too.

left message with aeria games

nukes still on standby

passwords are a brand name and a series of numbers, come up as strong security on the indications you tend to get nowadays


 
Posted : 11/10/2010 5:11 pm
Posts: 0
Free Member
Topic starter
 

looking at firewall log, it's blocking a lot of outgoing requests from an SVCHOST process to ip 239.255.255.0

is this normal? there's a log of a block ever few seconds at least


 
Posted : 11/10/2010 5:21 pm
Posts: 77699
Free Member
 

That address is a multicast address, not a 'regular' public IP. I don't [i]think [/i]this is likely to be nefarious - possibly something like uPnP being shouty. I reckon you can ignore it.


 
Posted : 11/10/2010 5:41 pm
Posts: 77699
Free Member
 

A bit of Googling would suggest this is SSDP. The only thing I can think of that uses SSDP in anger is the gateway discovery part of Windows Messenger. You can savely uninstall this (under "Windows Components" in Add/Remove Programs) - it's wholly unrelated to MSN / Live Messenger. Give it a go, see if your logs quieten down.


 
Posted : 11/10/2010 5:44 pm
Posts: 77699
Free Member
 

Ah, could also be media sharing - do you use something like TVersity / TwonkyMedia perhaps?


 
Posted : 11/10/2010 5:47 pm
Posts: 0
Free Member
Topic starter
 

no media sharing, not knowingly anyway although no doubt windows 7 defaults to some kind of sharing


 
Posted : 11/10/2010 8:21 pm
Posts: 0
Free Member
Topic starter
 

malwarebytes picked up nowt


 
Posted : 11/10/2010 8:22 pm
Posts: 0
Free Member
 

mrmichaelwright - Member

I used a 'ahem' borrowed version of symantec corporate for years and have never had a problem.

Karma


 
Posted : 11/10/2010 8:24 pm
Posts: 0
Free Member
Topic starter
 

ha, i've even paid for office this time, that's karma enough

anyway, Web 2.0 and all that, the big corporates will subsidise the open source developers providing software without support for lower users.

it's the future


 
Posted : 11/10/2010 8:40 pm
 Drac
Posts: 50459
 

I'd say it's your password brand name and a few digits isn't exactly strong. You need to avoid common words and names.


 
Posted : 11/10/2010 8:47 pm
Posts: 0
Free Member
Topic starter
 

it's not a common brand name, unless you are a mountain biker 😕

changed now by the way 😉


 
Posted : 11/10/2010 8:50 pm