Poker Chip Forums-ChipTalk.net
European Poker Tour: 100% Plastic Playing Cards Tough to Beat!
European Poker Tour: 100% Plastic Playing Cards Tough to Beat!
Home Classifieds Site Tools User Tools Quick Links Help
Go Back   Poker Chip Forums-ChipTalk.net > General Poker > Online Poker
User Name
Password Register

» Navigation Menu
» Latest Auction Listings
Title, Username, & Date
25% Cashback for Buy-it-Nows on eBay, using live.com and PayPal
11-17-2008 08:03 PM
Mark Twain Casino Paulsons on Ebay
11-15-2008 02:47 PM
Crystal Card Club-- Billings, MT
11-19-2008 12:40 AM
Very valuable HHR Tonopah Club chips
11-18-2008 12:09 AM
Paulson Legends of the West
11-18-2008 07:55 PM
65 Grey NCV Paulson Private Cardroom Poker Chips
11-18-2008 02:23 PM
custom asm's on ebay 47 chips
11-16-2008 03:18 PM
"Jockey&qu...
11-18-2008 04:59 PM
legends...
11-18-2008 03:57 PM
Let It Ride table
11-17-2008 11:43 PM
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #61 (permalink)     Top 
Old 01-04-2007, 07:25 PM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller account compromised - already lost over $1100

Thanks sog. Yes, my laptop is a Gateway so that explains the one service that you identified.

Here's the much longer log file from my Sony Vaio desktop. Your help is much appreciated. I really do feel vulnerable. I understand now what folks mean when they say that after and identity theft of some sort.

-jamby

Logfile of HijackThis v1.99.1
Scan saved at 6:21:00 PM, on 1/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Valued Customer\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\adobe\acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - d:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Merriam-Webster - {9E1128F1-53FA-11d5-8490-0048548030CA} - C:\WINDOWS\Downloaded Program Files\m-wtoolbar.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Merriam-Webster - {9E1128F1-53FA-11D5-8490-0048548030CA} - C:\WINDOWS\Downloaded Program Files\m-wtoolbar.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - D:\Program Files\Webshots\Webshots\WSToolbar4IE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Webshots.lnk = D:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Webshots.lnk = D:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Webshots Photo Search - res://D:\Program Files\Webshots\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Collegiate &Dictionary - C:\Program files\Merriam-Webster Toolbar\dictionary.htm
O8 - Extra context menu item: Collegiate &Thesaurus - C:\Program files\Merriam-Webster Toolbar\thesaurus.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://d:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://d:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?f0efc08533514ae8b8d39553da377e19
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?f0efc08533514ae8b8d39553da377e19
O8 - Extra context menu item: Post Image to Blog - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - d:\program files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - d:\program files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\program files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\program files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Merriam-Webster - {BAC53F31-6090-11d5-8497-0048548030CA} - C:\WINDOWS\Downloaded Program Files\m-wtoolbar.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - d:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - d:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - http://harpo-notes1.harpo.com/iNotes.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://access.harpo.com/CitrixSessi...a32/wficat.cab
O16 - DPF: {275E2FE0-7486-11D0-89D6-00A0C90C9B67} (MCSiMenuCtl Class) - http://www.acehardware-aceonline.com...i/McsiMenu.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://harpo-notes1.harpo.com/iNotes6W.cab
O16 - DPF: {3F1A2503-C1E0-4980-93DA-C64E44507EC1} (MSN Money QuickList) - http://fdl.msn.com/public/investor/v12/investor.cab
O16 - DPF: {405BBF5B-2FD8-4614-AC51-D8566F635B94} (SafeWallet Class) - http://idsm.citadelprocessing.com/Sa.../WalletCab.CAB
O16 - DPF: {41F841C0-AE16-11D5-8817-0050DA6EF5E5} (FarPoint Spread 6.0 (OLEDB)) - http://www.acehardware-aceonline.com...60/fpspr60.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.co...veX/winrep.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...6/mcinsctl.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1092958233729
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar...ackToolbar.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/bi.../GoogleNav.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1124839281500
O16 - DPF: {8DF4F477-0EF7-4AD2-A975-FD124B6F98DA} (MSN Money QuickList) - http://fdl.msn.com/public/investor/v11/investor.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.acehardware-aceonline.com/tsweb/msrdp.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://zinio.earthc.net/images.zinio...der/isetup.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.co...X/FileXfer.cab
O16 - DPF: {AA59BA6E-B44F-4514-AB3C-0C1DD2306FC3} (MSN Money Charting) - http://fdl.msn.com/public/investor/v12/invinstl.exe
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/Sha.../bin/cabsa.cab
O16 - DPF: {C3CBFE35-9BE8-11D1-B31B-006008948294} (OrgPublisher PluginX) - http://www.acehardware-aceonline.com...rt/OrgPubX.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/tech...l/SymAData.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mp...CX/FlashAX.cab
O16 - DPF: {F798683C-FE05-436C-B0FF-35B9122E9787} - http://www.merriamwebster.com/tools/...r/cabs/m-w.cab
O16 - DPF: {FF054BED-D972-4215-897E-726C3488DDBB} (sonyctl.sonycm) - http://supportcentral.sel.sony.com/s...ad/sonyctl.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Quote:
Originally Posted by shadesofgrey
Pretty run of the mill stuff...I think the laptop is okay.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #62 (permalink)     Top 
Old 01-04-2007, 07:34 PM
dad604's Avatar
dad604 dad604 is offline
World Series Champ
 
Join Date: Apr 2005
Posts: 4,396
Chips: 170
Rating: 0% (0)
Re: My Neteller account compromised - already lost over $1100

Quote:
Originally Posted by EmptyPocs
Well, I gave up on that and emailed Neteller support.
How on earth do you scrap your existing bank account link and add a new one. I can't find it anywhere!
You can do it over the phone. I had to it that way earlier this year.

Jamby, sorry to hear about your problem. I hope it gets resolve to your satisfaction.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #63 (permalink)     Top 
Old 01-04-2007, 07:35 PM
JM's Avatar
JM JM is offline
Mod & Postmeister General
 
Join Date: Apr 2005
Location: Massachusetts
Posts: 15,520
Chips: 14,462
Rating: 100% (7)
Re: My Neteller account compromised - already lost over $1100

A couple of online banks I can recommend for anyone looking for an extra account.
www.gmacbank.com
www.millenniumbank.com
www.firstib.com
__________________
Member: 3U Crew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #64 (permalink)     Top 
Old 01-04-2007, 07:43 PM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller account compromised - already lost over $1100

My P* and NT passwords were the same. Conceivably, he could have hacked into NT, checked the history for transactions, saw P* and tried the obvious. He then drained my P* account. That's what the P* folks think happened anyway. They weren't suspicious because there were no logon failures when he logged in there and he transferred the funds out the same way they had gone in. No red flags at all. Their conention is that the folks at Betway and ParadiseBet should have used the same precautions and matched the funding source with the account.
Quote:
Originally Posted by jojobinks
sorry, andi.

question: if this guy got money from p*...wouldn't he have had to had your p* password as well?

can you do that straight from NT?

i just ran through and changed all my passwords
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #65 (permalink)     Top 
Old 01-04-2007, 08:02 PM
PhilTheThrill14's Avatar
PhilTheThrill14 PhilTheThrill14 is offline
ChipTalk.net Article Writer
 
Join Date: Mar 2005
Location: Rochester, MA
Age: 40
Posts: 2,657
Chips: 8,339
Rating: 0% (0)
Send a message via AIM to PhilTheThrill14 Send a message via MSN to PhilTheThrill14
Re: My Neteller account compromised - already lost over $1100

I looked real quick and don't see anything wrong with that log either. Someone else take a look and confirm.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #66 (permalink)     Top 
Old 01-04-2007, 08:05 PM
7thSeat's Avatar
7thSeat 7thSeat is offline
Creativity Alliance
 
