Home Malware Programs Trojans Win64/Sathurbot.A

Win64/Sathurbot.A

Posted: August 28, 2014

Threat Metric

Ranking: 14,817
Threat Level: 8/10
Infected PCs: 8,040
First Seen: August 28, 2014
Last Seen: September 24, 2023
OS(es) Affected: Windows


Win64/Sathurbot.A is a Trojan horse infection that could load up through malicious sources on the internet. When loaded, Win64/Sathurbot.A is apt to running in the background were it may not be detected and it is able to perform malicious functions. Those functions could include opening up a backdoor where remote attackers can gain access to the infected system. This puts stored information and data on the hard drove of a system infected with Win64/Sathurbot.A at serious risk and could lead to issues like identity theft. It is very important to keep a system suspected to be infected with Win64/Sathurbot.A protected with the proper software. In addition, it is prudent that Win64/Sathurbot.A be safely detected and removed with an advanced antispyware tool capable of detecting and eliminating Trojan horse threats on Windows PCs.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp56AB.exe File name: tmp56AB.exe
Size: 121.34 KB (121344 bytes)
MD5: e9f9d813cefd9815a833179a21ef6074
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpA10B.exe File name: tmpA10B.exe
Size: 133.17 KB (133172 bytes)
MD5: dfb64c158b59d0d1a7dabd5576191c9e
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpAB40.exe File name: tmpAB40.exe
Size: 174.63 KB (174633 bytes)
MD5: b2ab8483df8c50ce52a54e80d1161033
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpFDBD.exe File name: tmpFDBD.exe
Size: 160.51 KB (160518 bytes)
MD5: 947850ea31b0746472d8f426139649dc
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp7EBD.exe File name: tmp7EBD.exe
Size: 117.56 KB (117561 bytes)
MD5: 7c18bc310ff85465400e2b9b0d2b1280
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpF9F4.exe File name: tmpF9F4.exe
Size: 183.34 KB (183346 bytes)
MD5: 6658bc1fb00fac2229955523f0f58400
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: May 8, 2020
C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll File name: PerformanceMonitor.dll
Size: 4.85 MB (4851200 bytes)
MD5: 555628cc5f5dac4b37fd1a87527b24c6
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll
Group: Malware file
Last Updated: April 5, 2021
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp6C20.exe File name: tmp6C20.exe
Size: 110.96 KB (110960 bytes)
MD5: 03871146d11281fb31599a47f4d26180
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll File name: PerformanceMonitor.dll
Size: 4.89 MB (4891648 bytes)
MD5: 1d8ae7e0cc2d42a3fa4cfda7b542028b
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\Microsoft\Performance\Monitor\PerformanceMonitor.dll
Group: Malware file
Last Updated: April 7, 2021
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpFE80.exe File name: tmpFE80.exe
Size: 165.88 KB (165887 bytes)
MD5: 8e04a81b7d2564131d95b3fddfa67666
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp869E.exe File name: tmp869E.exe
Size: 150.58 KB (150587 bytes)
MD5: 1e710904d65e5f037eb504ae75133f36
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmpB546.exe File name: tmpB546.exe
Size: 334.84 KB (334848 bytes)
MD5: 5f8ddf99f1438b6138b5c4f2e0245ce8
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp4EDC.exe File name: tmp4EDC.exe
Size: 335.36 KB (335360 bytes)
MD5: baca6c3316a4a83c5c3e0c021a899441
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%LOCALAPPDATA%\Microsoft\Performance\Monitor\PerformanceMonitor.dll File name: PerformanceMonitor.dll
Size: 4.85 MB (4859904 bytes)
MD5: 4c9a3490caa3da083aee06929907b81e
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\Performance\Monitor
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp1938.exe File name: tmp1938.exe
Size: 117.56 KB (117561 bytes)
MD5: 63a45cd50a19520fbce8ba0057d489eb
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\TheftProtection\temp\tmp74F.exe File name: tmp74F.exe
Size: 117.56 KB (117561 bytes)
MD5: 6b4943b8654562d7cc816b8659955090
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\TheftProtection\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp4430.exe File name: tmp4430.exe
Size: 168.94 KB (168942 bytes)
MD5: 68c25c12336f747848d08b5fc8022987
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp6114.exe File name: tmp6114.exe
Size: 128.48 KB (128486 bytes)
MD5: 5ad5e4365c8c56850925517e0cd5c028
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp\tmp3B13.exe File name: tmp3B13.exe
Size: 117.56 KB (117561 bytes)
MD5: 5c71561673cf37415ff06c5b478f1b70
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Performance\Monitor\temp
Group: Malware file
Last Updated: March 18, 2017
%LOCALAPPDATA%\Microsoft\Performance\Monitor\PerformanceMonitor.dll File name: PerformanceMonitor.dll
Size: 4.01 MB (4012544 bytes)
MD5: dda59260d82030b93c5e1bb2f210e827
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\Performance\Monitor
Group: Malware file
Last Updated: March 18, 2017
%LOCALAPPDATA%\Microsoft\Performance\Monitor\PerformanceMonitor.dll File name: PerformanceMonitor.dll
Size: 4.04 MB (4046336 bytes)
MD5: baf7226787d374f300dfdda3307b8553
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\Performance\Monitor
Group: Malware file
Last Updated: March 18, 2017
%UserProfile%\Programs\ AppData\roaming\[Random Charateristc].dll File name: %UserProfile%\Programs\ AppData\roaming\[Random Charateristc].dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Programs\Temp\[Random Charateristc].dll File name: %UserProfile%\Programs\Temp\[Random Charateristc].dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Programs\ AppData \[Random Charateristc].exe File name: %UserProfile%\Programs\ AppData \[Random Charateristc].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Microsoft\Performance\Monitor\SecurityHelper.dll%ALLUSERSPROFILE%\Microsoft\Security\Client\SecurityHelper.dll%PUBLIC%\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exeHKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run""= "%AppData%\.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run""= "%AppData%\.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes"=".random”
Loading...