So, I click on my sent folder in hotmail and notice a series of emails ordering a recharge of a cell phone number? Not sure what that is, maybe minutes. The person ordered from a online indian site called myshop.co.in. Claimed to be a person called "Derek Cormier". I have the cell phone numbers that it has recharged. The messages sent, started 3 days ago. I check my paypal account and there is money paid to the indian shop and also money to "Betamax GmbH & Co.KG". I reported the unauthorized charges to paypal. I emailed the indian shop with no response. 450 dollars were sent to my account from http://www.bvitans.com. I assume this is fake money? Today, I have gotten refund for the betamax, but not the indian shop. I changed my password for hotmail and paypal. Disconnected my card from paypal and ordered a security key. I'm still confused how they got into my accounts. My only guess is it was a cookie grabber? I didn't use the computer that much lately, but I think it might have been a Dragonball website. First thing I did was delete everything with ccleaner. I have searched with mcafee, adaware and spybot with little results. I have deleted only a few tracking cookies. I download a anti-dialer guard. Doesn't do anything. I download superantispyware, x-cleaner, 2 other programs and search and find nothing. My mcafee protection status keeps shutting off at long random intervals, not sure if this is related. My laptop is: Dell inspiron 9400, intel core duo cpu, t2250 @ 1.73GHz 1.73 Ghz, 2046 MB ram, 32 bit OS, Vista home premium Hijacklog: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:05:12 PM, on 7/28/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16681) Boot mode: Normal Running processes: C:\Windows\System32\smss[Caution: Executable File] C:\Windows\system32\csrss[Caution: Executable File] C:\Windows\system32\wininit[Caution: Executable File] C:\Windows\system32\csrss[Caution: Executable File] C:\Windows\system32\services[Caution: Executable File] C:\Windows\system32\lsass[Caution: Executable File] C:\Windows\system32\lsm[Caution: Executable File] C:\Windows\system32\winlogon[Caution: Executable File] C:\Windows\system32\svchost[Caution: Executable File] C:\Windows\system32\svchost[Caution: Executable File] C:\Windows\System32\svchost[Caution: Executable File] C:\Windows\System32\svchost[Caution: Executable File] C:\Windows\System32\svchost[Caution: Executable File] C:\Windows\system32\svchost[Caution: Executable File] C:\Windows\system32\SLsvc[Caution: Executable File] C:\Windows\system32\svchost[Caution: Executable File] C:\Windows\system32\svchost[Caution: Executable File] C:\Windows\SYSTEM32\WISPTIS[Caution: Executable File] C:\Program Files\Common Files\microsoft shared\ink\TabTip[Caution: Executable File] C:\Windows\System32\spoolsv[Caution: Executable File] C:\Windows\system32\Dwm[Caution: Executable File] C:\Windows\system32\taskeng[Caution: Executable File] C:\Windows\SYSTEM32\WISPTIS[Caution: Executable File] C:\Program Files\Common Files\microsoft shared\ink\TabTip[Caution: Executable File] C:\Windows\Explorer[Caution: Executable File] C:\Program Files\Windows Defender\MSASCui[Caution: Executable File] C:\Program Files\Synaptics\SynTP\SynTPEnh[Caution: Executable File] C:\Windows\sttray[Caution: Executable File] C:\Program Files\iTunes\iTunesHelper[Caution: Executable File] C:\Windows\System32\rundll32[Caution: Executable File] C:\Windows\System32\rundll32[Caution: Executable File] C:\Windows\System32\ATWTUSB[Caution: Executable File] C:\Windows\System32\WDBtnMgr[Caution: Executable File] C:\Program Files\McAfee.com\Agent\mcagent[Caution: Executable File] C:\Program Files\a-squared Anti-Dialer\a2adguard[Caution: Executable File] C:\Program Files\Spybot - Search & Destroy\TeaTimer[Caution: Executable File] C:\Program Files\AIM6\aim6[Caution: Executable File] C:\Program Files\Digital Line Detect\DLG[Caution: Executable File] C:\Program Files\Logitech\SetPoint\SetPoint[Caution: Executable File] C:\Windows\System32\rundll32[Caution: Executable File] C:\Program Files\a-squared Anti-Dialer\a2service[Caution: Executable File] C:\Program Files\Bonjour\mDNSResponder[Caution: Executable File] C:\Windows\System32\svchost[Caution: Executable File] c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy[Caution: Executable File] C:\Program Files\McAfee\MPF\MPFSrv[Caution: Executable File] C:\Program Files\McAfee\MSK\MskSrver[Caution: Executable File] C:\Windows\system32\oodag[Caution: Executable File] C:\Windows\system32\PnkBstrA[Caution: Executable File] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9[Caution: Executable File] C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV[Caution: Executable File] C:\Windows\system32\svchost[Caution: Executable File] C:\Program Files\Viewpoint\Common\ViewpointService[Caution: Executable File] C:\Windows\System32\svchost[Caution: Executable File] C:\Windows\system32\SearchIndexer[Caution: Executable File] C:\Windows\system32\DRIVERS\xaudio[Caution: Executable File] C:\Program Files\Spybot - Search & Destroy\SDWinSec[Caution: Executable File] C:\PROGRA~1\McAfee\MSC\mcmscsvc[Caution: Executable File] C:\Program Files\iPod\bin\iPodService[Caution: Executable File] C:\Program Files\Common Files\AOL\Loader\aolload[Caution: Executable File] C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR[Caution: Executable File] C:\Windows\System32\TBLMOUSE[Caution: Executable File] C:\Program Files\AIM6\aolsoftware[Caution: Executable File] C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon[Caution: Executable File] C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization[Caution: Executable File] c:\program files\common files\mcafee\mna\mcnasvc[Caution: Executable File] C:\Program Files\Mozilla Firefox\firefox[Caution: Executable File] C:\Windows\System32\osk[Caution: Executable File] C:\Program Files\Lavasoft\Ad-Aware\aawservice[Caution: Executable File] C:\Windows\system32\taskeng[Caution: Executable File] C:\Program Files\Orbitdownloader\orbitdm[Caution: Executable File] C:\Program Files\Orbitdownloader\orbitnet[Caution: Executable File] C:\Program Files\BitTorrent\bittorrent[Caution: Executable File] C:\PROGRA~1\mcafee\msc\mcshell[Caution: Executable File] C:\Program Files\Common Files\McAfee\Core\mchost[Caution: Executable File] C:\Program Files\McAfee\VirusScan\McShield[Caution: Executable File] C:\Program Files\Trend Micro\HijackThis\HijackThis[Caution: Executable File] C:\Windows\system32\wbem\wmiprvse[Caution: Executable File] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui[Caution: Executable File] -hide O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh[Caution: Executable File] O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray[Caution: Executable File] O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch[Caution: Executable File]" -start O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper[Caution: Executable File]" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched[Caution: Executable File]" -osboot O4 - HKLM\..\Run: [OODefragTray] C:\Windows\system32\oodtray[Caution: Executable File] O4 - HKLM\..\Run: [NvSvc] RUNDLL32[Caution: Executable File] C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32[Caution: Executable File] C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32[Caution: Executable File] C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NVHotkey] rundll32[Caution: Executable File] C:\Windows\system32\nvHotkey.dll,Start O4 - HKLM\..\Run: [atwtusb] atwtusb[Caution: Executable File] O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr[Caution: Executable File] O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR[Caution: Executable File] O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent[Caution: Executable File] /runkey O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Dialer\a2adguard[Caution: Executable File]" O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar[Caution: Executable File] /autoRun O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt[Caution: Executable File]" /startup O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer[Caution: Executable File] O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6[Caution: Executable File]" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr[Caution: Executable File]" /background O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32[Caution: Executable File] oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /detectMem (User 'NETWORK SERVICE') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader[Caution: Executable File] O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc[Caution: Executable File] O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl[Caution: Executable File] O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG[Caution: Executable File] O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint[Caution: Executable File] O4 - Global Startup: QuickSet.lnk = ? O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL[Caution: Executable File]/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx O16 - DPF: {77538FC7-CE52-4704-9865-494FE92BC320} (LaunchUBO.Ulit) - http://www.ultimatebaseballonline.com/m ... nchubo.OCX O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: McAfee Application Installer Cleanup (0164841217243236) (0164841217243236mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\016484~1[Caution: Executable File] O23 - Service: a-squared Anti-Dialer Service (a2AntiDialer) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Dialer\a2service[Caution: Executable File] O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice[Caution: Executable File] O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc[Caution: Executable File] O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder[Caution: Executable File] O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc[Caution: Executable File] O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService[Caution: Executable File] O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT[Caution: Executable File] O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService[Caution: Executable File] O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ[Caution: Executable File] O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc[Caution: Executable File] O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc[Caution: Executable File] O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods[Caution: Executable File] O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy[Caution: Executable File] O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield[Caution: Executable File] O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon[Caution: Executable File] O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv[Caution: Executable File] O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver[Caution: Executable File] O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag[Caution: Executable File] O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA[Caution: Executable File] O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9[Caution: Executable File] O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9[Caution: Executable File] O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd[Caution: Executable File] O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec[Caution: Executable File] O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV[Caution: Executable File] O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr[Caution: Executable File] O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService[Caution: Executable File] O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio[Caution: Executable File] -- End of file - 13164 bytes