Home Malware Programs Trojans Trojan.BestaFera

Trojan.BestaFera

Posted: May 25, 2016

Threat Metric

Threat Level: 8/10
Infected PCs: 4,265
First Seen: May 25, 2016
Last Seen: April 23, 2022
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\Google\Update\drive.exe File name: drive.exe
Size: 2.32 MB (2329600 bytes)
MD5: 1eb1d4defc3379bb5501e6b6d4dd2b35
Detection count: 330
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Google\Update
Group: Malware file
Last Updated: May 25, 2016
%APPDATA%\Microsoft\Internet Explorer\RtkAudioService64.exe File name: RtkAudioService64.exe
Size: 6.89 MB (6898176 bytes)
MD5: cbcf9c4528f58e42991a1da7b46148b8
Detection count: 281
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Internet Explorer
Group: Malware file
Last Updated: November 18, 2016
%ALLUSERSPROFILE%\HdVQIAudio\RAudioServTq64.exe File name: RAudioServTq64.exe
Size: 3.34 MB (3346944 bytes)
MD5: 09f18a0fdc07b2582843252ec7b35f2d
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\HdVQIAudio
Group: Malware file
Last Updated: September 16, 2017
%APPDATA%\MicrosoftCorporation.exe File name: MicrosoftCorporation.exe
Size: 3.85 MB (3853312 bytes)
MD5: 03585ca698ae4d9f2b2beac98bcb11c2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: July 1, 2017
%ALLUSERSPROFILE%\HdVQIAudio\WindowsUpdate_6.0_KB934307_x86_msu.exe File name: WindowsUpdate_6.0_KB934307_x86_msu.exe
Size: 1.58 MB (1589760 bytes)
MD5: 882b4c3e731bbf44786cbbe31f9c09d8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\HdVQIAudio
Group: Malware file
Last Updated: September 16, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Microsoft\Internet Explorer\RtkAudioService64.exe

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\ApplicationFrameWindows%ALLUSERSPROFILE%\HdVQIAudio
Loading...