xVidly Description

xVidly is a download manager that uses mildly disingenuous techniques to distribute and install itself to your PC, usually along with a xVidly Toolbar that hijacks your browser’s settings. Installers for xVidly usually are encountered during attempts to download various media files, and usually are done consensually. However, SpywareRemove.com malware researchers note that the browser changes made by xVidly are highly gratuitous, along with xVidly’s download-managing features being of questionable benefit to your PC. While not blatantly malicious, xVidly is categorized as a Potentially Unwanted Program or PUP, and you should remove xVidly software with a relevant anti-malware program in any case where you’re not sure that you want xVidly on your computer.

An Awfully Fiddly Way to Get Your ‘Vidly’

Ever since the termination of many easily-accessible, free media-sharing services, PC users have been desperate to uncover new ways to acquire music, movies and related files, and xVidly offers the download-managing services that would seem to help make that happen. What xVidly leaves opaque, however, is the fact that xVidly derives most of its profit from redirecting traffic towards advertisements and affiliated sites. Browser problems that malware experts have seen accompanying xVidly may include changes to your default homepage and default search engine, as well as the display of various advertisements and overall browser performance issues (slow page-loading, etc.).

Some xVidly installations also use less-than-honest methods, such as being bundled with compromised updates for Adobe Flash and other commonly-used applications.

Of course, this particular method of getting xVidly on your computer should be easily evaded, as long as you don’t make a habit of installing any important updates from suspicious pop-ups or untrustworthy websites.

Getting Your Downloads Streamlined with or without xVidly’s Help

Because xVidly is considered a Potentially Unwanted Program or PUP, xVidly is not a very hazardous program to keep on your computer, but SpywareRemove.com malware researchers do encourage removing xVidly in the very likely case of your not wanting xVidly on your PC or needing its feature set. Normal uninstall techniques for xVidly often will fail to remove all browser changes and other components of the xVidly installation, which is why it’s suggested that you use anti-malware tools for deleting xVidly.

Depending on the brand of anti-malware software being used to remove xVidly, xVidly or some of its components (like the xVidly Toolbar) may be identified as adware. Although xVidly does provide some legitimate features and is not very dangerous to your PC, many of its functions do overlap with adware programs, and SpywareRemove.com malware experts do recommend that you take a reasonable amount of care around advertisements from xVidly, which are not necessarily screened for your safety.
xVidly is not designed for one specific browser and can be found on Firefox, Internet Explorer or Chrome indiscriminately.

xVidly Automatic Detection Tool (Recommended)

Is your PC infected with xVidly? To safely & quickly detect xVidly we highly recommend you run the malware scanner listed below.

Technical Details

File System Modifications

  • The following files were created in the system:
    # File Name Detection Count
    1 %ALLUSERSPROFILE%\Application Data\Microsoft\Windows\Start Menu\Programs\Free Download Manager 225
    2 %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Free Download Manager 222
    3 %TEMP%\ct3289778 219
    4 %USERPROFILE%\Application Data\xvidly2 203
    5 %USERPROFILE%\AppData\LocalLow\xvidly2 200
    6 %PROGRAMFILES(x86)%\xvidly2 197
    7 %PROGRAMFILES%\xvidly2 194
    8 %PROGRAMFILES(x86)%\LyricsShout 191
    9 %PROGRAMFILES%\LyricsShout 187
    10 xVidly.exe 3

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}LyricsShout@lyricsshout.netxVidlyxvidly2 ToolbarHKEY..\..\..\..{RegistryKeys}FDM.FDMFDM.FDM.1FDM.FdmFlvDownloadFDM.FdmFlvDownload.1FDMDownload.FDMDownload.1FDMDownloadsStat.FDMDownloadsStatFDMDownloadsStat.FDMDownloadsStat.1FDMFlashVideoDownloads.FDMFlashVideoDownloadsFDMFlashVideoDownloads.FDMFlashVideoDownloads.1FdmIeBho.FDMIEBHOFdmIeBho.FDMIEBHO.1FdmTorrentFilesRcvr.FdmTorrentFilesRcvr.1FDMUploader.FDMUploaderFDMUploader.FDMUploader.1FDMUploadPackage.FDMUploadPackageFDMUploadPackage.FDMUploadPackage.1IeFdmdm.IEWGDMIeFdmdm.IEWGDM.1Software\AppDataLow\Software\LyricsShoutSoftware\AppDataLow\Software\xvidly2SOFTWARE\Classes\FDM.FDMSOFTWARE\Classes\FDM.FDM.1SOFTWARE\Classes\FDM.FdmFlvDownloadSOFTWARE\Classes\FDM.FdmFlvDownload.1SOFTWARE\Classes\FDM.FdmUiWindowSOFTWARE\Classes\FDMDownload.FDMDownloadSOFTWARE\Classes\FDMFlashVideoDownloads.FDMFlashVideoDownloads.1SOFTWARE\Classes\FdmIeBho.FDMIEBHOSOFTWARE\Classes\FdmIeBho.FDMIEBHO.1SOFTWARE\Classes\FdmIeBho.FDMIEStatSOFTWARE\Classes\FdmIeBho.FDMIEStat.1SOFTWARE\Classes\FdmTorrentFilesRcvr.FdmTorrentFilesRcvrSOFTWARE\Classes\FdmTorrentFilesRcvr.FdmTorrentFilesRcvr.1SOFTWARE\Classes\FDMUploadPackage.FDMUploadPackage.1SOFTWARE\Classes\IeFdmdm.IEWGDMSoftware\FreeDownloadManager.ORGSoftware\Google\Chrome\Extensions\kdlpoplpnhnnnhffgmfhpdbfapgkbbodSoftware\Microsoft\Internet Explorer\MenuExt\Download all with Free Download ManagerSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{533B3693-0C31-429D-9109-9D66A77E913F}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8c381847-2d83-463e-91b5-e1a6daf2bf0a}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}Software\Mozilla\Firefox\Extensions, value: {5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjpSOFTWARE\Wow6432Node\Google\Chrome\Extensions\kdlpoplpnhnnnhffgmfhpdbfapgkbbodSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{533B3693-0C31-429D-9109-9D66A77E913F}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8c381847-2d83-463e-91b5-e1a6daf2bf0a}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}SOFTWARE\Wow6432Node\xVidlySOFTWARE\Wow6432Node\xvidly2SOFTWARE\xVidlySOFTWARE\xvidly2WG.WGUrlReceiver.1Wow6432Node\AppID\priam_bho.DLL
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}{F8FA5B48-B7A2-4BC6-8389-9587643A4660}{8F2B3016-17D4-447A-B207-FFA8957A834A}{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}{42E8D680-A18B-4CAA-ACE0-18EA05E4A056}{40D3F599-74F0-44D3-B059-76C0F12C0D6E}{21402197-BB5B-476C-AA1D-3FFED8ED813A}{1B26E4A2-7F09-4365-9AB8-13E6891E42CB}{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233}{3C6AC8EC-B969-4E4A-825E-2B0A52A465EB}{8C381847-2D83-463E-91B5-E1A6DAF2BF0A}
Posted: June 27, 2013 | By
Threat Metric
Threat Level: 1/10
Detection Count: 422,587

