On May 29th I made a post about the email scam from gshargrave.com. I sent an email to Mr. Hargrave regarding my findings and found his reply to be rather sincere. I want to offer him the courtesy of an explanation; following is his response:
I just saw your letter below for the first time. My gmail account is set to auto-forward mail to my POP3 service, and this one either didn't make the trip or was inadvertently discarded. I only found it after accidentally running across your Spam Me Not entry last night, which prompted me to go to my gmail account. Your Spam Me Not post came up as I was doing a Google search on my own name, out of simple curiousity concerning how easily it might locate my website.
What I read in your post came as a very unpleasant shock indeed. Believe me, I have nothing but contempt for spammers and the purveyors of malware, and couldn't quite believe what I was reading. I quickly noted, however, that the webhost you mentioned was in fact my own. I also noted that the link you posted was a variation on that which leads to my legitimate website, the obvious difference being the "versa1" prefix; the first part of the address to my legit website begins only with my name.
As created, my website consisted only of topical text, a few photographs, links for internal page navigation, and a couple of relevant external links. There was absolutely no other content of any kind--most certainly nothing malicious. I even posted my contact address as an image file, so as to provide nothing that would attract the attention of spidering spamming software.
Perhaps unwisely, I clicked on the "versa1" link you posted. That took me to what is essentially a clone of my own legitimate website--with the apparent addition of some sort of mechanism that downloads malware. I immediately knew something was up last night because I'm on a slow dial-up connection. While my pages were designed to download fairly quickly over such a connection, the "versa1" clone just kept on running, evidently having started an unauthorized download in the background. Worse still, I could not close or navigate away from the page in a normal fashion, and was unable to shut down Internet Explorer via the CTRL/ALT/DEL command. Each time I shut down the program a new instance of Explorer would open, with the download continuing. Finally I simply killed the power with the surge protector switch, and then booted back up, dumped my temporary internet cache, and ran a full system virus scan. That fortunately revealed no problems. I was probably only able to interrupt what was undoubtedly a malware installation by virtue of having a slow connection. On broadband all of that probably would have been completed before I could have reacted--or even suspected. I was nearly a victim of "my own" website!
First thing this morning, I checked my website folders on my internet host. Sure enough, password protection nothwithstanding, I'd been hacked. There was a "versa1" folder that I never created, containing duplicates of my legit site files, and--although I can't ID it--presumably something to facilitate the transmission of malware. I immediately contacted my webhost and got a prompt reply. He told me quite a few of their other customers had the same problem. This has been coming to light as people on their customers' own mailing lists have slowly figured out the likely source of their increased volumes of spam mail. Unfortunately, they couldn't detect which sites were infected until such reports came in.
I'm going to pull all of the "versa1" files from the server ASAP. Hopefully that will plug the breech. Then I'm going to migrate my legitimate site along with my webhost service to his own new service provider. The fact that he's moving his entire operation may suggest that he has his own clear suspicions about the initial source of the malware.
Though none of this has resulted from any deliberate action or particular carelessness on my own part, I do sincerely apologize for any trouble it has given you. It's a helluva thing on my own end: I'd set up that site with the intention of furthering my efforts as a writer. Instead, I picked up a d-mn parasite that can create serious problems for anyone clicking on the wrong link, with all of that being directly associated with my own good name. I actually own you a thanks, because had I not run across your Spam Me Not page I might not have become aware of the problem for a very long time. Who would have considered the existence of an infected clone of one's own website, that is unknowingly associated with your own good name on Google? I don't often review the content of each file on my host server. I generally only pay attention to what I'm working on, and I've only worked on things rarely.
I can't say that I blame you at all for concluding that I personally had something to do with all of this. In your situation, I would likely have concluded exactly the same thing.
Sincerely,
G.S.Hargrave
Monday, June 15, 2009
Monday, June 8, 2009
Realdataentry.net scam and Google Comments
If you have a Google account (email, analytics, etc.) and use Google as your search engine you may have noticed that when you do a search there are several new options available. After an inquiry you will notice that next to the "title" of the site are two buttons; one that has an "up arrow" and an "X". If you were to visit the site you could decide to move it to page one on Google if you liked it by clicking on the Up Arrow. Or, you could select the "X" and remove it from your search all together. However, that's not the best benefit available. You see just below the description you will notice the words "Cached" and "Similar pages"; next to that is a "comments" bubble which allows you to place PUBLIC comments for all "Google" users to see. That includes your experience with realdataentry.net!!!!!! Hopefully Google is analyzing the comments and using that info to build a database to eliminate the scammers from trying to cheat honest hard working people. You now have a voice...express it! Make sure you check back soon, I have other information about the owner of realdataentry.net.
Friday, June 5, 2009
Who Is Natbug81?
Every day I read more about people being scammed by realdataentry.net. What I don't understand is after being warned of this company why people STILL sign up with them! Well after you get ripped off you'll want to know (like everyone else) how to contact them. The fact is they have the ability through their website to block your IP address so that they no longer have to deal with you. Furthermore because of Privacy Policies, their web hosting service and bank (Bank of America) will not provide you with ANY information. So what next? You research as much as you can, file the appropriate complaints, and wait for them to make a mistake. And make a mistake they did! Now before I tell you what I've discovered, let me inform you that the best thing you can do (in case a class action suit is taken against them) is to SAVE ALL the emails and assignments they sent you in a folder. Your email provider lists the time and date these were sent to you and also includes any duplicate assignments (which they claim if you submit, violates the terms of service...hence no payout)!
Now let's get down and dirty! Did you know that your email contains a link below the content called "Full Headers" that when opened shows several details of the orgin of the email? Well I sent an email to their hosting account ezwebsolution.net and received a nasty email that had the same tone as the responses I received from realdataentry.net. It appears "Tiffany" wanted to know about my complaints to the FTC (which included complaints about ezwebsolution.net) then claimed that they've seen "proof" of payments and felt I should not post their name in any forums or blogs for fear of spam! A professional and legitimate company would not respond in this manner nor have anything to fear. By the way if they're concerned then maybe they should do some research themselves and discover what we all know. It should be their responsibility to cease hosting realdataentry.net.
Anyway I managed to locate several IP addresses within the header and ran them through some programs that listed more information and oddly enough I discovered there were 5 other websites associated with that IP address. Of course I wasn't surprised when one of them was ezwebsolution.net...realdataentry's hosting provider! And dataprocessors.org...the other scam listed on my blog! Now I must admit that I didn't want to pay $20 to find the two other sites associated with them...I had enough!
Let me get back to my email situation. During all my inquiries someone forwarded my complaint to the owner of Realdataentry.net Shortly afterwards I received a response that read in part that "...I was the one trying to scam THEM!" Fortunately they replied using their PERSONAL email and from that I was able to do more research and found that nagbug81@gmail.com has quite the online presence. If you do a search just for natbug81 you will see some of her other endeavors and you'll even a glimpse of her. Now I thought I might be jumping to conclusions however natbug81 is not a common user ID...it's unique.
Now I don't want to make this post too long so I will list names, and other personal information in another post. I also have a Google trick that will let you post public comments below their websites description when doing a Google search.
Now let's get down and dirty! Did you know that your email contains a link below the content called "Full Headers" that when opened shows several details of the orgin of the email? Well I sent an email to their hosting account ezwebsolution.net and received a nasty email that had the same tone as the responses I received from realdataentry.net. It appears "Tiffany" wanted to know about my complaints to the FTC (which included complaints about ezwebsolution.net) then claimed that they've seen "proof" of payments and felt I should not post their name in any forums or blogs for fear of spam! A professional and legitimate company would not respond in this manner nor have anything to fear. By the way if they're concerned then maybe they should do some research themselves and discover what we all know. It should be their responsibility to cease hosting realdataentry.net.
Anyway I managed to locate several IP addresses within the header and ran them through some programs that listed more information and oddly enough I discovered there were 5 other websites associated with that IP address. Of course I wasn't surprised when one of them was ezwebsolution.net...realdataentry's hosting provider! And dataprocessors.org...the other scam listed on my blog! Now I must admit that I didn't want to pay $20 to find the two other sites associated with them...I had enough!
Let me get back to my email situation. During all my inquiries someone forwarded my complaint to the owner of Realdataentry.net Shortly afterwards I received a response that read in part that "...I was the one trying to scam THEM!" Fortunately they replied using their PERSONAL email and from that I was able to do more research and found that nagbug81@gmail.com has quite the online presence. If you do a search just for natbug81 you will see some of her other endeavors and you'll even a glimpse of her. Now I thought I might be jumping to conclusions however natbug81 is not a common user ID...it's unique.
Now I don't want to make this post too long so I will list names, and other personal information in another post. I also have a Google trick that will let you post public comments below their websites description when doing a Google search.
Labels:
natbug81,
realdataentry scams,
realdataentry.net
Friday, May 29, 2009
vers1.gshargrave.com/makemoney.html scam
While checking my email I noticed that there were a couple of "email failure notices" listed. When I opened the email I discovered that a program was sending emails to my ENTIRE list of contacts. The subject line stated "$$$ Online Casino-The Secrets Of Online Casinos". Of course I reported the abuse to Yahoo but I wanted to do some of my own research. When I opened the email I was able to do a Whois.com inquiry based off the URL http://vers1.gshargrave.com/makemoney.html. Whois.com indicated the hosting account was ns.awenwebservice.com. When I went to their website all they had was a graphic with NO links or any way to access the site....it was a bogus page. I then decided to look up just gshargrave.com and found the site to be innocent enough; however when I did a Google search for "gshargrave" I found their description to be rather odd. Below is a screen shot of that result. Do you smell a rat?!? The site below had a Contact page so I immediately sent them a nasty email.
Author G S Hargrave (Gregory S Hargrave) -- biographical sketch... cialis purchase · generic cialis from canada · 20mg cialis · cialis online discount · cipro generic name · for cipro uti · virus cipro · cipro order ...gshargrave.com/biogra.htm - 216k
Subscribe to:
Posts (Atom)
