video-saver152.exe

The application video-saver152.exe has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “video-saver”. This executable runs as a local area network (LAN) Internet proxy server listening on port 13828 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. This file is typically installed with the program Video-Saver by Video-Saver Soft which is a potentially unwanted software program. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
e9f2657d05ed097eaeaa329c9b0c93b7

SHA-1:
03eaf91f836d6dbc37e6ab1bc2ef5dc31fbcc61f

SHA-256:
22024815e68bc0e5e67163b1988af88d950801c1db0a64e266a0cb11ee25b0d3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 11:04:19 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Revizer.Service.O
14.3.19.23

File size:
162 KB (165,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\video-saver\video-saver152.exe

File PE Metadata
Compilation timestamp:
1/24/2014 1:27:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
3072:r8BY2C93xZSsGRGj5fRXsYGEu06KWUHQvvRTyGWTBfHdn:r83C0sGRGLsYVutbiQvZTZWTB/B

Entry address:
0x12A36

Entry point:
E8, 48, 5A, 00, 00, E9, 95, FE, FF, FF, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, E8, BE, 42, 00, 00, 74, 05, E9, B2, 5A, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44, 24, 08, 5F, C3, 8B...
 
[+]

Entropy:
6.5621

Code size:
111.5 KB (114,176 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:13828/

Local host port:
13828

Default credentials:
No


Service
Display name:
video-saver

Description:
Video-Saver

Type:
Win32OwnProcess


The file video-saver152.exe has been discovered within the following program.

Video-Saver  by Video-Saver Soft
This toolbar/web browser extension is ad/search-supported that is typically installed as an optional offer, users generally have this bundled with 3rd party software.
86% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

TCP (HTTP):
Connects to snt-re2-8c.sjc.dropbox.com  (108.160.163.43:80)

TCP (HTTP):
Connects to snt-re2-8b.sjc.dropbox.com  (108.160.163.42:80)

TCP (HTTP):
Connects to mrs02s05-in-f5.1e100.net  (173.194.35.101:80)

TCP (HTTP):
Connects to mrs02s05-in-f14.1e100.net  (173.194.35.110:80)

TCP (HTTP):
Connects to mrs02s05-in-f1.1e100.net  (173.194.35.97:80)

TCP (HTTP):
Connects to mrs02s04-in-f0.1e100.net  (173.194.39.32:80)

TCP (HTTP SSL):
Connects to ec2-52-6-82-78.compute-1.amazonaws.com  (52.6.82.78:443)

TCP (HTTP):
Connects to driveridentifier.com  (78.46.64.194:80)

TCP (HTTP):
Connects to dow1.drivereasy.com  (198.27.75.32:80)

TCP (HTTP):
Connects to 84-235-64-142.static.saudi.net.sa  (84.235.64.142:80)

Remove video-saver152.exe - Powered by Reason Core Security