Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Video Saver 2

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,132 posts
Content is republished with permission from Malwarebytes.

What is Video Saver 2?

The Malwarebytes research team has determined that Video Saver 2 is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.

How do I know if my computer is affected by Video Saver 2?

You may see this entry in your list of installed software:

warning4.png

and these warnings during install:

main.png

warning1.png

and these browser add-ons:

warning2.png

warning3.png

warning5.png

warning6.png

and these Scheduled Tasks:

warning7.png

and you may get this warning when you are trying to alter your Search Provider in Internet Explorer:

warning8.png


How did Video Saver 2 get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software.

How do I remove Video Saver 2?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Video Saver 2?
  • If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the Video Saver 2 entry.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Video Saver 2 hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

protection1.png


Technical details for experts

Signs in a HijackThis log:

R3 - URLSearchHook: Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll
O2 - BHO: Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll
O23 - Service: VideoSaverSvc - Unknown owner - C:\Program Files (x86)\Video Saver 2\svc\Service.exe
Note : the filename of the dll is random

Possible signs in FRST logs:

 () C:\Program Files (x86)\Video Saver 2\svc\Service.exe
 () C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe
 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
 URLSearchHook: HKCU - Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll ()
 URLSearchHook: HKCU - Video Saver - {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} - C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll ()
 SearchScopes: HKCU -> DefaultScope {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} URL = 
 BHO: Video Saver -> {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} -> C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll [2015-07-22] ()
 BHO-x32: Video Saver -> {631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} -> C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll [2015-07-22] ()
 FF DefaultSearchEngine: Search with us!
 FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\search-with-us-.xml [2015-08-13]
 FF Extension: Video Saver - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3} [2015-08-13]
 CHR Extension: (No Name) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo [2015-08-13]
 OPR Extension: (No Name) - C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo [2015-08-13]
 R2 VideoSaverSvc; C:\Program Files (x86)\Video Saver 2\svc\Service.exe [87280 2015-07-22] ()
 C:\Windows\System32\Tasks\Recovery Tool for Video Saver 22
 C:\Windows\System32\Tasks\Update Service for Video Saver 22
 C:\Windows\System32\Tasks\Recovery Tool for Video Saver 2
 C:\Windows\System32\Tasks\Update Service for Video Saver 2
 C:\Windows\Tasks\Recovery Tool for Video Saver 22.job
 C:\Windows\Tasks\Recovery Tool for Video Saver 2.job
 C:\Windows\Tasks\Update Service for Video Saver 22.job
 C:\Windows\Tasks\Update Service for Video Saver 2.job
 C:\Program Files (x86)\Video Saver 2

Video Saver (HKLM-x32\...\Video Saver 2) (Version: 1.1.1.2 - )
Task: {35701936-0F18-4422-8A26-A4FFBF1F8E1A} - System32\Tasks\Recovery Tool for Video Saver 2 => C:\Program Files (x86)\Video Saver 2\tool\recover.exe [2015-07-22] () <==== ATTENTION
Task: {8E8FC513-7BD9-40E5-B5A0-882F0D4C2CD1} - System32\Tasks\Recovery Tool for Video Saver 22 => C:\Program Files (x86)\Video Saver 2\tool\recover.exe [2015-07-22] () <==== ATTENTION
Task: {A8044441-00FF-48D5-A795-55C63043BA4D} - System32\Tasks\Update Service for Video Saver 2 => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe [2015-07-22] () <==== ATTENTION
Task: {D5FD10FB-95EA-4740-B384-8965455BF6E9} - System32\Tasks\Update Service for Video Saver 22 => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe [2015-07-22] () <==== ATTENTION
Task: C:\Windows\Tasks\Recovery Tool for Video Saver 2.job => C:\Program Files (x86)\Video Saver 2\tool\recover.exe <==== ATTENTION
Task: C:\Windows\Tasks\Recovery Tool for Video Saver 22.job => C:\Program Files (x86)\Video Saver 2\tool\recover.exe <==== ATTENTION
Task: C:\Windows\Tasks\Update Service for Video Saver 2.job => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe <==== ATTENTION
Task: C:\Windows\Tasks\Update Service for Video Saver 22.job => C:\Program Files (x86)\Video Saver 2\hErCAF6.exe <==== ATTENTION
Alterations made by the installer:

