Trojan

Trojan-Banker.Win32.BestaFera.bcl removal instruction

Malware Removal

The Trojan-Banker.Win32.BestaFera.bcl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.BestaFera.bcl virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Trojan-Banker.Win32.BestaFera.bcl?


File Info:

name: 167AE2AC3B98110040A5.mlw
path: /opt/CAPEv2/storage/binaries/3d56e0863f6119ca61f6c656eb9740b695c7311e122cd051f6b6b7b979c38a56
crc32: 8A487C1A
md5: 167ae2ac3b98110040a517c7c89f4e70
sha1: 19620b23bde2ffd73c16a222e149ecad7e725310
sha256: 3d56e0863f6119ca61f6c656eb9740b695c7311e122cd051f6b6b7b979c38a56
sha512: b04f1703bdc7813993aad54c7bd6791609c5f30660aeb851c319751402a12b11c66b6907defbe55d16271b816521f29736443638460705c97217f12ec6dce538
ssdeep: 12288:Lqcj9dP5OifGHNC9ixSz9Q8zBP0wP4j3GAiW0Th:rpvOifGHNUi8GEPjP4j3GAiTh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134B47E23F6E08537D13729789C1B97F8682A7E107D28988F3BE43D4D5F39681392A197
sha3_384: b5952c3e5f934a6fc1176e2b5989614539ab0879665b4520a3ee3dd7a896dd5142b9fe70e31fd33193d5ff8ba8847505
ep_bytes: 558bec83c4f0b86c8e4600e8e0c0f9ff
timestamp: 2012-01-10 13:44:09

Version Info:

0: [No Data]

Trojan-Banker.Win32.BestaFera.bcl also known as:

LionicTrojan.Win32.BestaFera.7!c
MicroWorld-eScanTrojan.GenericKD.38092467
FireEyeTrojan.GenericKD.38092467
ALYacTrojan.GenericKD.38092467
ZillyaTrojan.BestaFera.Win32.7095
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanBanker:Win32/BestaFera.dbd17209
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3bde2f
BitDefenderThetaGen:NN.ZelphiCO.34062.GKW@aiDLtTji
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Banker.Win32.BestaFera.bcl
BitDefenderTrojan.GenericKD.38092467
NANO-AntivirusTrojan.Win32.BestaFera.dxsncw
AvastFileRepMalware
RisingTrojan.Generic@ML.87 (RDML:w5sSpfeIeK/bj0pchcKF7g)
Ad-AwareTrojan.GenericKD.38092467
EmsisoftTrojan.GenericKD.38092467 (B)
TrendMicroTROJ_GEN.R002C0PKP21
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
SophosMal/Generic-S
IkarusTrojan.Spy.BestaFera
GDataWin32.Trojan.Agent.Z18M5T
JiangminTrojan.Banker.BestaFera.by
WebrootW32.Bestafera
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.16D6C19
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Bestafera.537600
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeGenericR-GQR!167AE2AC3B98
VBA32TrojanBanker.BestaFera
TrendMicro-HouseCallTROJ_GEN.R002C0PKP21
TencentMalware.Win32.Gencirc.11493e95
YandexTrojan.GenAsa!lxxcW4FsClg
FortinetW32/PossibleThreat
AVGFileRepMalware
PandaTrj/CI.A

How to remove Trojan-Banker.Win32.BestaFera.bcl?

Trojan-Banker.Win32.BestaFera.bcl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment