Home Malware Programs Potentially Unwanted Programs (PUPs) iLivid

iLivid

Posted: July 12, 2011

Threat Metric

Ranking: 287
Threat Level: 1/10
Infected PCs: 517,211
First Seen: July 12, 2011
Last Seen: October 17, 2023
OS(es) Affected: Windows

The iLivid Download Manager from Bandoo Media Inc. that can be found at Ilivid.com and in freeware bundles is deemed as a Potentially Unwanted Program with adware capabilities. The iLivid Download Manager is detected by most AV solutions as PUP.iLivid and users may have installed it to download videos from YouTube and watch videos on some torrent networks. The iLivid Download Manager may allow users to input URLs to videos from the Internet and download the content in MP4, AVI, and MKV file formats, but it may display numerous pop-up windows and banners with marketing materials. PUP.iLivid is programmed to provide limited functionality to dissuade users from removing it as soon as the ads start pouring on their desktop. The iLivid Download Manager may integrate into Google Chrome, Internet Explorer, and Mozilla Firefox to read your browsing and download history, display commercials and change your homepage to Avplus-online.org. The site mentioned before is associated with a browser hijacker that may redirect users to harmful domains and the changes applied by PUP.iLivid may not be for your good.

PUP.iLivid may edit your Windows Registry settings to start with Windows and open your Internet browser to meet you with promotional content from sponsors. The iLivid Download Manager may send information like your IP address, software configuration and bookmarks collection to advertisers for analysis and marketing purposes. Moreover, PUP.iLivid may welcome users to install other riskware such as ICForge and LiMo that may cause system errors and decrease your computer performance. The iLivid Download Manager may place its files in the program Files directory of Windows like legitimate programs do, but it may not be safe to use. Computer users need to install a reliable anti-malware application that can delete all components of PUP.iLivid efficiently.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\iLivid\ilivid.exe File name: ilivid.exe
Size: 2.03 MB (2033152 bytes)
MD5: a485b5376a7bd86e17da042a64ee3e86
Detection count: 9,265
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\iLivid\ilivid.exe
Group: Malware file
Last Updated: October 12, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\iLivid\iLivid.exe File name: iLivid.exe
Size: 3.43 MB (3431424 bytes)
MD5: 9115b5ba4ef0a97d5a9cc0c9800f816a
Detection count: 1,787
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\iLivid\iLivid.exe
Group: Malware file
Last Updated: November 7, 2022
C:\Program Files (x86)\iLivid\ilivid.exe File name: ilivid.exe
Size: 1.94 MB (1946112 bytes)
MD5: f6a90c059c5bacc2a30e9ba3327ecbda
Detection count: 895
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\iLivid\ilivid.exe
Group: Malware file
Last Updated: April 26, 2023
%USERPROFILE%\My Documents\Downloads\iLividSetup-r120-n-bi.exe File name: iLividSetup-r120-n-bi.exe
Size: 1.92 MB (1923880 bytes)
MD5: 2b1532464d1357a97d00677bb8937b85
Detection count: 525
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents\Downloads
Group: Malware file
Last Updated: July 27, 2016
%USERPROFILE%\Downloads\ilivid.exe File name: ilivid.exe
Size: 509.23 KB (509232 bytes)
MD5: ef7e5deb8213abdddac2d5ab30d4cf1e
Detection count: 183
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Downloads
Group: Malware file
Last Updated: July 27, 2016
F:\CS JUAN HERRERO PC(1)\Disco local\Documents and Settings\All Users.WINDOWS.0\Datos de programa\{F2213FEC-3C17-4AAD-8CAE-F67400E8ACAC}\iLividSetupV1.exe File name: iLividSetupV1.exe
Size: 3.02 MB (3024844 bytes)
MD5: fa66983ea440a5a3a2f5df132559c3a3
Detection count: 143
File type: Executable File
Mime Type: unknown/exe
Path: F:\CS JUAN HERRERO PC(1)\Disco local\Documents and Settings\All Users.WINDOWS.0\Datos de programa\{F2213FEC-3C17-4AAD-8CAE-F67400E8ACAC}\iLividSetupV1.exe
Group: Malware file
Last Updated: August 18, 2020
%USERPROFILE%\Local Settings\Application Data\iLivid\iLivid.exe File name: iLivid.exe
Size: 8.24 MB (8242399 bytes)
MD5: ff2d87a718f0f966ad9eaab6ea1a6b6f
Detection count: 133
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\iLivid
Group: Malware file
Last Updated: July 27, 2016
%ALLUSERSPROFILE%\{448606af-ef0d-df3e-4486-606afef01abf}\iLivid Downloader.exe File name: iLivid Downloader.exe
Size: 1.11 MB (1111552 bytes)
MD5: e974c8315ad80d839d79b98c3797e522
Detection count: 117
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\{448606af-ef0d-df3e-4486-606afef01abf}
Group: Malware file
Last Updated: July 27, 2016
%USERPROFILE%\Desktop\Marion\iLividSetupV1.exe File name: iLividSetupV1.exe
Size: 1.3 MB (1304096 bytes)
MD5: 83bda536c4b02781d0fe8dcd580bffaa
Detection count: 108
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop\Marion
Group: Malware file
Last Updated: March 29, 2020
F:\RESERVE LOGICIELS\KEEPVID\iLividSetup-r2149-n-bi.exe File name: iLividSetup-r2149-n-bi.exe
Size: 1.75 MB (1758776 bytes)
MD5: 9ffe9b4807dbd35878959764d4875c57
Detection count: 105
File type: Executable File
Mime Type: unknown/exe
Path: F:\RESERVE LOGICIELS\KEEPVID
Group: Malware file
Last Updated: July 27, 2016
%USERPROFILE%\My Documents\New Folder\iLividSetupV1.exe File name: iLividSetupV1.exe
Size: 311.63 KB (311633 bytes)
MD5: daf3ee2f441fd5dd6e8146a80aeea273
Detection count: 103
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents\New Folder
Group: Malware file
Last Updated: May 13, 2020
%USERPROFILE%\Desktop\iLividSetup-r312-n-bi.exe File name: iLividSetup-r312-n-bi.exe
Size: 1.92 MB (1923880 bytes)
MD5: e48cd0c1da19aad68ba2cab84ceb14a9
Detection count: 101
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: July 27, 2016