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\Video Saver 2
       Adds the file hErCAF6.exe"="22/07/2015 16:04, 107872 bytes, A
       Adds the file Runner.exe"="22/07/2015 16:04, 81760 bytes, A
       Adds the file uninstall.exe"="22/07/2015 16:04, 1629128 bytes, A
       Adds the file update.xml"="22/07/2015 16:04, 441 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF
       Adds the file 9QmmsRpaHT.dll"="22/07/2015 16:03, 344416 bytes, A
       Adds the file icon.ico"="22/07/2015 16:03, 9662 bytes, A
       Adds the file icon16.ico"="22/07/2015 16:03, 1150 bytes, A
       Adds the file info.json"="22/07/2015 16:03, 1970 bytes, A
       Adds the file Interfaces32.dll"="22/07/2015 16:03, 178536 bytes, A
       Adds the file Interfaces64.dll"="22/07/2015 16:03, 220520 bytes, A
       Adds the file R4kuoFUSwb.exe"="22/07/2015 16:03, 913776 bytes, A
       Adds the file uSzNxazviV.dll"="22/07/2015 16:03, 363360 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files
       Adds the file background.html"="22/07/2015 16:03, 129 bytes, A
       Adds the file Kernel.js"="22/07/2015 16:03, 18511 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files
       Adds the file background.js"="22/07/2015 16:03, 19777 bytes, A
       Adds the file foreground.js"="22/07/2015 16:03, 131025 bytes, A
       Adds the file main.css"="22/07/2015 16:03, 6568 bytes, A
       Adds the file proxy.js"="22/07/2015 16:03, 364 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ab.vksaver.custom
       Adds the file download.png"="22/07/2015 16:03, 221 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.facebook.videosaver
       Adds the file icon32.png"="22/07/2015 16:03, 492 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube
       Adds the file arrow.png"="22/07/2015 16:03, 2951 bytes, A
       Adds the file arrow2.png"="22/07/2015 16:03, 235 bytes, A
       Adds the file plus.png"="22/07/2015 16:03, 2904 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\svc
       Adds the file LocalServer.exe"="22/07/2015 16:03, 199920 bytes, A
       Adds the file Service.exe"="22/07/2015 16:03, 87280 bytes, A
    Adds the folder C:\Program Files (x86)\Video Saver 2\tool
       Adds the file Chromium.dll"="22/07/2015 16:04, 222560 bytes, A
       Adds the file freebl3.dll"="22/07/2015 16:03, 389120 bytes, A
       Adds the file KompexSQLiteWrapper.dll"="22/07/2015 16:03, 551792 bytes, A
       Adds the file nspr4.dll"="22/07/2015 16:03, 266240 bytes, A
       Adds the file nss3.dll"="22/07/2015 16:03, 889344 bytes, A
       Adds the file nssutil3.dll"="22/07/2015 16:03, 207360 bytes, A
       Adds the file plc4.dll"="22/07/2015 16:03, 77824 bytes, A
       Adds the file plds4.dll"="22/07/2015 16:03, 74752 bytes, A
       Adds the file recover.exe"="22/07/2015 16:03, 209920 bytes, A
       Adds the file softokn3.dll"="22/07/2015 16:03, 241664 bytes, A
       Adds the file sqlite3.dll"="22/07/2015 16:03, 548864 bytes, A
       Adds the file srecoverlib.dll"="22/07/2015 16:04, 428384 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0
       Adds the file Content.js"="22/07/2015 16:03, 1413 bytes, A
       Adds the file Kernel.js"="22/07/2015 16:03, 19261 bytes, A
       Adds the file manifest.json"="13/08/2015 09:42, 1093 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}
       Adds the file bootstrap.js"="22/07/2015 16:03, 11083 bytes, A
       Adds the file chrome.manifest"="22/07/2015 16:03, 78 bytes, A
       Adds the file install.rdf"="22/07/2015 16:03, 17278 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins
       Adds the file search-with-us-.xml"="13/08/2015 09:42, 927 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons
    In the existing folder C:\Windows\System32\Tasks
       Adds the file Recovery Tool for Video Saver 2"="13/08/2015 09:42, 2828 bytes, A
       Adds the file Recovery Tool for Video Saver 22"="13/08/2015 09:42, 2976 bytes, A
       Adds the file Update Service for Video Saver 2"="13/08/2015 09:42, 2808 bytes, A
       Adds the file Update Service for Video Saver 22"="13/08/2015 09:42, 2956 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file Recovery Tool for Video Saver 2.job"="13/08/2015 09:42, 354 bytes, A
       Adds the file Recovery Tool for Video Saver 22.job"="13/08/2015 09:42, 354 bytes, A
       Adds the file Update Service for Video Saver 2.job"="13/08/2015 09:42, 334 bytes, A
       Adds the file Update Service for Video Saver 22.job"="13/08/2015 09:42, 334 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]
       "(Default)"="REG_SZ", "Video Saver"
       "ProgID"="REG_SZ", "Toolbar.ExtensionHelperObject.1"
       "TypeLib"="REG_SZ", "{1D5A4199-956E-49BC-B89F-6A35C57C0D13}"
       "VersionIndependentProgID"="REG_SZ", "Toolbar.ExtensionHelperObject"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Programmable]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}]
       "(Default)"="REG_SZ", "_IjMA2nMv9p5kWEgxbMniEvents"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020420-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\TypeLib]
       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}]
       "(Default)"="REG_SZ", "IjMA2nMv9p5kWEgxbMni"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\TypeLib]
       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}]
       "(Default)"="REG_SZ", "{8D95A89C-A2F2-4E3C-9458-64ACA196C980}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\TypeLib]
       "(Default)"="REG_SZ", "{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0]
       "(Default)"="REG_SZ", "HxLvYVg1IWnDhc132NUQbUjIzWpPKxixjDCr"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0\0\win32]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\R4kuoFUSwb.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0]
       "(Default)"="REG_SZ", "{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0\0\win32]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}]
       "(Default)"="REG_SZ", "BackgroundScriptEngine Class"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}\LocalServer32]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\R4kuoFUSwb.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}\Programmable]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]
       "(Default)"="REG_SZ", "Video Saver"
       "ProgID"="REG_SZ", "Toolbar.ExtensionHelperObject.1"
       "TypeLib"="REG_SZ", "{1D5A4199-956E-49BC-B89F-6A35C57C0D13}"
       "VersionIndependentProgID"="REG_SZ", "Toolbar.ExtensionHelperObject"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\Programmable]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}]
       "(Default)"="REG_SZ", "_IjMA2nMv9p5kWEgxbMniEvents"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020420-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{39425798-7DC7-42A3-8386-235B3ED67CED}\TypeLib]
       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}]
       "(Default)"="REG_SZ", "IjMA2nMv9p5kWEgxbMni"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}\TypeLib]
       "(Default)"="REG_SZ", "{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}]
       "(Default)"="REG_SZ", "{8D95A89C-A2F2-4E3C-9458-64ACA196C980}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}\TypeLib]
       "(Default)"="REG_SZ", "{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]
