Threat Database Adware Adware:Win32/Vidsaver

Adware:Win32/Vidsaver

By ZulaZuza in Adware

Threat Scorecard

Ranking: 4,479
Threat Level: 20 % (Normal)
Infected Computers: 7,582
First Seen: January 18, 2013
Last Seen: September 19, 2023
OS(es) Affected: Windows

Adware:Win32/Vidsaver is an adware application that shows offers associated with an affected PC user's Internet surfing from the application's website. Adware:Win32/Vidsaver shows offers in the hacked Internet browser which declare 'ads not by this site' or display the text 'Ads by Vid-Saver plugin' when a computer user puts the mouse cursor over them may signify the occurrence of Adware:Win32/Vidsaver on their PCs. When started, the installer for Adware:Win32/Vidsaver creates a folder named 'Vidsaver' and installs the files there. The icon for Adware:Win32/Vidsaver will occur. Adware:Win32/Vidsaver installs itself as a BHO (browser helper object), which can be seen in Internet Explorer's Manage Add-ons window. Adware:Win32/Vidsaver also installs itself as a Google Chrome extension by downloading the files. Adware:Win32/Vidsaver creates an installation entry in the Programs and Features section of the Control Panel, and running this uninstaller may uninstall Adware:Win32/Vidsaver from the machine. Once installed, Adware:Win32/Vidsaver shows offers to a PC user as he/she surfs the Internet. Adware:Win32/Vidsaver also changes particular keywords on websites with a hyperlink. The destination of the hyperlink depends on the keyword.

SpyHunter Detects & Remove Adware:Win32/Vidsaver

File System Details

Adware:Win32/Vidsaver may create the following file(s):
# File Name MD5 Detections
1. vid-saver.dll
2. vid-saver.exe
3. vid-saver-bg.exe
4. buttonutil.dll
5. %LOCALAPPDATA%\Google\Chrome\user data\Default\databases\chrome-extension_pgmfkblbflahhponhjmkcnpjinenhlnc_0\3
6. vid-saver.ico
7. %LOCALAPPDATA%\Google\Chrome\user data\Default\databases\databases.db
8. vid-saver.ini
9. %LOCALAPPDATA%\Google\Chrome\user data\Default\databases\databases.db-journal
10. 5560cb14577d42dbb336b515f4c3d49d de7db704ad0d4453239aeba2bd7fe378 0
11. cdc07802fa8a66e08f84c5eeb44a7ef1 c99517dcbb192427b4da5db30c12bec6 0
12. 43CF451E785F3EEF571F1E4E6319B6002AADC46C.exe d9ba18c428c84f6d120c405f88fa09dd 0

Registry Details

Adware:Win32/Vidsaver may create the following registry entry or registry entries:
CLSID
{11111111-1111-1111-1111-110011341191}
{22222222-2222-2222-2222-220022342291}
{33333333-3333-3333-3333-330033343391}
{44444444-4444-4444-4444-440044344491}
{55555555-5555-5555-5555-550055345591}
{66666666-6666-6666-6666-660066346691}
{77777777-7777-7777-7777-770077347791}
Software\AppDataLow\Software\Vid-Saver
SOFTWARE\Classes\CrossriderApp0003491.BHO
SOFTWARE\Classes\CrossriderApp0003491.BHO.1
SOFTWARE\Classes\CrossriderApp0003491.FBApi
SOFTWARE\Classes\CrossriderApp0003491.FBApi.1
SOFTWARE\Classes\CrossriderApp0003491.Sandbox
SOFTWARE\Classes\CrossriderApp0003491.Sandbox.1
Software\Cr_Installer\3491
Software\InstalledBrowserExtensions\215 Apps\3491
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Vid-Saver-repairJob
SOFTWARE\Vid-Saver
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011341191}
SOFTWARE\Wow6432Node\Microsoft\Tracing\Vid-Saver_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Vid-Saver_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Vid-Saver-repairJob

Directories

Adware:Win32/Vidsaver may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Vid-Saver
%LOCALAPPDATA%\Updater3491
%LOCALAPPDATA%\Vid-Saver
%PROGRAMFILES%\Vid-Saver
%PROGRAMFILES(x86)%\Vid-Saver

URLs

Adware:Win32/Vidsaver may call the following URLs:

Vid-Saver
vid-saver.com

Trending

Most Viewed

Loading...