Jump to content

Removal instructions for Video Saver 2


Recommended Posts

  • Staff

What is Video Saver 2?

The Malwarebytes research team has determined that Video Saver 2 is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.

How do I know if my computer is affected by Video Saver 2?

You may see this entry in your list of installed software:

warning4.png

and these warnings during install:

main.png

warning1.png

and these browser add-ons:

warning2.png

warning3.png

warning5.png

warning6.png

and these Scheduled Tasks:

warning7.png

and you may get this warning when you are trying to alter your Search Provider in Internet Explorer:

warning8.png

How did Video Saver 2 get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software.

How do I remove Video Saver 2?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.

  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Video Saver 2?
  • If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the Video Saver 2 entry.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Video Saver 2 hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

protection1.png

Technical details for experts

Signs in a HijackThis log:

R3 - URLSearchHook: Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dllO2 - BHO: Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dllO23 - Service: VideoSaverSvc - Unknown owner - C:\Program Files (x86)\Video Saver 2\svc\Service.exe
Note : the filename of the dll is random

Possible signs in FRST logs:

 

 () C:\Program Files (x86)\Video Saver 2\svc\Service.exe () C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION URLSearchHook: HKCU - Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll () URLSearchHook: HKCU - Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll () SearchScopes: HKCU -> DefaultScope {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} URL =  BHO: Video Saver -> {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} -> C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll [2015-07-22] () BHO-x32: Video Saver -> {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} -> C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll [2015-07-22] () FF DefaultSearchEngine: Search with us! FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\search-with-us-.xml [2015-08-13] FF Extension: Video Saver - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} [2015-08-13] CHR Extension: (No Name) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo [2015-08-13] OPR Extension: (No Name) - C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo [2015-08-13] R2 VideoSaverSvc; C:\Program Files (x86)\Video Saver 2\svc\Service.exe [87280 2015-07-22] () C:\Windows\System32\Tasks\Recovery Tool for Video Saver 22 C:\Windows\System32\Tasks\Update Service for Video Saver 22 C:\Windows\System32\Tasks\Recovery Tool for Video Saver 2 C:\Windows\System32\Tasks\Update Service for Video Saver 2 C:\Windows\Tasks\Recovery Tool for Video Saver 22.job C:\Windows\Tasks\Recovery Tool for Video Saver 2.job C:\Windows\Tasks\Update Service for Video Saver 22.job C:\Windows\Tasks\Update Service for Video Saver 2.job C:\Program Files (x86)\Video Saver 2Video Saver (HKLM-x32\...\Video Saver 2) (Version: 1.1.1.2 - )Task: {35701936-0F18-4422-8A26-A4FFBF1F8E1A} - System32\Tasks\Recovery Tool for Video Saver 2 => C:\Program Files (x86)\Video Saver 2\tool\recover.exe [2015-07-22] () <==== ATTENTIONTask: {8E8FC513-7BD9-40E5-B5A0-882F0D4C2CD1} - System32\Tasks\Recovery Tool for Video Saver 22 => C:\Program Files (x86)\Video Saver 2\tool\recover.exe [2015-07-22] () <==== ATTENTIONTask: {A8044441-00FF-48D5-A795-55C63043BA4D} - System32\Tasks\Update Service for Video Saver 2 => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe [2015-07-22] () <==== ATTENTIONTask: {D5FD10FB-95EA-4740-B384-8965455BF6E9} - System32\Tasks\Update Service for Video Saver 22 => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe [2015-07-22] () <==== ATTENTIONTask: C:\Windows\Tasks\Recovery Tool for Video Saver 2.job => C:\Program Files (x86)\Video Saver 2\tool\recover.exe <==== ATTENTIONTask: C:\Windows\Tasks\Recovery Tool for Video Saver 22.job => C:\Program Files (x86)\Video Saver 2\tool\recover.exe <==== ATTENTIONTask: C:\Windows\Tasks\Update Service for Video Saver 2.job => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe <==== ATTENTIONTask: C:\Windows\Tasks\Update Service for Video Saver 22.job => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe <==== ATTENTION
Alterations made by the installer:

 

File system details [View: All details] (Selection)---------------------------------------------------    Adds the folder C:\Program Files (x86)\Video Saver 2       Adds the file hErCAF6.exe"="22/07/2015 16:04, 107872 bytes, A       Adds the file Runner.exe"="22/07/2015 16:04, 81760 bytes, A       Adds the file uninstall.exe"="22/07/2015 16:04, 1629128 bytes, A       Adds the file update.xml"="22/07/2015 16:04, 441 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF       Adds the file 9QmmsRpaHT.dll"="22/07/2015 16:03, 344416 bytes, A       Adds the file icon.ico"="22/07/2015 16:03, 9662 bytes, A       Adds the file icon16.ico"="22/07/2015 16:03, 1150 bytes, A       Adds the file info.json"="22/07/2015 16:03, 1970 bytes, A       Adds the file Interfaces32.dll"="22/07/2015 16:03, 178536 bytes, A       Adds the file Interfaces64.dll"="22/07/2015 16:03, 220520 bytes, A       Adds the file R4kuoFUSwb.exe"="22/07/2015 16:03, 913776 bytes, A       Adds the file uSzNxazviV.dll"="22/07/2015 16:03, 363360 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files       Adds the file background.html"="22/07/2015 16:03, 129 bytes, A       Adds the file Kernel.js"="22/07/2015 16:03, 18511 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files       Adds the file background.js"="22/07/2015 16:03, 19777 bytes, A       Adds the file foreground.js"="22/07/2015 16:03, 131025 bytes, A       Adds the file main.css"="22/07/2015 16:03, 6568 bytes, A       Adds the file proxy.js"="22/07/2015 16:03, 364 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ab.vksaver.custom       Adds the file download.png"="22/07/2015 16:03, 221 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.facebook.videosaver       Adds the file icon32.png"="22/07/2015 16:03, 492 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube       Adds the file arrow.png"="22/07/2015 16:03, 2951 bytes, A       Adds the file arrow2.png"="22/07/2015 16:03, 235 bytes, A       Adds the file plus.png"="22/07/2015 16:03, 2904 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\svc       Adds the file LocalServer.exe"="22/07/2015 16:03, 199920 bytes, A       Adds the file Service.exe"="22/07/2015 16:03, 87280 bytes, A    Adds the folder C:\Program Files (x86)\Video Saver 2\tool       Adds the file Chromium.dll"="22/07/2015 16:04, 222560 bytes, A       Adds the file freebl3.dll"="22/07/2015 16:03, 389120 bytes, A       Adds the file KompexSQLiteWrapper.dll"="22/07/2015 16:03, 551792 bytes, A       Adds the file nspr4.dll"="22/07/2015 16:03, 266240 bytes, A       Adds the file nss3.dll"="22/07/2015 16:03, 889344 bytes, A       Adds the file nssutil3.dll"="22/07/2015 16:03, 207360 bytes, A       Adds the file plc4.dll"="22/07/2015 16:03, 77824 bytes, A       Adds the file plds4.dll"="22/07/2015 16:03, 74752 bytes, A       Adds the file recover.exe"="22/07/2015 16:03, 209920 bytes, A       Adds the file softokn3.dll"="22/07/2015 16:03, 241664 bytes, A       Adds the file sqlite3.dll"="22/07/2015 16:03, 548864 bytes, A       Adds the file srecoverlib.dll"="22/07/2015 16:04, 428384 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0       Adds the file Content.js"="22/07/2015 16:03, 1413 bytes, A       Adds the file Kernel.js"="22/07/2015 16:03, 19261 bytes, A       Adds the file manifest.json"="13/08/2015 09:42, 1093 bytes, A    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}       Adds the file bootstrap.js"="22/07/2015 16:03, 11083 bytes, A       Adds the file chrome.manifest"="22/07/2015 16:03, 78 bytes, A       Adds the file install.rdf"="22/07/2015 16:03, 17278 bytes, A    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins       Adds the file search-with-us-.xml"="13/08/2015 09:42, 927 bytes, A    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons    In the existing folder C:\Windows\System32\Tasks       Adds the file Recovery Tool for Video Saver 2"="13/08/2015 09:42, 2828 bytes, A       Adds the file Recovery Tool for Video Saver 22"="13/08/2015 09:42, 2976 