Solved! Use SALV.EXE (Unknown) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SALV.EXE – Unknown removal

SALV.EXE size: 71184 bytes
SALV.EXE hash: 0E9BE256A4F036D5A32DF46BC99798DE

Created files:

%TEMP%\IXP000.TMP\adapt.dll
%TEMP%\IXP000.TMP\adaptres.dll
%TEMP%\IXP000.TMP\autoupdt.dll
%TEMP%\IXP000.TMP\bbdll.dll
%TEMP%\IXP000.TMP\binrsrc.dll
%TEMP%\IXP000.TMP\compdll.dll
%TEMP%\IXP000.TMP\copymar.exe
%TEMP%\IXP000.TMP\ctl1.dll
%TEMP%\IXP000.TMP\daupdate.exe
%TEMP%\IXP000.TMP\dlxres.dll
%TEMP%\IXP000.TMP\inv2008.ocx
%TEMP%\IXP000.TMP\marble.dll
%TEMP%\IXP000.TMP\mcmoney.dll
%TEMP%\IXP000.TMP\mnyadv.dll
%TEMP%\IXP000.TMP\mnybb.exe
%TEMP%\IXP000.TMP\mnybbsvc.exe
%TEMP%\IXP000.TMP\mnyimprt.exe
%TEMP%\IXP000.TMP\mnymetal.dll
%TEMP%\IXP000.TMP\mnymtllc.dll
%TEMP%\IXP000.TMP\mnyob99.dll
%TEMP%\IXP000.TMP\mnysetup.dll
%TEMP%\IXP000.TMP\mnysl08.dll
%TEMP%\IXP000.TMP\mnysvc08.dll
%TEMP%\IXP000.TMP\mnyxml.dll
%TEMP%\IXP000.TMP\mscofd08.dll
%TEMP%\IXP000.TMP\mscps.dll
%TEMP%\IXP000.TMP\msidcrl4.dll
%TEMP%\IXP000.TMP\msmoney.exe
%TEMP%\IXP000.TMP\msofd.dll
%TEMP%\IXP000.TMP\myisam08.dll
%TEMP%\IXP000.TMP\myuni08.dll
%TEMP%\IXP000.TMP\obres.dll
%TEMP%\IXP000.TMP\ocvt.dll
%TEMP%\IXP000.TMP\ofdutil.dll
%TEMP%\IXP000.TMP\ofx.dll
%TEMP%\IXP000.TMP\olshared.dll
%TEMP%\IXP000.TMP\pidgen08.dll
%TEMP%\IXP000.TMP\pmres.dll
%TEMP%\IXP000.TMP\QM.dll
%TEMP%\IXP000.TMP\rcmpacct.dll
%TEMP%\IXP000.TMP\rcmpbank.dll
%TEMP%\IXP000.TMP\rcmpbb.dll
%TEMP%\IXP000.TMP\rcmpbled.dll
%TEMP%\IXP000.TMP\rcmpblls.dll
%TEMP%\IXP000.TMP\rcmpbllw.dll
%TEMP%\IXP000.TMP\rcmpbobo.dll
%TEMP%\IXP000.TMP\rcmpcon.dll
%TEMP%\IXP000.TMP\rcmpctcl.dll
%TEMP%\IXP000.TMP\rcmpffm.dll
%TEMP%\IXP000.TMP\rcmpiad.dll
%TEMP%\IXP000.TMP\rcmpinv.dll
%TEMP%\IXP000.TMP\rcmpiue.dll
%TEMP%\IXP000.TMP\rcmploan.dll
%TEMP%\IXP000.TMP\rcmplst.dll
%TEMP%\IXP000.TMP\rcmpolsv.dll
%TEMP%\IXP000.TMP\rcmppay.dll
%TEMP%\IXP000.TMP\rcmpport.dll
%TEMP%\IXP000.TMP\rcreport.dll
%TEMP%\IXP000.TMP\resdll.dll
%TEMP%\IXP000.TMP\rpteng.dll
%TEMP%\IXP000.TMP\rsalv.dll
%TEMP%\IXP000.TMP\rsntz.dll
%TEMP%\IXP000.TMP\salv.exe
%TEMP%\IXP000.TMP\sanitize.exe
%TEMP%\IXP000.TMP\signin.exe
%TEMP%\IXP000.TMP\smrtsync.dll
%TEMP%\IXP000.TMP\surf.mar
%TEMP%\IXP000.TMP\surfinet.dll
%TEMP%\IXP000.TMP\surfshim.dll
%TEMP%\IXP000.TMP\svcst808.dll
%TEMP%\IXP000.TMP\themedef.mar
%TEMP%\IXP000.TMP\udsxml.dll
%TEMP%\IXP000.TMP\uninst.exe
%TEMP%\IXP000.TMP\uparser.dll
%TEMP%\IXP000.TMP\uparser2.dll
%TEMP%\IXP000.TMP\update.exe
%TEMP%\IXP000.TMP\utlsrf08.dll
%TEMP%\IXP000.TMP\wlctrl10.dll
%TEMP%\IXP000.TMP\wlutlres.dll
%TEMP%\IXP000.TMP\zlib.dll

Detected by UnHackMe:

SALV.EXE
Default location: %TEMP%\IXP000.TMP\SALV.EXE

Dropper information:
MD5: 878ec0515bdc2f81b74d4b8485e74d34
File size: 21583392 bytes

Leave a Reply