Home Malware Programs Potentially Unwanted Programs (PUPs) xVidly

xVidly

Posted: June 27, 2013

Threat Metric

Ranking: 2,098
Threat Level: 1/10
Infected PCs: 117,112
First Seen: June 27, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

xVidly is a download manager that uses mildly disingenuous techniques to distribute and install itself to your PC, usually along with a xVidly Toolbar that hijacks your browser's settings. Installers for xVidly usually are encountered during attempts to download various media files, and usually are done consensually. However, SpywareRemove.com malware researchers note that the browser changes made by xVidly are highly gratuitous, along with xVidly's download-managing features being of questionable benefit to your PC. While not blatantly malicious, xVidly is categorized as a Potentially Unwanted Program or PUP, and you should remove xVidly software with a relevant anti-malware program in any case where you're not sure that you want xVidly on your computer.

An Awfully Fiddly Way to Get Your 'Vidly'

Ever since the termination of many easily-accessible, free media-sharing services, PC users have been desperate to uncover new ways to acquire music, movies and related files, and xVidly offers the download-managing services that would seem to help make that happen. What xVidly leaves opaque, however, is the fact that xVidly derives most of its profit from redirecting traffic towards advertisements and affiliated sites. Browser problems that malware experts have seen accompanying xVidly may include changes to your default homepage and default search engine, as well as the display of various advertisements and overall browser performance issues (slow page-loading, etc.).

Some xVidly installations also use less-than-honest methods, such as being bundled with compromised updates for Adobe Flash and other commonly-used applications. Of course, this particular method of getting xVidly on your computer should be easily evaded, as long as you don't make a habit of installing any important updates from suspicious pop-ups or untrustworthy websites.

Getting Your Downloads Streamlined with or without xVidly's Help

Because xVidly is considered a Potentially Unwanted Program or PUP, xVidly is not a very hazardous program to keep on your computer, but SpywareRemove.com malware researchers do encourage removing xVidly in the very likely case of your not wanting xVidly on your PC or needing its feature set. Normal uninstall techniques for xVidly often will fail to remove all browser changes and other components of the xVidly installation, which is why it's suggested that you use anti-malware tools for deleting xVidly.

Depending on the brand of anti-malware software being used to remove xVidly, xVidly or some of its components (like the xVidly Toolbar) may be identified as adware. Although xVidly does provide some legitimate features and is not very dangerous to your PC, many of its functions do overlap with adware programs, and SpywareRemove.com malware experts do recommend that you take a reasonable amount of care around advertisements from xVidly, which are not necessarily screened for your safety.
xVidly is not designed for one specific browser and can be found on Firefox, Internet Explorer or Chrome indiscriminately.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



xVidly.exe File name: xVidly.exe
Size: 208.32 KB (208320 bytes)
MD5: e017a251c8f66667217b684f2f665fc9
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2020

Registry Modifications

The following newly produced Registry Values are:

CLSID{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233}{1B26E4A2-7F09-4365-9AB8-13E6891E42CB}{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}{21402197-BB5B-476C-AA1D-3FFED8ED813A}{351A47E5-B59E-4CF2-B81A-B651D75FE944}{40D3F599-74F0-44D3-B059-76C0F12C0D6E}{42E8D680-A18B-4CAA-ACE0-18EA05E4A056}{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}{454A4044-16EC-4D64-9069-C5B8832B7B55}{64844F4D-492F-429E-881C-D7F106259738}{8F2B3016-17D4-447A-B207-FFA8957A834A}{959BA0A4-0893-48B4-8B02-BA0DA0A401FE}{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}{F8FA5B48-B7A2-4BC6-8389-9587643A4660}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\LyricsShoutSoftware\AppDataLow\Software\xvidly2SOFTWARE\Classes\FDM.FDMSOFTWARE\Classes\FDM.FDM.1SOFTWARE\Classes\FDM.FdmFlvDownloadSOFTWARE\Classes\FDM.FdmFlvDownload.1SOFTWARE\Classes\FDM.FdmUiWindowSOFTWARE\Classes\FDMDownload.FDMDownloadSOFTWARE\Classes\FDMDownload.FDMDownload.1SOFTWARE\Classes\FDMDownloadsStat.FDMDownloadsStat.1SOFTWARE\Classes\FDMFlashVideoDownloads.FDMFlashVideoDownloadsSOFTWARE\Classes\FDMFlashVideoDownloads.FDMFlashVideoDownloads.1SOFTWARE\Classes\FdmIeBho.FDMIEBHOSOFTWARE\Classes\FdmIeBho.FDMIEBHO.1SOFTWARE\Classes\FdmIeBho.FDMIEStatSOFTWARE\Classes\FdmIeBho.FDMIEStat.1SOFTWARE\Classes\FdmTorrentFilesRcvr.FdmTorrentFilesRcvrSOFTWARE\Classes\FdmTorrentFilesRcvr.FdmTorrentFilesRcvr.1SOFTWARE\Classes\FDMUploader.FDMUploaderSOFTWARE\Classes\FDMUploader.FDMUploader.1SOFTWARE\Classes\FDMUploadPackage.FDMUploadPackageSOFTWARE\Classes\FDMUploadPackage.FDMUploadPackage.1SOFTWARE\Classes\IeFdmdm.IEWGDMSoftware\Microsoft\Internet Explorer\MenuExt\Download all with Free Download ManagerSoftware\Microsoft\Internet Explorer\URLSearchHooks\{8c381847-2d83-463e-91b5-e1a6daf2bf0a}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}Software\Mozilla\Firefox\Extensions\LyricsShout@lyricsshout.netSoftware\Mozilla\Firefox\Extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}SOFTWARE\Wow6432Node\Microsoft\Tracing\xvidly_conduit_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\xvidly_conduit_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}SOFTWARE\Wow6432Node\xVidlySOFTWARE\Wow6432Node\xvidly2SOFTWARE\xVidlyHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Free Download Manager_is1xVidlyxvidly2 Toolbar

Additional Information

The following directories were created:
%APPDATA%\Free Download Manager%APPDATA%\xVidly%PROGRAMFILES%\Free Download Manager%PROGRAMFILES(x86)%\Free Download Manager%PROGRAMFILES(x86)%\xvidly2%TEMP%\ct3289778%USERPROFILE%\AppData\LocalLow\xvidly2
The following URL's were detected:
xVidly
Loading...