Join Date: Jan 2006
Location: SWEDEN
Posts: 2,265
Chips: 2,987
Rating: 100% (1)
Re: My Neteller account compromised - already lost over $1100

I am very sorry to hear about your trouble Andi.
Hang in there and demand top notch help from all the involved parties.
I have only vauge knowleuage in computers/internet but should P* not been able to find an IP address from the thief?
Hopefully it will get solved in the end, I hold my thumbs for you.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #67 (permalink)     Top 
Old 01-04-2007, 08:21 PM
shadesofgrey's Avatar
shadesofgrey shadesofgrey is offline
World Series Final Table
 
Join Date: Apr 2005
Location: portland
Age: 98
Posts: 2,833
Chips: 1,818
Rating: 0% (0)
Re: My Neteller account compromised - already lost over $1100

One suspect is the FlashXControl.... but it might be nothing. Your version from register3 is from 2004.... I download the one from ladbrokescasino and it is from 2006..... Hmmm...

Yours reads:
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mp...CX/FlashAX.cab

When I look for the same process it should be:
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://play.ladbrokescasino.com/ladbrokes/FlashAX.cab

OR

O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://virtualcitycasino.microgamin...no/FlashAX.cab

I might be wrong.... but FlashAX.cab seems like a probable target being its mainly associated with gambling sites.

jamby - could you issue a "netstat -a" and post the output? Maybe there is something that is opening a port and sending out info.

Or even better go to www.grc.com and do a "shields up" test. that will test all your ports for leaks.

One other thing to check is if there are any new exeptions in your firewall.... I know I can add programs to the firewall exception list programmatically - basically allowing my applications access to the internet without ever having the user click anything. There may be clues in there.

Do you use DSL, Broadband, or Dialup.... I see netzero and comcast. Is your network wired or wireless? Just curious.... Well I guess the thief was in alabama so its not someone sitting out side your house sniffing packets...

One last thing to check is if you have upnp enabled on your router... I know I can back door into routers that have UPnP enabled... then set up a port forward & sniff the packets.... Just a thought.

Lastly there is the Microsoft PID sniffer, but I believe that used as an anti-piracy mechanism for MS Office.

GL! Hopefully this gets resolved.
__________________
“One cannot step twice in the same river.” – Heraclitus

Last edited by shadesofgrey : 01-04-2007 at 08:32 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #68 (permalink)     Top 
Old 01-04-2007, 08:31 PM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller account compromised - already lost over $1100

Thanks 7. Yes, P* knows the IP of the person who logged into my account this morning and authorized the transfer to NT. It is an IP from Arkansas and only one P* user has ever logged on with that IP. I have his Neteller ID too. Not a whole lot of help though at this point though since it could be an IP of an internet cafe or something like that so they aren't willing to connect the user with the IP in this case.
Quote:
Originally Posted by 7thSeat
I am very sorry ...should P* not been able to find an IP address from the thief?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #69 (permalink)     Top 
Old 01-04-2007, 08:42 PM
shadesofgrey's Avatar
shadesofgrey shadesofgrey is offline
World Series Final Table
 
Join Date: Apr 2005
Location: portland
Age: 98
Posts: 2,833
Chips: 1,818
Rating: 0% (0)
Re: My Neteller account compromised - already lost over $1100

PhilTheThrill - what do you think about that flashax.cab?
__________________
“One cannot step twice in the same river.” – Heraclitus
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #70 (permalink)     Top 
Old 01-04-2007, 08:56 PM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller account compromised - already lost over $1100

Here's the netstat -a output. If anybody has a better way to get the dos output into a readable file format let me know.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

vBClassified Featured Listings
St JOs Casino Paulson Cash Set
650pc Empty Hourglass set
WTS: 44mm/39mm Mixed High Stakes Tournament S..,
Paulsons, ASM Rounders replicas, ASM solid ca..,



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes