Hi,

Yesterday when I used IE 6 to go to Paypal web site, it went to www.paypal.com.org. So I closed the browser and didn't go there again. Is my PC infected ? I just went to Paypal web site again today, it seemed to be the genunine Paypal site.

What should I do to avoid identity theft in this case?

I have NOD32, ZoneAlarm with Antivirus, Spyware Blaster for online protection. I periodically scan my PC with Spybot Search & Destroy, Spyware Terminator and A-squared free. Are there any other software I should have?

Thanks in advance.

Dani AI

Generated

A short, practical summary that builds on and : that transient redirect could be either a harmless DNS/hosting quirk or a sign that local name resolution was altered (hosts file or local malware) — both are plausible. was right to flag the hosts-file angle; is also right that some domains show a “how you got here” redirect when a registered domain changes hands. Follow a careful, staged response rather than panicking. (support.microsoft.com)

Immediate, high-priority steps: do not enter credentials on the suspicious page. From a different, trusted device (not the one you think might be infected) open PayPal via the official app or a bookmarked URL, review recent transactions, change your PayPal password, and enable 2‑step verification. If you see unauthorized activity, report it to PayPal and follow the government guidance for identity-theft recovery. For account recovery and the safest practice of making credential changes from a clean device, see vendor and incident-response guidance. (paypal.com)

Cleanup and verification: run full, up‑to‑date antivirus/antimalware scans (consider Windows Defender/Windows Safety Scanner and an on‑demand tool like Malwarebytes/AdwCleaner), then inspect startup and autostart locations with a trusted tool such as Sysinternals Autoruns. If multiple devices on the same network show the same redirect, check router DNS/settings and firmware (router compromise happens). If you’re not comfortable with manual cleanup, back up personal files and consider a clean OS reinstall. (support.microsoft.com)

Prevention going forward: stop using very old, unsupported browsers (IE6-era browsers are insecure) — use a modern, updated browser and enable automatic updates. Harden the home router (change default admin passwords, update firmware, disable remote management) and enable multifactor authentication everywhere important. If you remain worried about identity theft, freeze or monitor credit and follow the FTC’s recovery plan. (learn.microsoft.com)

Recommended Answers

All 4 Replies

yeah it seems a virus has modified a thing called your hosts file to redirect you.

Do it in this order

the "hosts" file lives in C:\WINDOWS\system32\drivers\etc

IT SHOULD ONLY CONTAIN

127.0.0.1       localhost

also check the file "lmhosts.sam". Everything should be commented out with a # - if anything is on a line on its own then delete it.

next, go into spybot s+d and do a scan and fix all then do "immunise"
then check with all your other programs to be sure

after that download a tool called HijackThis. Rename hijackthis to something else and then run it. Choose to run a scan and save a log. Post the log file here.

Hatespy, it is most likely not a problem with your computer, more likely Paypal was momentarily down and IE then fooled with the URL. If you want a complete explanation [or one, anyway] click on the link in your post above and then in the webpage that opens click the link How you got here...
Com.org is benign.

Thanks a lot, folks!

James, I checked the "hosts" file as suggested, below "127.0.0.1 localhost" there are tons of weird URLs I never visited.

Should I delete all of them?

Would there be any risk involved?

Thanks!


yeah it seems a virus has modified a thing called your hosts file to redirect you.

Do it in this order

the "hosts" file lives in C:\WINDOWS\system32\drivers\etc

IT SHOULD ONLY CONTAIN

127.0.0.1       localhost

also check the file "lmhosts.sam". Everything should be commented out with a # - if anything is on a line on its own then delete it.

next, go into spybot s+d and do a scan and fix all then do "immunise"
then check with all your other programs to be sure

after that download a tool called HijackThis. Rename hijackthis to something else and then run it. Choose to run a scan and save a log. Post the log file here.

spybots immunisation adds some lines, but spyware can add lines too. delete everything apart from the "127.0.0.1 localhost" line and reapply the spybot immunisations

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.