Win64/Sathurbot.A
Posted: August 28, 2014
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 14,817 |
---|---|
Threat Level: | 8/10 |
Infected PCs: | 8,040 |
First Seen: | August 28, 2014 |
---|---|
Last Seen: | September 24, 2023 |
OS(es) Affected: | Windows |
Win64/Sathurbot.A is a Trojan horse infection that could load up through malicious sources on the internet. When loaded, Win64/Sathurbot.A is apt to running in the background were it may not be detected and it is able to perform malicious functions. Those functions could include opening up a backdoor where remote attackers can gain access to the infected system. This puts stored information and data on the hard drove of a system infected with Win64/Sathurbot.A at serious risk and could lead to issues like identity theft. It is very important to keep a system suspected to be infected with Win64/Sathurbot.A protected with the proper software. In addition, it is prudent that Win64/Sathurbot.A be safely detected and removed with an advanced antispyware tool capable of detecting and eliminating Trojan horse threats on Windows PCs.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp56AB.exe
File name: tmp56AB.exeSize: 121.34 KB (121344 bytes)
MD5: e9f9d813cefd9815a833179a21ef6074
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpA10B.exe
File name: tmpA10B.exeSize: 133.17 KB (133172 bytes)
MD5: dfb64c158b59d0d1a7dabd5576191c9e
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpAB40.exe
File name: tmpAB40.exeSize: 174.63 KB (174633 bytes)
MD5: b2ab8483df8c50ce52a54e80d1161033
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpFDBD.exe
File name: tmpFDBD.exeSize: 160.51 KB (160518 bytes)
MD5: 947850ea31b0746472d8f426139649dc
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp7EBD.exe
File name: tmp7EBD.exeSize: 117.56 KB (117561 bytes)
MD5: 7c18bc310ff85465400e2b9b0d2b1280
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpF9F4.exe
File name: tmpF9F4.exeSize: 183.34 KB (183346 bytes)
MD5: 6658bc1fb00fac2229955523f0f58400
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: May 8, 2020
C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll
File name: PerformanceMonitor.dllSize: 4.85 MB (4851200 bytes)
MD5: 555628cc5f5dac4b37fd1a87527b24c6
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll
Group: Malware file
Last Updated: April 5, 2021
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp6C20.exe
File name: tmp6C20.exeSize: 110.96 KB (110960 bytes)
MD5: 03871146d11281fb31599a47f4d26180
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll
File name: PerformanceMonitor.dllSize: 4.89 MB (4891648 bytes)
MD5: 1d8ae7e0cc2d42a3fa4cfda7b542028b
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll
Group: Malware file
Last Updated: April 7, 2021
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpFE80.exe
File name: tmpFE80.exeSize: 165.88 KB (165887 bytes)
MD5: 8e04a81b7d2564131d95b3fddfa67666
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp869E.exe
File name: tmp869E.exeSize: 150.58 KB (150587 bytes)
MD5: 1e710904d65e5f037eb504ae75133f36
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpB546.exe
File name: tmpB546.exeSize: 334.84 KB (334848 bytes)
MD5: 5f8ddf99f1438b6138b5c4f2e0245ce8
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp4EDC.exe
File name: tmp4EDC.exeSize: 335.36 KB (335360 bytes)
MD5: baca6c3316a4a83c5c3e0c021a899441
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%LOCALAPPDATA%\Microsoft\Performance\Monitor\PerformanceMonitor.dll
File name: PerformanceMonitor.dllSize: 4.85 MB (4859904 bytes)
MD5: 4c9a3490caa3da083aee06929907b81e
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\Performance\Monitor
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp1938.exe
File name: tmp1938.exeSize: 117.56 KB (117561 bytes)
MD5: 63a45cd50a19520fbce8ba0057d489eb
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\TheftProtection\temp\tmp74F.exe
File name: tmp74F.exeSize: 117.56 KB (117561 bytes)
MD5: 6b4943b8654562d7cc816b8659955090
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\TheftProtection\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp4430.exe
File name: tmp4430.exeSize: 168.94 KB (168942 bytes)
MD5: 68c25c12336f747848d08b5fc8022987
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp6114.exe
File name: tmp6114.exeSize: 128.48 KB (128486 bytes)
MD5: 5ad5e4365c8c56850925517e0cd5c028
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp3B13.exe
File name: tmp3B13.exeSize: 117.56 KB (117561 bytes)
MD5: 5c71561673cf37415ff06c5b478f1b70
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%LOCALAPPDATA%\Microsoft\Performance\Monitor\PerformanceMonitor.dll
File name: PerformanceMonitor.dllSize: 4.01 MB (4012544 bytes)
MD5: dda59260d82030b93c5e1bb2f210e827
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\Performance\Monitor
Group: Malware file
Last Updated: March 18, 2017
%LOCALAPPDATA%\Microsoft\Performance\Monitor\PerformanceMonitor.dll
File name: PerformanceMonitor.dllSize: 4.04 MB (4046336 bytes)
MD5: baf7226787d374f300dfdda3307b8553
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\Performance\Monitor
Group: Malware file
Last Updated: March 18, 2017
%UserProfile%\Programs\ AppData\roaming\[Random Charateristc].dll
File name: %UserProfile%\Programs\ AppData\roaming\[Random Charateristc].dllFile type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Programs\Temp\[Random Charateristc].dll
File name: %UserProfile%\Programs\Temp\[Random Charateristc].dllFile type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Programs\ AppData \[Random Charateristc].exe
File name: %UserProfile%\Programs\ AppData \[Random Charateristc].exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
More files
Registry Modifications
Regexp file mask%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\SecurityHelper.dll%ALLUSERSPROFILE%\Microsoft\Security\Client\SecurityHelper.dll%PUBLIC%\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exeHKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run""= "%AppData%\.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run""= "%AppData%\.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes"=".random”
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.