Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

3.3.140513.1589 7.69%
3.3.131004.1527 7.69%
3.3.130726.1469 7.69%
3.3.130706.1458 7.69%
3.3.130610.1369 7.69%
3.2.121229.1266 38.46%
3.2.121229.1266 7.69%
3.1.110425.1262 7.69%
3.1.110425.1262 7.69%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
LookupPrivilegeValueW, OpenProcessToken, RegCloseKey, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, AdjustTokenPrivileges
kernel32.dll
HeapFree, HeapReAlloc, GetLastError, GetTickCount, Sleep, CreateProcessW, FindFirstFileW, FindClose, DeleteFileW, GetTempPathW, GetSystemTimeAsFileTime, MoveFileExW, WriteFile, FindResourceW, SizeofResource, LoadResource, LockResource, WaitForSingleObject, CreateMutexW, SetEvent, ExitProcess, FindNextFileW, RemoveDirectoryW, GetVersion, GetCurrentThread, CreateThread, GetCurrentProcessId, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, GetCurrentProcess, OpenProcess, TerminateProcess, ReadFile, InitializeCriticalSection, CreateDirectoryW, GetShortPathNameW, GetModuleFileNameW, CreateEventW, GetCommandLineW, GetCommandLineA, GetVersionExW, OpenMutexW, WriteConsoleW, SetStdHandle, IsProcessorFeaturePresent, GetConsoleMode, GetConsoleCP, SetFilePointer, GetStringTypeW, MultiByteToWideChar, LCMapStringW, WideCharToMultiByte, RtlUnwind, LoadLibraryW, QueryPerformanceCounter, DeleteCriticalSection, GetFileType, GetFileSize, CloseHandle, GetFileTime, CreateFileW, LeaveCriticalSection, EnterCriticalSection, GetProcessHeap, HeapAlloc, InitializeCriticalSectionAndSpinCount, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, FlushFileBuffers, HeapCreate, GetStdHandle, GetCurrentThreadId, SetLastError, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, IsValidCodePage, GetOEMCP, GetACP, InterlockedDecrement, InterlockedIncrement, GetCPInfo, GetModuleHandleW, GetProcAddress, HeapSize, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer
ole32.dll
CoCreateInstance, CoInitializeEx, CoUninitialize, CoInitializeSecurity
psapi.dll
EnumProcessModules, EnumProcesses, GetModuleBaseNameW
shell32.dll
ShellExecuteExW, Shell_NotifyIconW, SHGetSpecialFolderPathW
user32.dll
LoadIconW, wsprintfW, FindWindowExW, DispatchMessageW, LoadMenuW, GetSubMenu, SetForegroundWindow, GetSystemMetrics, TrackPopupMenuEx, DestroyMenu, MessageBoxW, SendMessageW, SetDlgItemTextW, SetTimer, EndDialog, LoadCursorW, RegisterClassExW, GetCursorPos, DialogBoxParamW, DefWindowProcW, CreateWindowExW, GetMessageW, TranslateMessage
wininet.dll
InternetConnectA, HttpOpenRequestA, InternetOpenA, InternetReadFile, HttpQueryInfoA, HttpSendRequestA, InternetCloseHandle
ws2_32.dll
WSAConnect, WSAResetEvent, getaddrinfo, WSACreateEvent, WSAEventSelect, WSAWaitForMultipleEvents, WSAEnumNetworkEvents, WSACloseEvent, WSAAccept

VKSaver.exe

VKSaver by AudioVkontakte.ru

Remove VKSaver.exe
Version:   3.1.110425.1262
MD5:   5544d3a4b0498abade8719f621c8bf2d
SHA1:   991d9062a8cee0e6957b7c45cd8676966af68f61
SHA256:   f26dada24225f1dc8b0128f2eb4da38ebf88c26eb44079ef642b0ca47f78d1a6

Overview

vksaver.exe executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges). It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine).

DetailsDetails

File name:vksaver.exe
Publisher:AudioVkontakte.ru
Product name:VKSaver
Description:VKSaver tray proxy for saving music from vkontakte.ru
Typical file path:C:\ProgramData\vksaver\vksaver.exe
File version:3.1.110425.1262
Size:219.5 KB (224,768 bytes)
Build date:4/25/2011 7:59 AM
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The task 'VKSaverUpdate' runs on boot in the path 'C:\WINDOWS\Tasks\VKSaverUpdate.job'
  • Entry path '\VKSaverUpdate'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\VKSaverUpdate'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'VKSaver' → C:\ProgramData\VKSaver\VKSaver.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00006872%
0.028634%
Kernel CPU:0.00002713%
0.013761%
User CPU:0.00004159%
0.014873%
Kernel CPU time:15,625 ms/min
100,923,805ms/min
Memory
Private memory:1.59 MB
21.59 MB
Private (maximum):3.28 MB
Private (minimum):3.28 MB
Non-paged memory:1.59 MB
21.59 MB
Virtual memory:32.59 MB
140.96 MB
Virtual memory (peak):35.48 MB
169.69 MB
Working set:3.28 MB
18.61 MB
Working set (peak):3.29 MB
37.95 MB
Resource allocations
Threads:2
12
Handles:71
600
GUI GDI count:14
103
GUI USER count:6
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • "C:\Documents and Settings\user\Application data\vksaver\vksaver.exe" -autoupdate
  • "C:\Documents and Settings\user\Application data\vksaver\vksaver.exe"
Owner:SYSTEM
Parent process:svchost.exe (Generic Host Process for Win32 Services by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Basic 38.46%
Windows 7 Ultimate 15.38%
Microsoft Windows XP 15.38%
Windows 7 Home Premium 15.38%
Windows 8.1 Single Language 7.69%
Windows 7 Professional 7.69%

Distribution by countryDistribution by country

Russia installs about 46.15% of VKSaver.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 66.67%
ASUS 13.33%
Hewlett-Packard 6.67%
American Megatrends 6.67%
Acer 6.67%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE