Read the same in:    English  Deutsch  Polski  Русский  
You are welcome to subscribe to "New articles in Knowledge Base" mailing list.




Virus Activity

Virus Activity

virus activity is normal




 
Search :  
Search tips Article ID # :     
 

XJR Antivirus

Rogue security software is a form of computer malware that deceives or misleads users into paying for the fake or simulated removal of malware. Rogue security software, in recent years, has become a growing and serious security threat in desktop computing. For your convenience in this section we gathered all known rogue security software in one list by alphabet.


XJR Antivirus

 ID Article: 4425    Other languages:  Deutsch  Polski  Русский      Views for 7 days 2    Last modified on 2010 Jul 09 09:36 Printable version

1. Program description

XJR Antivirus is a type of misleading application that pretends to be legitimate security software, such as an antivirus scanner or registry cleaner, but which actually provides the user with little or no protection (Rogue Security Software). The author also  created AKM Antivirus 2010 Pro and RST Antivirus 2010.

2. Actions

Once the scan is started XJR Antivirus generates and shows fake messages about viruses, Trojans and worms detected on the computer. Still the detected viruses cannot be deleted unless the program license is purchased.

3. Files

During the installation XJR Antivirus copies the following files to the hard drive:

%ProgramFiles%\wp4.dat
%ProgramFiles%\adc_w32.dll
%ProgramFiles%\alggui.exe
%ProgramFiles%\skynet.dat
%ProgramFiles%\svchost.exe
%ProgramFiles%\wp3.dat
%ProgramFiles%\XJR Antivirus\XJR Antivirus.exe
%UserProfile%\Desktop\XJR Antivirus.lnk
%UserProfile%\Start Menu\Programs\XJR Antivirus\XJR Antivirus.lnk

4. System registry

In order to function normally XJR Antivirus creates the following branches in the system registry:

HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32
HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
HKEY_CURRENT_USER\software\XJR Antivirus
HKEY_CURRENT_USER\software\XJR Antivirus\wpp
HKEY_CURRENT_USER\software\XJR Antivirus\wpp\Registration
HKEY_CURRENT_USER\software\XJR Antivirus\wpp\setdata
HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus
HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\Registration
HKEY_CURRENT_USER\software\XJR Antivirus\XJR Antivirus\setdata

5. Screenshots of the program


 Did the provided info help you?

                       

 Give your detailed feedback.

 

Kaspersky Lab

Copyright © 1997-2013 Kaspersky Lab
Site map  |   Contact us  |   International Support Service  |  Send us a suspected file
Login CompanyAccount  |   Register  |   FAQ for CompanyAccount  |   Login Your Personal Cabinet

Stay connected