| Windows 7: 161.40.59.127 attacked port 13567 BankerfoxA |
30 Jun 2010
|
| | win 7 pro upgrade disc set running 64 bit 12 posts |
161.40.59.127 attacked port 13567 BankerfoxA I am running 64 bit Windows 7 and use Microsoft Security Essentials which is updated and real time protection is enabled. when a pop up window claimed i was infected by Bankerfoxa port 977 attacked port 13567 161.40.59.127 asking me if it wanted me to have it turn on my virus protection I hit my toolbar to see if security essentials was loaded ( which it was suppose to be but it was not) so i click start/programs, Microsoft security essentials i right click it run as admin and it opens its window and then closes and a pop up claims one of its files are corrupt and ask again if it wants me to have it start my anti virus program, while this attack is in progress i cannot use the prompt and run sfc /scannow or chkdsk /f all of Microsoft tools are disabled I have to reboot in order to stop this from happening and it has happened twice both times while looking for something with Google. wondering if anyone else has had this or similar and should i switch to avira anti virus
thanks | My System Specs |
| System Manufacturer/Model Number msi ms-7549 OS win 7 pro upgrade disc set running 64 bit CPU amd Phenom II x 4 B50 processor 3.10 GHz Motherboard 785gtm-e45 main board Memory 4.0 GB Graphics Card radeon 4200 Sound Card Realtech High Definition Audio Monitor(s) Displays hp 2009m @ 1024x768 256 MB Standard VGA Graphics Adapter Keyboard Standard PS/2 Keyboard, HID keyboard device Mouse PS/2 Compatible Mouse, HID-compliant mouse Case desktop Hard Drives 160 GB Hitachi HtS541616J9SA00 ATA Device (IDE) 96 F
500 GB Hitachi HtS545050B9A300 ATA Device (IDE) 112 F
3GB SD Memory Card (NULL) Internet Speed Sprint Broadband sierra wirerless usb modem 595u Other Info HL-DT-ST DVD+ -RW GSA-T21N ATA Device |
30 Jun 2010
|
| | Win 7 Ultimate x64 6,700 posts Etobicoke, Ontario |
Following this, How to Remove BankerFox.A
should get rid of it. And for what it's worth the IP address that was reported by that popup, I don't think they were trying to hack your computer, Whois record for 161.40.59.127 | My System Specs | | System Manufacturer/Model Number Me OS Win 7 Ultimate x64 CPU Phenom II x4 955 @ 4 GHz. Motherboard Asus M5A97 EVO Memory 2x2 GB Kingston HyperX DDR3 1600 Graphics Card Sapphire HD 6850 Sound Card Xonar DGX w/ Logitech X-530 Monitor(s) Displays Acer S232HL Abid Screen Resolution 1920x1080 Keyboard Logitech Wave Mouse Logitech G5 v2 PSU Antec Earthwatts 650W Green Case Antec Three Hundred Cooling Cooler Master 212 EVO Hard Drives 120 GB OCZ Vertex 3
500 GB Seagate 7200.12 Internet Speed 24000/1000 |
30 Jun 2010
|
| | Windows 7 Professional x64 SP1 570 posts Calgary |
LOL@the Whois record. Definite win. | My System Specs | | OS Windows 7 Professional x64 SP1 CPU Intel Core i5-2500K Motherboard Gigabyte P67X-UD3-B3 Memory 8 GB Corsair Vengeance Blue DDR3-1600 Graphics Card Sapphire Radeon HD 6870 1 GB GDDR5 Monitor(s) Displays Samsung SyncMaster T220HD Screen Resolution 1680x1050 PSU Corsair 650W Hard Drives 120 GB Corsair Force SSD + 320 GB Seagate Barracuda SATA2 + 2 TB My Book Elite Internet Speed 50 Mbps |
30 Jun 2010
|
| | Windows 2000 5.0 Build 2195 787 posts |
Your link wanted us to download a registry-related program which, based on past experiences, aren't really reliable.
McAfee lists BankerFox.A as a fake malware as per FakeAlert-SpywareProtect
Based on McAfee's data, Microsoft list this similar scenario as caused by Encyclopedia entry: Trojan:Win32/FakeSpypro - Learn more about malware - Microsoft Malware Protection Center | My System Specs | | System Manufacturer/Model Number Asus G73SW-XN2 OS Windows 2000 5.0 Build 2195 CPU Intel Core i7-2630QM@2GHz(2.9GHz Turbo Boost) [Sandy Bridge] Motherboard Asus G73SW (Intel HM65 Chipset) Memory Kingston DDR3 1333 16GB (4GBx4) Graphics Card nVidia GTX 460m 1.5GB Sound Card EAX Advanced HD 5.0, THX TruStudio Monitor(s) Displays 17.3 in. primary & 23 in. secondary Screen Resolution 1920x1080 Keyboard Built-in 102-Key Backlit Keyboard Hard Drives Seagate Momentus XT (SATA II) 500 GB @ 7200 RPM
Hitachi (SATA II) 500GB @ 7200 RPM
Non Raid because ASUS was crappy to choose an HM65 Chipset Other Info It's a Laptop. |
30 Jun 2010
|
| | Windows 7 Ultimate x86 build 7600 (XP, 98SE, 95, 3.11, DOS 7.10 on VM) + Ubuntu 10.04 LTS Lucid Lynx 1,141 posts Chennai, India |
One thing I don't understand, if MSE was not running then where did the popup come from ?? | My System Specs | | Computer type Laptop System Manufacturer/Model Number HP EliteBook 8530w Mobile Workstation OS Windows 7 Ultimate x86 build 7600 (XP, 98SE, 95, 3.11, DOS 7.10 on VM) + Ubuntu 10.04 LTS Lucid Lynx CPU Intel Core 2 Duo Processor P8600 (2.40 GHz, 3 MB L2 cache) Motherboard Mobile Intel PM45 Express Chipset ICH9M-Enhanced Memory 2GB 800 MHz DDR2 SDRAM Graphics Card ATI Mobility FireGL V5700 with 256 MB Sound Card SoundMAX Integrated Digital HD Audio Monitor(s) Displays 15.4-inch WXGA anti-glare (1280 x 800 resolution) Screen Resolution 1280 x 800 Mouse Synaptics PS/2 Port Touchpad, USB Mouse Hard Drives 250GB Fujitsu MJA2250BH G2 ATA Device (IDE),
120GB in External Casing Internet Speed 2 Mbps Antivirus MSE Browser Firefox, Chrome, IE Other Info Authentec AES2810 Fingerprint Reader,
Optiarc DVD RW AD-7561S LightScribe |
30 Jun 2010
|
| | Windows 2000 5.0 Build 2195 787 posts |
It has to be one of those websites were they trick you in to installing rogue anti-virus malware. See my first link, some screenshots are there. | My System Specs | | System Manufacturer/Model Number Asus G73SW-XN2 OS Windows 2000 5.0 Build 2195 CPU Intel Core i7-2630QM@2GHz(2.9GHz Turbo Boost) [Sandy Bridge] Motherboard Asus G73SW (Intel HM65 Chipset) Memory Kingston DDR3 1333 16GB (4GBx4) Graphics Card nVidia GTX 460m 1.5GB Sound Card EAX Advanced HD 5.0, THX TruStudio Monitor(s) Displays 17.3 in. primary & 23 in. secondary Screen Resolution 1920x1080 Keyboard Built-in 102-Key Backlit Keyboard Hard Drives Seagate Momentus XT (SATA II) 500 GB @ 7200 RPM
Hitachi (SATA II) 500GB @ 7200 RPM
Non Raid because ASUS was crappy to choose an HM65 Chipset Other Info It's a Laptop. |
30 Jun 2010
|
| | Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86 5,148 posts |
Scan with Malwarebytes and Spybot. | My System Specs | | System Manufacturer/Model Number Too many to describe... OS Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86 |
01 Jul 2010
|
| | win 7 pro upgrade disc set running 64 bit 12 posts |
I thank all of you for your knowledge, i am downloading the file and hopefully kill whatever it is. MSE was running at the time of the first pop-up window i believe the pop-up window was responsible for disabling MSE and the prompt (admin) was lame also you could type sfc /scannow and enter but it would not run, chkdsk /f also as arkhi said the reason for it is to have you buy it out of fear, both times i i rebooted it went back into hiding i suppose i do know both times i was using goggle and again both time i was looking at the choices of my search motor mounts for a neon. the program kept asking if i wanted it to turn on my anti-virus program each time i would (x) close it but when i try and start MSE this banker thing rendered it useless and another pop-up would claim the exe file is corrupt and again ask to turn on virus. i thank you all very much and i will do as you have suggested. thanks | My System Specs | | System Manufacturer/Model Number msi ms-7549 OS win 7 pro upgrade disc set running 64 bit CPU amd Phenom II x 4 B50 processor 3.10 GHz Motherboard 785gtm-e45 main board Memory 4.0 GB Graphics Card radeon 4200 Sound Card Realtech High Definition Audio Monitor(s) Displays hp 2009m @ 1024x768 256 MB Standard VGA Graphics Adapter Keyboard Standard PS/2 Keyboard, HID keyboard device Mouse PS/2 Compatible Mouse, HID-compliant mouse Case desktop Hard Drives 160 GB Hitachi HtS541616J9SA00 ATA Device (IDE) 96 F
500 GB Hitachi HtS545050B9A300 ATA Device (IDE) 112 F
3GB SD Memory Card (NULL) Internet Speed Sprint Broadband sierra wirerless usb modem 595u Other Info HL-DT-ST DVD+ -RW GSA-T21N ATA Device |
01 Jul 2010
|
| | Windows 7 & Windows Vista Ultimate 2,476 posts Upstate NY |
Hi, Hollywood2. Another name for the rogue is Antivirus Soft. See the removal guide at Bleeping Computer: Remove Antivirus Soft. | My System Specs | | OS Windows 7 & Windows Vista Ultimate 161.40.59.127 attacked port 13567 BankerfoxA problems? All times are GMT -5. The time now is 01:52 PM. | |