Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: money.cafreedom.com  (Read 15304 times)

0 Members and 1 Guest are viewing this topic.

matt

  • Guest
money.cafreedom.com
« on: November 07, 2004, 10:15:21 AM »
ok, i have the sygate personal firewall on my computer, i run firefox as my browser, but when ever i launch explorer to acesses my computer or my documents, the firwall pops up and says:

Windows Explorer (exploter.exe) is trying to connect to money.cafreedom.com [66.17.180.52] using remote port 80(HTTP - World Wide Web).  Do you want to allow this program to access the network?"

i always say no, but then ever i close out to my computer/mydocuments etc., explorere crashed.  it reloads fine and the computer still runs, just what is this? and how can i get ride of it?  i ran ad-aware but that found nothing.

Raptor

  • Guest
Re: money.cafreedom.com
« Reply #1 on: November 07, 2004, 10:58:09 AM »
Scan for Spyware.

matt

  • Guest
Re: money.cafreedom.com
« Reply #2 on: November 07, 2004, 11:31:45 AM »
i ran both ad-aware and spy-bot

Raptor

  • Guest
Re: money.cafreedom.com
« Reply #3 on: November 07, 2004, 12:12:08 PM »
Reconfigure them to do extensive scans.

matt

  • Guest
Re: money.cafreedom.com
« Reply #4 on: November 07, 2004, 12:23:41 PM »
i did for ad-aware, im not sure how for spy-bot

Raptor

  • Guest
Re: money.cafreedom.com
« Reply #5 on: November 07, 2004, 12:26:57 PM »
Have you scanned for Viruses and Trojan Horses?

matt

  • Guest
Re: money.cafreedom.com
« Reply #6 on: November 07, 2004, 12:42:19 PM »
yea, using AVG anti-virus, i'll run it agian now though, and how can i set spy-bot to deep scan

matt

  • Guest
Re: money.cafreedom.com
« Reply #7 on: November 07, 2004, 01:11:00 PM »
the virus/trojan scan came up clean

Raptor

  • Guest
Re: money.cafreedom.com
« Reply #8 on: November 07, 2004, 01:15:00 PM »
I have no experience with Spybot S&D

Do you have programs installed  that may be forcing your browser to connect to that adress?

Use HijackThis

matt

  • Guest
Re: money.cafreedom.com
« Reply #9 on: November 07, 2004, 01:39:08 PM »
not to my knowledge, but i'll try highjack this

matt

  • Guest
Re: money.cafreedom.com
« Reply #10 on: November 07, 2004, 01:48:30 PM »
here is my hijack this log:

O2 - BHO: (no name) - {11CEFA27-5AE9-46CB-B791-738C242B4761} - E:\WINDOWS\system32\6ji.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Dell AIO Printer A920] "E:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG_CC] E:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] E:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: PeerGuardian (2).lnk = E:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM95\aim.exe
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - e:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll


it all seems fine to me, expect the first and third objects, i dont know what they are.

Raptor

  • Guest
Re: money.cafreedom.com
« Reply #11 on: November 07, 2004, 02:14:23 PM »
The Toolbar & Radio is harmless, I believe. I've seen it before on my PC as well. Must come with Internet Explorer.

Entry number one does seem a bit dubious, no Google search results..

There's a tool  that seems to be recommended often. Give it a try: CWShredder
« Last Edit: November 07, 2004, 02:18:36 PM by Raptor »

matt

  • Guest
Re: money.cafreedom.com
« Reply #12 on: November 08, 2004, 10:07:31 AM »
i fooled around with CWShredder, but it didnt find anything.  any other ideas, this thing is really anoying.

Raptor

  • Guest
Re: money.cafreedom.com
« Reply #13 on: November 08, 2004, 10:43:48 AM »
use different spyware/virus scanners. See if any of them picks up any threats the others do not.

2k dummy

  • Guest
Re: money.cafreedom.com
« Reply #14 on: November 08, 2004, 11:54:27 AM »
Do you have any dealings or relationship to any of the following:

NRSoftware
Bane Media
xeex
Yipes

The url and IP address belongs NRSoftware. They are a rather nefarious outfit and are known to be spammers. They use hosting  companies to cover their tracks. You likely have a backdoor that they are trying to use. Use a dedicated trojan detection software and keylogger detection. By all means, keep it blocked in the firewall.