bytes, A       Adds the file Update Service for Video Saver 2"="13/08/2015 09:42, 2808 bytes, A       Adds the file Update Service for Video Saver 22"="13/08/2015 09:42, 2956 bytes, A    In the existing folder C:\Windows\Tasks       Adds the file Recovery Tool for Video Saver 2.job"="13/08/2015 09:42, 354 bytes, A       Adds the file Recovery Tool for Video Saver 22.job"="13/08/2015 09:42, 354 bytes, A       Adds the file Update Service for Video Saver 2.job"="13/08/2015 09:42, 334 bytes, A       Adds the file Update Service for Video Saver 22.job"="13/08/2015 09:42, 334 bytes, ARegistry details [View: All details] (Selection)------------------------------------------------    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]       "(Default)"="REG_SZ", "Video Saver"       "ProgID"="REG_SZ", "Toolbar.ExtensionHelperObject.1"       "TypeLib"="REG_SZ", "{1D5A4199-956E-49BC-B89F-6A35C57C0D13}"       "VersionIndependentProgID"="REG_SZ", "Toolbar.ExtensionHelperObject"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\InprocServer32]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll"       "ThreadingModel"="REG_SZ", "Apartment"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Programmable]       "(Default)"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}]       "(Default)"="REG_SZ", "_IjMA2nMv9p5kWEgxbMniEvents"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020420-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\TypeLib]       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}]       "(Default)"="REG_SZ", "IjMA2nMv9p5kWEgxbMni"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\TypeLib]       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}]       "(Default)"="REG_SZ", "{8D95A89C-A2F2-4E3C-9458-64ACA196C980}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\TypeLib]       "(Default)"="REG_SZ", "{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0]       "(Default)"="REG_SZ", "HxLvYVg1IWnDhc132NUQbUjIzWpPKxixjDCr"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0\0\win32]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\R4kuoFUSwb.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0\FLAGS]       "(Default)"="REG_SZ", "0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0\HELPDIR]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0]       "(Default)"="REG_SZ", "{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0\0\win32]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0\FLAGS]       "(Default)"="REG_SZ", "0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0\HELPDIR]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}]       "(Default)"="REG_SZ", "BackgroundScriptEngine Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}\LocalServer32]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\R4kuoFUSwb.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}\Programmable]       "(Default)"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]       "(Default)"="REG_SZ", "Video Saver"       "ProgID"="REG_SZ", "Toolbar.ExtensionHelperObject.1"       "TypeLib"="REG_SZ", "{1D5A4199-956E-49BC-B89F-6A35C57C0D13}"       "VersionIndependentProgID"="REG_SZ", "Toolbar.ExtensionHelperObject"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\InprocServer32]       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll"       "ThreadingModel"="REG_SZ", "Apartment"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Programmable]       "(Default)"="REG_SZ", ""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}]       "(Default)"="REG_SZ", "_IjMA2nMv9p5kWEgxbMniEvents"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020420-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\TypeLib]       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}]       "(Default)"="REG_SZ", "IjMA2nMv9p5kWEgxbMni"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\TypeLib]       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}]       "(Default)"="REG_SZ", "{8D95A89C-A2F2-4E3C-9458-64ACA196C980}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\TypeLib]       "(Default)"="REG_SZ", "{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]       "(Default)"="REG_SZ", "Video Saver"       "NoExplorer"="REG_DWORD", 1    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]       "Recovery Tool for Video Saver 2.job"="REG_BINARY, ................................       "Recovery Tool for Video Saver 2.job.fp"="REG_DWORD", 279267936       "Recovery Tool for Video Saver 22.job"="REG_BINARY, ................................       "Recovery Tool for Video Saver 22.job.fp"="REG_DWORD", -1239084046       "Update Service for Video Saver 2.job"="REG_BINARY, ................................       "Update Service for Video Saver 2.job.fp"="REG_DWORD", 279266385       "Update Service for Video Saver 22.job"="REG_BINARY, ................................       "Update Service for Video Saver 22.job.fp"="REG_DWORD", -1789626314    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallWhitelist]       "1"="REG_SZ", "hjlmfejeepodkfiapgfhkniokjdcmkfo"    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]       "(Default)"="REG_SZ", "Video Saver"       "NoExplorer"="REG_DWORD", 1    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Video Saver 2]       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\uninstall.exe"       "DisplayName"="REG_SZ", "Video Saver"       "DisplayVersion"="REG_SZ", "1.1.1.2"       "NoModify"="REG_DWORD", 1       "NoRepair"="REG_DWORD", 1       "Publisher"="REG_SZ", ""       "UninstallString"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\uninstall.exe"       "URLInfoAbout"="REG_SZ", "http://gigabase.ru"    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Video Saver 2]       "guid"="REG_SZ", "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"       "Installed"="REG_DWORD", 1       "Path"="REG_SZ", "C:\Program Files (x86)\Video Saver 2"       "postback_url"="REG_SZ", "http://trapdont.ru/tool/searches?v=1.1.1.2CUSTOM_TOOL_POSTBACK_URLq=qwe"       "Uninstalled"="REG_SZ", "1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Video Saver 2\Components]       "Main"="REG_SZ", "1"    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VideoSaverSvc]       "DisplayName"="REG_SZ", "VideoSaverSvc"       "ErrorControl"="REG_DWORD", 1       "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\Video Saver 2\svc\Service.exe"       "ObjectName"="REG_SZ", "LocalSystem"       "ServerImagePath"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe"       "ServerPort"="REG_DWORD", 5001       "Start"="REG_DWORD", 2       "Type"="REG_DWORD", 272       "WOW64"="REG_DWORD", 1    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Approved Extensions]       "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"="REG_BINARY, ............    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]       "R4kuoFUSwb.exe"="REG_DWORD", 9999    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]       "DefaultScope" = REG_SZ, "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]       "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"="REG_SZ", ""    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]       "UsePolicySearchProvidersOnly"="REG_DWORD", 1    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]       "DisplayName"="REG_SZ", "Search with us!"       "FaviconPath"="REG_SZ", "http://altavista.com/favicon.ico"       "FaviconURLFallback"="REG_SZ", "http://altavista.com/favicon.ico"       "SortIndex"="REG_DWORD", 0       "SuggestionsURLFallback"="REG_SZ", ""       "TopResultURLFallback"="REG_SZ", ""       "URL"="REG_SZ", "http://search.com/?q={searchTerms}"    [HKEY_CURRENT_USER\Software\Video Saver 2]       "Installed"="REG_DWORD", 1       "Path"="REG_SZ", "C:\Program Files (x86)\Video Saver 2"       "Uninstalled"="REG_SZ", "1"    [HKEY_CURRENT_USER\Software\Video Saver 2\Components]       "Main"="REG_SZ", "1"
Excerpt of the Malwarebytes Anti-Malware log (full log available on request):

 

Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 13/08/2015Scan Time: 13:12Logfile: mbamVideoSaver2.txtAdministrator: YesVersion: 2.1.8.1057Malware Database: v2015.08.13.04Rootkit Database: v2015.08.06.01License: PremiumMalware Protection: DisabledMalicious Website Protection: EnabledSelf-protection: DisabledOS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser: {username}Scan Type: Threat ScanResult: CompletedObjects Scanned: 330048Time Elapsed: 4 min, 21 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: EnabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 2PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\Service.exe, 3708, Delete-on-Reboot, [a6b2c7410784cd696a99c8bc6e97df21]PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe, 3600, Delete-on-Reboot, [fd5b29dfc5c655e1d72cea9ae61f55ab]Modules: 0(No malicious items detected)Registry Keys: 34PUP.Optional.Neobar, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VideoSaverSvc, Quarantined, [a6b2c7410784cd696a99c8bc6e97df21], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\TYPELIB\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\INTERFACE\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\INPROCSERVER32, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}, Quarantined, [7eda7a8e246749ed5238854e0cf6c23e], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}, Quarantined, [7eda7a8e246749ed5238854e0cf6c23e], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05A24304-1561-4565-AF25-BFC59A160CA6}, Quarantined, [7eda7a8e246749ed5238854e0cf6c23e], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{39425798-7DC7-42A3-8386-235B3ED67CED}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{39425798-7DC7-42A3-8386-235B3ED67CED}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{39425798-7DC7-42A3-8386-235B3ED67CED}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Video Saver 2, Quarantined, [8cccd434c6c5c6700c331f7c1be6cf31], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Recovery Tool for Video Saver 2, Delete-on-Reboot, [cf898a7ec4c7d066ac0ed0e23dc76a96], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Recovery Tool for Video Saver 22, Delete-on-Reboot, [4e0aab5d404b57df3783486a51b321df], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Update Service for Video Saver 2, Delete-on-Reboot, [b5a30206177495a183de1bfc3bc8d22e], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Update Service for Video Saver 22, Delete-on-Reboot, [5206e91f5a31ce68530ea07730d3a060], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\VIDEO SAVER 2, Quarantined, [5bfd17f136554aecf8c3991949bbff01], PUP.Optional.SearchWithUs.ChrPRST, HKCU\SOFTWARE\POLICIES\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [e375ab5dfb9090a6c0f0644e7d87718f], PUP.Optional.VideoSaver.A, HKCU\SOFTWARE\VIDEO SAVER 2, Quarantined, [64f4da2e7417fc3a5960a11118ec5fa1], Registry Values: 5PUP.Optional.Neobar, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.VideoSaver.A, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [cf89bd4bb1da979f7b8326abef136f91], PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\Video Saver 2|postback_url, http://trapdont.ru/tool/searches?v=1.1.1.2CUSTOM_TOOL_POSTBACK_URLq=qwe, Quarantined, [5bfd17f136554aecf8c3991949bbff01]PUP.Optional.SearchWithUs.ChrPRST, HKCU\SOFTWARE\POLICIES\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}|URL, http://search.com/?q={searchTerms}, Quarantined, [e375ab5dfb9090a6c0f0644e7d87718f]PUP.Optional.VideoSaver.A, HKCU\SOFTWARE\VIDEO SAVER 2|Path, C:\Program Files (x86)\Video Saver 2, Quarantined, [64f4da2e7417fc3a5960a11118ec5fa1]Registry Data: 0(No malicious items detected)Folders: 267PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2, Delete-on-Reboot, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ab.vksaver.custom, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.facebook.videosaver, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\svc, Delete-on-Reboot, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], Files: 333PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\Service.exe, Delete-on-Reboot, [a6b2c7410784cd696a99c8bc6e97df21], PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe, Delete-on-Reboot, [fd5b29dfc5c655e1d72cea9ae61f55ab], PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll, Quarantined, [b6a29375236841f52ed5fc8806ff738d], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\R4kuoFUSwb.exe, Quarantined, [0256d434cac10432b1da349f7d8521df], PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\hErCAF6.exe, Quarantined, [e17749bf8b0058de1ee54c38d4312ed2], PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\Runner.exe, Quarantined, [a0b8d83018736cca24dfbbc9d1346997], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\uninstall.exe, Quarantined, [8cccd434c6c5c6700c331f7c1be6cf31], PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\Chromium.dll, Quarantined, [d187b2567c0f40f6da291c68ab5a09f7], PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\KompexSQLiteWrapper.dll, Quarantined, [481036d29fecbb7b33d0c4c0e421bf41], PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\wmInMwn.dll, Quarantined, [7cdc6e9a5c2f9d993dc62d5795702bd5], PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\ybCsDFY.dll, Quarantined, [7edad2366f1cf44225deaadacc397b85], PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\nsb7023.tmp\nsProcess.dll, Quarantined, [d484de2ae1aa80b6b2517a0a91749c64], PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Update Service for Video Saver 2, Quarantined, [c791e820fb902a0c4fa527797193768a], PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Update Service for Video Saver 22, Quarantined, [61f7d7318cffe056856fffa1f60ea957], PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Update Service for Video Saver 2.job, Quarantined, [95c32ddbd0bb43f341b4930d7a8a1ee2], PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Update Service for Video Saver 22.job, Quarantined, [4018a6623d4e55e153a20898de26d927], PUP.Optional.SearchWithUs.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\search-with-us-.xml, Quarantined, [59ff9078038861d5f2bdb4feeb198a76], PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Recovery Tool for Video Saver 2, Quarantined, [fc5c54b4a6e5f6406354cce66d9752ae], PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Recovery Tool for Video Saver 22, Quarantined, [9fb9f117a5e670c63285ffb3956f34cc], PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Recovery Tool for Video Saver 2.job, Quarantined, [95c3df293457e74f13a521918084e31d], PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Recovery Tool for Video Saver 22.job, Quarantined, [8ccc55b32962f83ec4f4ad05a55faa56], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\bootstrap.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome.manifest, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\install.rdf, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\background.html, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\background.xul, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\Kernel.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\background.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\foreground.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\main.css, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ab.vksaver.custom\download.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.facebook.videosaver\icon32.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ytdownloader.YouTube\plus.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\icons\icon19.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\icons\icon48.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\icons\icon64.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\arrow.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\background.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\bindings.css, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\bindings.xml, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\styles.css, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\update.xml, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\icon.ico, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\icon16.ico, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\info.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\Interfaces32.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\Interfaces64.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\background.html, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\Kernel.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\background.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\foreground.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\main.css, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\proxy.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ab.vksaver.custom\download.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.facebook.videosaver\icon32.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube\plus.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\hi\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\am\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ar\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\be\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\bg\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\bn\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ca\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\cs\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\da\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\de\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\el\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\en\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\en_GB\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\en_US\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\es\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\es_419\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\et\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fa\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fi\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fil\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\gu\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\he\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\hr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\hu\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\id\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\it\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ja\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\kn\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ko\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\lt\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\lv\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\mk\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ml\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\mr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ms\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\nl\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\no\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pl\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pt\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pt_BR\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pt_PT\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ro\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ru\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sk\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sl\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sq\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sv\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sw\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ta\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\te\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\th\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\tr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\uk\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\vi\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\zh_CN\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\zh_TW\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\Chromium.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\freebl3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\KompexSQLiteWrapper.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\nspr4.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\nss3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\nssutil3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\plc4.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\plds4.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\recover.exe, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\softokn3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\sqlite3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\srecoverlib.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\manifest.json, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Content.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Kernel.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\background.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\foreground.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\main.css, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ab.vksaver.custom\download.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.facebook.videosaver\icon32.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\plus.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon128.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon16.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon48.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales\hi\messages.json, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\manifest.json, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Content.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Kernel.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\background.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\foreground.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\main.css, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ab.vksaver.custom\download.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.facebook.videosaver\icon32.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\plus.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon128.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon16.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon48.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales\hi\messages.json, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], Physical Sectors: 0(No malicious items detected)(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.

We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.