Oberon wrote:
What's the email address of the PayPal account it sends you to?
I curse myself for blocking it now, cause that would really have helped alot - the link just said "www.paypal.com" but computers don't go to links like that for nothing, we all know that and I strongly doubt that paypal would use that kind of "advertisement"
lexiKos wrote:
It is relatively easy to inject code into a running process (at least if you are an administrator?)
I am, its a home PC
lexiKos wrote:
but like you said, why would anyone bother? Maybe the (hypothetical) virus hijacks a random process to disguise itself?
Yes thats hypotheical possible, although i think the chance of something like that happening is VERY slim.And the strange thing was, that the program was NOT running at all (when i checked after firewall prompting). I checked my running processes to see if it somehow failed to closed correctly, but no nothing. (I was playing a game full screen with a minimum of app running in the back, at the time)
I know it must have been running when it wanted to launch mozilla, otherwise the firewall would be bugged (and lets just exclude that one)
So something must have launched it, as a background process and then tell it to go to these pages.
I searched my registry for "paypal" and it found nothing. Since I have a firewall running (and its prompting both in and outgoing "firsttimers") the chances of someone remotely activating the application are slim to zero.
So status is that :
1 : the exe file have been checked, dobbelt checked, and its not infected, bugged or corrupted.
2 : No "weird" strings have been found in the exe file(at least not in Unicode)
3 : SmartGui.exe was not running (under my authority) when it happened
4. I searched my registry for "paypal" and found 0 items
next we have story's about how gnomes, and midgets might be taking over my desktop and turn it into a waffle bakery
I mean this its hopeless, there is no chance of ever getting to know what did this, someone did it and whoever that was he/she must truly be a mastermind.
If anyone has any idea to as what more can be done to figure out what caused this problem, please add it.