Associated Malware Groups
The filename is associated with the malware group:
- Fraudulent Security Program
File Behavior
SALVANDO-USB[1].EXE has been seen to perform the following behavior:
- This process creates other processes on disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- This Process Deletes Other Processes From Disk
- Injects code into other processes
- Copies files
- Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
- Uses Instant Messaging to communicate without the user's knowledge
- Uses embeded Instant Message Channel Settings
- Found on infected systems and resists interrogation by security products
SALVANDO-USB[1].EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Terminated as a Process
- Copied to multiple locations on the system
Country Of Origin
The filename SALVANDO-USB[1].EXE was first seen on Nov 19 2009 in the following geographical regions of the Prevx community:
- Peru on Nov 19 2009
- Chile on Nov 19 2009
- Italy on Nov 21 2009
- The United States on Nov 21 2009
- Venezuela on Dec 4 2009
File Name Aliases
SALVANDO-USB[1].EXE can also use the following file names:
- CONMSYRTL.EXE
- ERASEME_38814.EXE
- ERASEME_74388.EXE
- ERASEME_81503.EXE
- ERASEME_28380.EXE
- ERASEME_03658.EXE
- ERASEME_16287.EXE
- ERASEME_30860.EXE
- ERASEME_23366.EXE
- ERASEME_86440.EXE
- ERASEME_72362.EXE
- ERASEME_22627.EXE
- ERASEME_03856.EXE
- ERASEME_78257.EXE
- ERASEME_13815.EXE
- ERASEME_10612.EXE
- ERASEME_28777.EXE
- ERASEME_36660.EXE
- ERASEME_02234.EXE
- ERASEME_35356.EXE
- ERASEME_62663.EXE
- ERASEME_30045.EXE
- ERASEME_53855.EXE
- ERASEME_42828.EXE
- ERASEME_22401.EXE
- ERASEME_75381.EXE
- ERASEME_81400.EXE
- ERASEME_42326.EXE
- ERASEME_85824.EXE
- ERASEME_45324.EXE
- ERASEME_75477.EXE
- ERASEME_20364.EXE
- ERASEME_04886.EXE
- ERASEME_42453.EXE
- ERASEME_31853.EXE
- ERASEME_32627.EXE
- ERASEME_10667.EXE
- ERASEME_84481.EXE
- ERASEME_37530.EXE
- ERASEME_85837.EXE
- ERASEME_13205.EXE
- ERASEME_30708.EXE
- ERASEME_12025.EXE
- ERASEME_12648.EXE
- ERASEME_50348.EXE
- ERASEME_60302.EXE
- ERASEME_66217.EXE
- ERASEME_67830.EXE
Filesizes
The following file size has been seen:
- 101,623 bytes
- 101,517 bytes
- 153,250 bytes
File Type
The filename SALVANDO-USB[1].EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.