       "(Default)"="REG_SZ", "Video Saver"
       "NoExplorer"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]
       "Recovery Tool for Video Saver 2.job"="REG_BINARY, ................................
       "Recovery Tool for Video Saver 2.job.fp"="REG_DWORD", 279267936
       "Recovery Tool for Video Saver 22.job"="REG_BINARY, ................................
       "Recovery Tool for Video Saver 22.job.fp"="REG_DWORD", -1239084046
       "Update Service for Video Saver 2.job"="REG_BINARY, ................................
       "Update Service for Video Saver 2.job.fp"="REG_DWORD", 279266385
       "Update Service for Video Saver 22.job"="REG_BINARY, ................................
       "Update Service for Video Saver 22.job.fp"="REG_DWORD", -1789626314
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallWhitelist]
       "1"="REG_SZ", "hjlmfejeepodkfiapgfhkniokjdcmkfo"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]
       "(Default)"="REG_SZ", "Video Saver"
       "NoExplorer"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Video Saver 2]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\uninstall.exe"
       "DisplayName"="REG_SZ", "Video Saver"
       "DisplayVersion"="REG_SZ", "1.1.1.2"
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", ""
       "UninstallString"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\uninstall.exe"
       "URLInfoAbout"="REG_SZ", "http://gigabase.ru"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Video Saver 2]
       "guid"="REG_SZ", "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"
       "Installed"="REG_DWORD", 1
       "Path"="REG_SZ", "C:\Program Files (x86)\Video Saver 2"
       "postback_url"="REG_SZ", "http://trapdont.ru/tool/searches?v=1.1.1.2CUSTOM_TOOL_POSTBACK_URLq=qwe"
       "Uninstalled"="REG_SZ", "1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Video Saver 2\Components]
       "Main"="REG_SZ", "1"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VideoSaverSvc]
       "DisplayName"="REG_SZ", "VideoSaverSvc"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\Video Saver 2\svc\Service.exe"
       "ObjectName"="REG_SZ", "LocalSystem"
       "ServerImagePath"="REG_SZ", "C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe"
       "ServerPort"="REG_DWORD", 5001
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 272
       "WOW64"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Approved Extensions]
       "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"="REG_BINARY, ............
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
       "R4kuoFUSwb.exe"="REG_DWORD", 9999
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
       "DefaultScope" = REG_SZ, "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
       "{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}"="REG_SZ", ""
    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
       "UsePolicySearchProvidersOnly"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}]
       "DisplayName"="REG_SZ", "Search with us!"
       "FaviconPath"="REG_SZ", "http://altavista.com/favicon.ico"
       "FaviconURLFallback"="REG_SZ", "http://altavista.com/favicon.ico"
       "SortIndex"="REG_DWORD", 0
       "SuggestionsURLFallback"="REG_SZ", ""
       "TopResultURLFallback"="REG_SZ", ""
       "URL"="REG_SZ", "http://search.com/?q={searchTerms}"
    [HKEY_CURRENT_USER\Software\Video Saver 2]
       "Installed"="REG_DWORD", 1
       "Path"="REG_SZ", "C:\Program Files (x86)\Video Saver 2"
       "Uninstalled"="REG_SZ", "1"
    [HKEY_CURRENT_USER\Software\Video Saver 2\Components]
       "Main"="REG_SZ", "1"

