Remove Satiloler.f. Description and removal instructions

 
Title: Satiloler.f

Type: Trojans
Severity scale:Satiloler.f severity is 80  (80 / 100)
 
Satiloler.f is a trojan designed to steal user sensitive information. Once executed, the parasite silently installs itself to the system, overwrites system files with own copies, disables Windows essential tools and components, terminates some running antiviruses, firewalls, browsers and system utilities. Satiloler.f runs an integrated keylogger, which records various login names, passwords and e-mail profile details. It also tracks user Internet activity, records web sites visited, steals system information and logs all the data that the user enters on banking web sites. Furthermore, the trojan captures screenshots of active browser windows in attempt to steal credit card numbers, specific codes and other confidential banking details. It transfers gathered data to a predetermined web server. Satiloler.f uses an integrated rootkit to hide itself from the user and security-related software. The parasite is able to bypass the Windows Firewall and update itself via the Internet. It runs on every Windows startup.


Satiloler.f properties:
• Takes and sends out screenshots of user activity
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Satiloler.f removal:

remover for Satiloler.f

Satiloler.f manual removal:

Kill processes:
ctfmon.exe, lsass.exe, tml_[X].exe, userinit.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\system
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=%System%\init.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable=FFFFFF9D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCScan=0
HKEY_CURRENT_USER\Software\ver
HKEY_CURRENT_USER\Software\vs
HKEY_CURRENT_USER\Software\Microsoft\x
Delete files:
ctfmon.exe, lsass.exe, tml_[X].exe, userinit.exe, init.dll, sfc.dll, sfc_os.dll, xvid.dll, ip.sys, divx.ini, xvid.ini, bkup.reg
Misc:
[X] is a combination of random characters.

Exact file location:
bkup.reg - C:
tml_[X].exe - C:\Windows\Temp or C:\Winnt\Temp
lsass.exe - C:\Program Files\Common Files\System
ip.sys - C:\Windows\System\Drivers, C:\Windows\System32\Drivers or C:\Winnt\System32\Drivers
ctfmon.exe, userinit.exe, init.dll, sfc.dll, sfc_os.dll, xvid.dll, divx.ini, xvid.ini - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Satiloler.f:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 13/04/06
Information updated: 13/04/06

Additional resources related to Satiloler.f:

Attention: If you know or you have a website or page about Satiloler.f removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Satiloler.f parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: