Home Malware Programs Adware Adware.KeepVid.com

Adware.KeepVid.com

Posted: February 10, 2014

Threat Metric

Ranking: 7,171
Threat Level: 2/10
Infected PCs: 118,440
First Seen: February 10, 2014
Last Seen: March 4, 2025
OS(es) Affected: Windows


KeepVid is a potentially unwanted program and adware threat that can be downloaded by PC users from its official web page KeepVid.com. KeepVid.com offers to download steaming videos straight to the computer system by simply entering the link to the search bar. However, while KeepVid.com may look legitimate and trustworthy, KeepVid may act as a browser hijacker and lead to forced browser redirects. KeepVid may also be associated with Ilivid. KeepVid may be capable of changing the default settings of the search engine and compromise every Web browser, which is installed on the PC involving Google Chrome, Mozilla Firefox and Internet Explorer. The owners of Keepvid.com may use tricky techniques for spreading their software called Keepvid. KeepVid may propagate and access the computer system through bundled freeware.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\CommonLauncher.exe File name: CommonLauncher.exe
Size: 210.94 KB (210944 bytes)
MD5: 8cd67f454d2c9158b17e83219badccf7
Detection count: 17,549
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\CommonLauncher.exe
Group: Malware file
Last Updated: June 18, 2024
%USERPROFILE%\Downloads\SoftonicDownloader_per_keepvid.exe File name: SoftonicDownloader_per_keepvid.exe
Size: 400.72 KB (400728 bytes)
MD5: 5475d18be0b96c95fe3f13020f5aa83f
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Downloads
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Descargar Musica Gratis\keepvid.dll File name: keepvid.dll
Size: 89.08 KB (89088 bytes)
MD5: 351e494c0d14a2a01d3dc1bd7bdb327a
Detection count: 22
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Descargar Musica Gratis
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\keepvid\keepvid.com.exe File name: keepvid.com.exe
Size: 1.24 MB (1245697 bytes)
MD5: ecd502f8dc03183b5fc864309eb233cd
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\keepvid
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\keepvid\keepvid.exe File name: keepvid.exe
Size: 1.41 MB (1417728 bytes)
MD5: 1bcb160e4d4faeeb7dc91315410688fc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\keepvid
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES(x86)%\keepvid\keepvidService.exe File name: keepvidService.exe
Size: 135.16 KB (135168 bytes)
MD5: f53a2a86d64a2d75b3129d19f1114d5e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\keepvid
Group: Malware file
Last Updated: March 7, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{49ed9900-38cd-453c-bba7-3f2613317f5a}{A1D74F49-2C1A-400B-A3BA-22147E24B208}Regexp file mask%LOCALAPPDATA%\helper.dat%LOCALAPPDATA%\keepvid.com.exe%LOCALAPPDATA%\keepvid.xpi%WinDir%\SysWOW64\helper.dat%WinDir%\SysWOW64\keepvid.dll%WinDir%\SysWOW64\keepvid.xpiHKEY..\..\..\..{RegistryKeys}Software\CashPartners CompanySOFTWARE\Classes\AppID\SubsHelperBHO.DLLSOFTWARE\Classes\AppID\{2580FD71-40E2-4319-8768-49EF61C0452B}SOFTWARE\Classes\SubsHelperBHO.SubsHelperBHOImplSOFTWARE\Classes\SubsHelperBHO.SubsHelperBHOImpl.1SOFTWARE\Classes\Wow6432Node\AppID\SubsHelperBHO.DLLSOFTWARE\Classes\Wow6432Node\AppID\{2580FD71-40E2-4319-8768-49EF61C0452B}Software\keepvid CompanySOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{49ed9900-38cd-453c-bba7-3f2613317f5a}Software\Microsoft\Windows\CurrentVersion\Run\CashPartnersSOFTWARE\Microsoft\Windows\CurrentVersion\Run\keepvidSoftware\Mozilla\Firefox\Extensions\keepvid.com@helper.comSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\keepvidSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files\keepvidSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\keepvidSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files\keepvidSOFTWARE\Wow6432Node\Classes\AppID\SubsHelperBHO.DLLSOFTWARE\Wow6432Node\Classes\AppID\{2580FD71-40E2-4319-8768-49EF61C0452B}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{49ed9900-38cd-453c-bba7-3f2613317f5a}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\keepvidHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}keepvid_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Microsoft\Windows\Start Menu\Programs\keepvid%ALLUSERSPROFILE%\Start Menu\Programs\keepvid%LOCALAPPDATA%\aHaskZ3
Loading...