Excerpt of the Malwarebytes Anti-Malware log (full log available on request):

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 13/08/2015
Scan Time: 13:12
Logfile: mbamVideoSaver2.txt
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.08.13.04
Rootkit Database: v2015.08.06.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330048
Time Elapsed: 4 min, 21 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\Service.exe, 3708, Delete-on-Reboot, [a6b2c7410784cd696a99c8bc6e97df21]
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe, 3600, Delete-on-Reboot, [fd5b29dfc5c655e1d72cea9ae61f55ab]

Modules: 0
(No malicious items detected)

Registry Keys: 34
PUP.Optional.Neobar, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VideoSaverSvc, Quarantined, [a6b2c7410784cd696a99c8bc6e97df21], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\TYPELIB\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\INTERFACE\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8D95A89C-A2F2-4E3C-9458-64ACA196C980}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E54ED555-AD7A-4A1C-89E9-6EBC2C03433A}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, HKLM\SOFTWARE\CLASSES\CLSID\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\INPROCSERVER32, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}, Quarantined, [7eda7a8e246749ed5238854e0cf6c23e], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{05A24304-1561-4565-AF25-BFC59A160CA6}, Quarantined, [7eda7a8e246749ed5238854e0cf6c23e], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{05A24304-1561-4565-AF25-BFC59A160CA6}, Quarantined, [7eda7a8e246749ed5238854e0cf6c23e], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{39425798-7DC7-42A3-8386-235B3ED67CED}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{39425798-7DC7-42A3-8386-235B3ED67CED}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{39425798-7DC7-42A3-8386-235B3ED67CED}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{653CED39-0660-4ACE-8A8F-CE7F48F5B167}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{421B5223-9CD5-4D2B-9B91-BD0476D4A64A}, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Video Saver 2, Quarantined, [8cccd434c6c5c6700c331f7c1be6cf31], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Recovery Tool for Video Saver 2, Delete-on-Reboot, [cf898a7ec4c7d066ac0ed0e23dc76a96], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Recovery Tool for Video Saver 22, Delete-on-Reboot, [4e0aab5d404b57df3783486a51b321df], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Update Service for Video Saver 2, Delete-on-Reboot, [b5a30206177495a183de1bfc3bc8d22e], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Update Service for Video Saver 22, Delete-on-Reboot, [5206e91f5a31ce68530ea07730d3a060], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\VIDEO SAVER 2, Quarantined, [5bfd17f136554aecf8c3991949bbff01], 
PUP.Optional.SearchWithUs.ChrPRST, HKCU\SOFTWARE\POLICIES\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [e375ab5dfb9090a6c0f0644e7d87718f], 
PUP.Optional.VideoSaver.A, HKCU\SOFTWARE\VIDEO SAVER 2, Quarantined, [64f4da2e7417fc3a5960a11118ec5fa1], 

Registry Values: 5
PUP.Optional.Neobar, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.VideoSaver.A, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [cf89bd4bb1da979f7b8326abef136f91], 
PUP.Optional.VideoSaver.A, HKLM\SOFTWARE\WOW6432NODE\Video Saver 2|postback_url, http://trapdont.ru/tool/searches?v=1.1.1.2CUSTOM_TOOL_POSTBACK_URLq=qwe, Quarantined, [5bfd17f136554aecf8c3991949bbff01]
PUP.Optional.SearchWithUs.ChrPRST, HKCU\SOFTWARE\POLICIES\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}|URL, http://search.com/?q={searchTerms}, Quarantined, [e375ab5dfb9090a6c0f0644e7d87718f]
PUP.Optional.VideoSaver.A, HKCU\SOFTWARE\VIDEO SAVER 2|Path, C:\Program Files (x86)\Video Saver 2, Quarantined, [64f4da2e7417fc3a5960a11118ec5fa1]

Registry Data: 0
(No malicious items detected)

Folders: 267
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2, Delete-on-Reboot, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ab.vksaver.custom, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.facebook.videosaver, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\svc, Delete-on-Reboot, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 

Files: 333
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\Service.exe, Delete-on-Reboot, [a6b2c7410784cd696a99c8bc6e97df21], 
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\svc\LocalServer.exe, Delete-on-Reboot, [fd5b29dfc5c655e1d72cea9ae61f55ab], 
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\IEEF\uSzNxazviV.dll, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\IEEF\9QmmsRpaHT.dll, Quarantined, [b6a29375236841f52ed5fc8806ff738d], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\R4kuoFUSwb.exe, Quarantined, [0256d434cac10432b1da349f7d8521df], 
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\hErCAF6.exe, Quarantined, [e17749bf8b0058de1ee54c38d4312ed2], 
PUP.Optional.Neobar, C:\Program Files (x86)\Video Saver 2\Runner.exe, Quarantined, [a0b8d83018736cca24dfbbc9d1346997], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\uninstall.exe, Quarantined, [8cccd434c6c5c6700c331f7c1be6cf31], 
PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\Chromium.dll, Quarantined, [d187b2567c0f40f6da291c68ab5a09f7], 
PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\KompexSQLiteWrapper.dll, Quarantined, [481036d29fecbb7b33d0c4c0e421bf41], 
PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\wmInMwn.dll, Quarantined, [7cdc6e9a5c2f9d993dc62d5795702bd5], 
PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\iOHFF4z1Zl_770881\ybCsDFY.dll, Quarantined, [7edad2366f1cf44225deaadacc397b85], 
PUP.Optional.Neobar, C:\Users\{username}\AppData\Local\Temp\nsb7023.tmp\nsProcess.dll, Quarantined, [d484de2ae1aa80b6b2517a0a91749c64], 
PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Update Service for Video Saver 2, Quarantined, [c791e820fb902a0c4fa527797193768a], 
PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Update Service for Video Saver 22, Quarantined, [61f7d7318cffe056856fffa1f60ea957], 
PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Update Service for Video Saver 2.job, Quarantined, [95c32ddbd0bb43f341b4930d7a8a1ee2], 
PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Update Service for Video Saver 22.job, Quarantined, [4018a6623d4e55e153a20898de26d927], 
PUP.Optional.SearchWithUs.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\searchplugins\search-with-us-.xml, Quarantined, [59ff9078038861d5f2bdb4feeb198a76], 
PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Recovery Tool for Video Saver 2, Quarantined, [fc5c54b4a6e5f6406354cce66d9752ae], 
PUP.Optional.VideoSaver.A, C:\Windows\System32\Tasks\Recovery Tool for Video Saver 22, Quarantined, [9fb9f117a5e670c63285ffb3956f34cc], 
PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Recovery Tool for Video Saver 2.job, Quarantined, [95c3df293457e74f13a521918084e31d], 
PUP.Optional.VideoSaver.A, C:\Windows\Tasks\Recovery Tool for Video Saver 22.job, Quarantined, [8ccc55b32962f83ec4f4ad05a55faa56], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\bootstrap.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome.manifest, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\install.rdf, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\background.html, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\background.xul, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\Kernel.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\background.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\foreground.js, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\main.css, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ab.vksaver.custom\download.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.facebook.videosaver\icon32.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\files\com.ytdownloader.YouTube\plus.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\icons\icon19.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\icons\icon48.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\icons\icon64.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\arrow.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\background.png, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\bindings.css, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\bindings.xml, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\{631F9C5D-6307-4E32-BC0D-B1C3A0C064F3}\chrome\skin\styles.css, Quarantined, [1f39da2e42495fd71a6fc54b3ec56c94], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\update.xml, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\icon.ico, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\icon16.ico, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\info.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\Interfaces32.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\Interfaces64.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\background.html, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\Kernel.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\background.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\foreground.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\main.css, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\proxy.js, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ab.vksaver.custom\download.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.facebook.videosaver\icon32.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\files\com.ytdownloader.YouTube\plus.png, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\hi\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\am\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ar\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\be\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\bg\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\bn\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ca\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\cs\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\da\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\de\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\el\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\en\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\en_GB\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\en_US\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\es\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\es_419\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\et\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fa\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fi\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fil\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\fr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\gu\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\he\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\hr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\hu\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\id\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\it\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ja\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\kn\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ko\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\lt\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\lv\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\mk\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ml\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\mr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ms\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\nl\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\no\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pl\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pt\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pt_BR\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\pt_PT\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ro\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ru\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sk\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sl\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sq\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sv\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\sw\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\ta\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\te\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\th\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\tr\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\uk\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\vi\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\zh_CN\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\IEEF\files\_locales\zh_TW\messages.json, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\Chromium.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\freebl3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\KompexSQLiteWrapper.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\nspr4.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\nss3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\nssutil3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\plc4.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\plds4.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\recover.exe, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\softokn3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\sqlite3.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.VideoSaver.A, C:\Program Files (x86)\Video Saver 2\tool\srecoverlib.dll, Quarantined, [21372fd9d4b79b9b859e0a82ba4bce32], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\manifest.json, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Content.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Kernel.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\background.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\foreground.js, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\main.css, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ab.vksaver.custom\download.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.facebook.videosaver\icon32.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\plus.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon128.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon16.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon48.png, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales\hi\messages.json, Quarantined, [4c0ccc3c5f2c1b1b12107f0dfc0955ab], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\manifest.json, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Content.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\Kernel.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\background.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\foreground.js, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\main.css, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ab.vksaver.custom\download.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.facebook.videosaver\icon32.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\arrow2.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\files\com.ytdownloader.YouTube\plus.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon128.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon16.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\icons\icon48.png, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 
PUP.Optional.NeoBars.Gen, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hjlmfejeepodkfiapgfhkniokjdcmkfo\1.1.1.2_0\_locales\hi\messages.json, Quarantined, [1b3d5eaac3c89d998997eaa2b0553fc1], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.