The PayPal documentation says this of the 10417 error:> 10417 Transaction cannot complete.
The transaction cannot complete successfully. Instruct the customer to use an alternative payment method.
It is possible that the payment method the customer chooses on PayPal might not succeed when you send DoExpressCheckoutPayment. The most likely cause is that the customer’s credit card failed bank authorization.
Another possible, though rare, cause is that the final OrderTotal is significantly higher than the original estimated OrderTotal
you sent with SetExpressCheckout at Integration Point 1, and the final OrderTotal does not pass PayPal’s risk model analysis.
If the customer has no other PayPal funding source that is likely to succeed, DoExpressCheckoutPayment response
returns error code 10417. Instruct the customer that PayPal is unable to process the payment and redisplay alternative
payment methods with which the customer can pay.
In another section they further state:> Account not associated with a usable funding source.
Essentially, it appears to boil down to a case where the customer's PayPal account hasn't sufficient funds to complete the transaction, and their alternate funding sources aren't deemed acceptable to PayPal at the present time.
You mentioned that you've noticed an unusual number of similar cases recently. This is something I think PayPal will have to evaluate to determine whether they've got a system problem or if all those customers' accounts are problematic, or if maybe someone's targeting your store with fraudulent credit cards or something. Only PayPal will be able to determine specifically why they refused those transactions.
As for which logs to submit to PayPal, the filenames containing "CURL" are the ones they'll find useful. The rest are just Zen Cart program flow snapshots, not useful to PayPal technicians.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.