Associated Malware Groups
The filename is associated with the malware group:
File Behavior
SALVANDO[1].EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- This process creates other processes on disk
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- This Process Deletes Other Processes From Disk
- Injects code into other processes
- Copies files
- Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
SALVANDO[1].EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Copied to multiple locations on the system
Country Of Origin
The filename SALVANDO[1].EXE was first seen on Nov 3 2009 in the following geographical regions of the Prevx community:
- MEXICO on Nov 3 2009
- PERU on Nov 17 2009
- GREAT BRITAIN on Nov 17 2009
File Name Aliases
SALVANDO[1].EXE can also use the following file names:
- CONMSYRTL.EXE
- ERASEME_65576.EXE
- ERASEME_26035.EXE
- ERASEME_30310.EXE
- ERASEME_52365.EXE
- ERASEME_42677.EXE
- ERASEME_11157.EXE
- ERASEME_86327.EXE
- ERASEME_83740.EXE
- MSNHACKS.EXE
- IMAGE.SCR
- PORNO.MPEG.EXE
- LIMEWIRECRACK.EXE
- RAPIDSHAREPREMIUM.EXE
- WILDHORNEYTEENS.SCR
- EBOOKS.EXE
- HOW-TO-MAKE-MONEY.EXE
- SCREENMELTER.EXE
- DDOSPING.EXE
- WIRESHARK.EXE
- AUTOLOADER.EXE
- YAHOOCRACKER.EXE
- PARIS-HILTON.SCR
- FREEPORN.EXE,FUCKSHITCUNT.SCR
- ILOVETOFUCK.SCR
- HEADJOBS.SCR
- PORNO.SCR
- VISTAULTIMATE-CRACK.EXE
- HOTMAILHACKER.EXE
- ERASEME_71767.EXE
Filesizes
The following file size has been seen:
- 284,817 bytes
- 105,370 bytes
File Type
The filename SALVANDO[1].EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.