Registry Modifications

The following newly produced Registry Values are:

CLSID{2977d8cc-8902-4340-be88-2c676bf96b8d}File name without pathiLivid App.lnkiLivid.lnkHKEY..\..\..\..{RegistryKeys}"Software\iLividSoftware\AppDataLow\Software\ilividmoviestoolbar20Software\AppDataLow\Software\ilividmoviestoolbarhaSOFTWARE\Classes\.torrent\iLivid.torrent_backupSOFTWARE\Classes\Applications\ilivid.exeSOFTWARE\Classes\Applications\iLividSetup-r1312-n-bi.exeSOFTWARE\Classes\Applications\iLividSetup-r1771-n-bc.exeSoftware\Classes\iLivid.torrentSOFTWARE\Clients\Download\iLividSoftware\ilividSoftware\ilividmoviestoolbar20Software\Microsoft\Internet Explorer\Approved Extensions\{2977D8CC-8902-4340-BE88-2C676BF96B8D}Software\Microsoft\Internet Explorer\DOMStorage\www.ilivid.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2977d8cc-8902-4340-be88-2c676bf96b8d}SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ilivid.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ilivid.comSOFTWARE\Microsoft\Internet Explorer\Toolbar\{2977d8cc-8902-4340-be88-2c676bf96b8d}SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SetupDataMngr_iLivid.exeSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2977d8cc-8902-4340-be88-2c676bf96b8d}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2977D8CC-8902-4340-BE88-2C676BF96B8D}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2977D8CC-8902-4340-BE88-2C676BF96B8D}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2977D8CC-8902-4340-BE88-2C676BF96B8D}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iLividSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\!iLividOnceSOFTWARE\RegisteredApplications\iLividSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\user\AppData\Local\iLividSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\user\AppData\Local\iLividSOFTWARE\Wow6432Node\Clients\Download\iLividSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2977d8cc-8902-4340-be88-2c676bf96b8d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{2977d8cc-8902-4340-be88-2c676bf96b8d}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2977d8cc-8902-4340-be88-2c676bf96b8d}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2977D8CC-8902-4340-BE88-2C676BF96B8D}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\iLividSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\!iLividOnceSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iLividSOFTWARE\Wow6432Node\RegisteredApplications\iLividHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}iLividIlivid Download Manager PackagesilividbandoomoviestoolbarCRilividbandoomoviestoolbarIEilividmoviestoolbar20FFilividmoviestoolbar20IEilividmoviestoolbarhaFFilividmoviestoolbarhaIE

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\iLivid%LOCALAPPDATA%\ilividbandoomoviestoolbar%LocalAppData%\iLivid%USERPROFILE%\AppData\LocalLow\iLivid%USERPROFILE%\AppData\LocalLow\ilividbandoomoviestoolbar%USERPROFILE%\AppData\LocalLow\ilividmoviestoolbarha%USERPROFILE%\Application Data\iLivid%USERPROFILE%\Application Data\ilividbandoomoviestoolbar%USERPROFILE%\Application Data\ilividmoviestoolbarha%UserProfile%\Local Settings\Application Data\ilividbandoomoviestoolbar
The following URL's were detected:
Movies Toolbar (Dist. by Bandoo Media, Inc.)ilividlive.com

Related Posts

Loading...