Backdoor

About “Backdoor:Win32/Sathenvir.A” infection

Malware Removal

The Backdoor:Win32/Sathenvir.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Sathenvir.A virus can do?

  • Executable code extraction
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Sathenvir.A?


File Info:

crc32: 18C2E645
md5: c832948160402e6ff97bfaaf0f3097c6
name: C832948160402E6FF97BFAAF0F3097C6.mlw
sha1: 1d2ed0493dee3532761a8ac2a0f51e4c638c335f
sha256: ddcf2b6654b2afceb0c5a4a9205f6941c5ce3e3e37b1d6610455453d23c7a884
sha512: c8c0886149ad541aa1d6e3631ac8d881097f31cc550629d6b17cc1daadbeefe62372ee784c9eddb4949494acafc1132f0906851a1460ab1eaa365a917f76e44a
ssdeep: 3072:wuxzRtE2eSe5A0sdfCC4aJU+PuLFuBEoW2:PjtEFF2p4aJVWLF4z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: teta
FileVersion: 1.00
CompanyName: Microsoft
ProductName: prjRATServer
ProductVersion: 1.00
OriginalFilename: teta.exe

Backdoor:Win32/Sathenvir.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaike.1243
FireEyeGeneric.mg.c832948160402e6f
CAT-QuickHealTrojan.VBCrypt.MF.8944
ALYacGen:Variant.Jaike.1243
CylanceUnsafe
ZillyaBackdoor.VB.Win32.6997
AlibabaBackdoor:Win32/VBKrypt.a846817f
Cybereasonmalicious.160402
BitDefenderThetaGen:NN.ZevbaF.34804.jm1@aWGf4boi
CyrenW32/Hupigon.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
BaiduWin32.Trojan.VB.jq
APEXMalicious
AvastWin32:VB-LGC [Trj]
ClamAVWin.Dropper.Zusy-6519829-0
BitDefenderGen:Variant.Jaike.1243
NANO-AntivirusTrojan.Win32.VB.ddfwoq
ComodoBackdoor@#2enh4ls16av6c
DrWebTrojan.DownLoader6.53846
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroBKDR_RSHOT.SMA
SophosML/PE-A + Mal/Behav-246
IkarusBackdoor.Win32.Sathenvir
JiangminTrojan.VBKrypt.bedc
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Jaike.D4DB
ZoneAlarmTrojan.Win32.VBKrypt.wlsp
MicrosoftBackdoor:Win32/Sathenvir.A
CynetMalicious (score: 90)
McAfeeArtemis!C83294816040
VBA32Trojan.VBKrypt
ESET-NOD32a variant of Win32/VB.NGV
TrendMicro-HouseCallBKDR_RSHOT.SMA
YandexTrojan.GenAsa!3QzhwH3Ggfw
SentinelOneStatic AI – Malicious PE – Worm
eGambitGeneric.Malware
FortinetW32/VB.ISL!tr.bdr
AVGWin32:VB-LGC [Trj]
PandaAdware/AccesMembre
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.0B1B.Malware.Gen

How to remove Backdoor:Win32/Sathenvir.A?

Backdoor:Win32/Sathenvir.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment