Vosteran

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 1,762
Threat Level: 50 % (Medium)
Infected Computers: 73,417
First Seen: October 13, 2014
Last Seen: September 20, 2023
OS(es) Affected: Windows

The Vosteran malware should not be mistaken for the Vosteran.com browser hijacker because they differ greatly. While the Vosteran.com browser hijacker may cause annoyance and load several tabs with promotions in your browser, the Vosteran malware may prevent users from accessing their desktop at all times. Security experts report that the Vosteran Trojan may be deployed to users by means of free software packages and fake updates for Google Chrome. Some experts use the tag Deep Vosteran to distinguish the Trojan from the browser hijacker mentioned above. The Vosteran Trojan is a severe threat that is similar to Sirefef, Basutra and Ircbrute that upon infection may initiate a restart on the victim's PC automatically. Moreover, the Vosteran Trojan may substitute the installations of Google Chrome with a corrupted version of the Google's browser that might be listed in the 'Programs and Features' panel as Vosteran.

Deep Vosteran may install other programs like WS_Vosteran, Arcade Giant and StormWatch that are recognized as adware and might use your system resources for Bitcoin mining and cloud-computing. The corrupted Vosteran browser seems to serve one purpose—that is to show numerous advertisements. Also, the Vosteran browser may become the default Internet client of users that are infected with the Deep Vosteran malware. The Vosteran Trojan may write several registry keys to cement its infiltration, welcome users to browse the Internet without protection and display advertisements to earn affiliate marketing revenue for its creators.

In many cases, the Deep Vosteran malware may disable the taskbar of the Windows systems and load the Vosteran browser during system startup to direct users to sponsored websites and wait for users to input their credit card data. The disappearance of your Taskbar should be enough for you to abstain from using the corrupted browser associated with the Deep Vosteran malware. Security experts note that bootable USBs and rescue disks may not help users to remove the Vosteran Trojan. The proper strategy to follow when addressing the Vosteran malware is to install a reputable anti-malware utility and run a security scan.

SpyHunter Detects & Remove Vosteran

File System Details

Vosteran may create the following file(s):
# File Name MD5 Detections
1. bkup.dat 1f032b23dadb1e50c84beef698d49713 55
2. UpdateTask.exe 81714713107c861bdecb16ff5e150763 55
3. UpdateTask.exe 1e6eca0bc6a58c9dac3dd93628228080 45
4. bkup.dat 9bb829d43653349012133f5c13479436 41
5. bkup.dat 606b76ec1bc1c07dc2225631df15c234 28
6. bkup.dat a109c316b7d28ce552cd4a79bc47fb68 28
7. UpdateTask.exe e2d3fb36651c0e44f1174da387fa52bf 22
8. bkup.dat 6224f3ab10246c76ee37bb2f6d64c8d4 21
9. bkup.dat 1db2c76685ab9be965a623ea52cf3d0d 19
10. bkup.dat 9d5e0f13243766e6d11d1a0a1460755a 18
11. bkup.dat b8e05d78a75eadf2cad33f5ae8675040 13
12. bkup.dat 318948ab544a9b45916c205c98093e9e 13
13. bkup.dat 2ee57463815b90bc8babdc57f4d3aa73 12
14. UpdateTask.exe 6695bc2a98d91d49386af14d52d0e9a2 11
15. UpdateTask.exe d489605d403867b778fe55728481029d 10
16. UpdateTask.exe 6311c9f5fdb5a5c300084f353b39ea77 9
17. UpdateTask.exe 2ca746ce57e7eb879c82ee25399496c2 8
18. UpdateTask.exe a8540eda05b58ac73e2ef6983f1a20cb 6
19. vosteran.exe 9b986c9f99a099605471b05e1fadf61f 4
20. vosteran.exe ae8f905d39ca149695accaca6864db25 3
21. vosteran.exe 123f683c6e79bc559f95e863a241a398 2
22. vosteran.exe f20f903560666166700da7726b8dcc98 2
23. vosteran.exe 4f570dc695159d5a895d78ed0b0174ee 1
24. vosteran.exe 90ff41413233cb0f101edfc5d42794cd 1
25. vosteran.exe b2914b18c9c179fff894e42544b64e8c 1
26. vosteran.exe 6253b94773983ec33085b19c111183ed 1
27. vosteran.exe 80326c7c52d474dfc2586f3d0287fc24 1
28. vosteran.exe dc5bc01095d32e9409fbd82c09721378 1
29. wow_helper.exe
30. C:\Users\\appdata\local\vosteran\application\vosteran.exe 944a91af08bbed92bd0abc81203042a9
31. "C:\Users\\appdata\Local\Vosteran\Application\31.0.1650.23\Installer\setup.exe" --uninstall
32. chrome.dll
33. chrome_child.dll
34. npchrome_frame.dll
35. am.dll
36. ar.dll
37. bg.dll
38. bn.dll
39. ca.dll
40. chrome_frame_helper.dll
41. chrome_frame_helper.exe
42. chrome_launcher.exe
43. cs.dll
44. d3dcompiler_46.dll
45. da.dll
46. de.dll
47. delegate_execute.exe
48. el.dll
49. en-GB.dll
50. en-US.dll
51. es.dll
52. es-419.dll
53. et.dll
54. fa.dll
55. ffmpegsumo.dll
56. fi.dll
57. fil.dll
58. fr.dll
59. gu.dll
60. he.dll
61. hi.dll
62. hr.dll
63. icudt.dll
64. id.dll
65. it.dll
66. ja.dll
67. kn.dll
68. libegl.dll
69. libglesv2.dll
70. metro_driver.dll
71. nacl64.exe
72. ppgooglenaclpluginchrome.dll
73. hu.dll
More files

Registry Details

Vosteran may create the following registry entry or registry entries:
CLSID
{0A6B3C37-2EC3-508F-435B-7567673389FF}
{4CB3598A-82E8-4D1F-983F-061238AE696E}
File name without path
Vosteran.lnk
Software\Microsoft\Internet Explorer\DOMStorage\vosteran.com
Software\Microsoft\Internet Explorer\SearchScopes\{9E20EB26-0B53-4159-9FC6-F2ACA85DF167}
SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\vosteran.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Vosteran
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\vosteran.exe
Software\Microsoft\Windows\CurrentVersion\RunOnce\WSE_Vosteran
SOFTWARE\RegisteredApplications\Vosteran.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Vosteran
Software\Vosteran Browser
SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\vosteran.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\vosteran.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\WSE_Vosteran
SOFTWARE\Wow6432Node\RegisteredApplications\Vosteran.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\wse_vosteran

Directories

Vosteran may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Vosteran
%APPDATA%\Vosteran
%APPDATA%\WSE_Vosteran
%LOCALAPPDATA%\Vosteran
%PROGRAMFILES%\WSE_Vosteran
%PROGRAMFILES(x86)%\WSE_Vosteran
%UserProfile%\Local Settings\Application Data\Vosteran

URLs

Vosteran may call the following URLs:

http://vosteran.com/?
http://vosteran.com/?a=&q

Related Posts

Trending

Most Viewed

Loading...