What is Retrovirus?

Retrovirus is software application developed by Cadenza Interactive Games. It is most commonly found on computers running Windows 7 with nearly 51.72% of installations running this operating system. Retrovirus's installer is typically 1.00 GB in size and installs around 60 files.

Retrovirus is most popular in the United States with 59.57% of installations residing in this country.

Retrovirus adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Retrovirus is known to create 3 firewall exceptions to allow inbound and outbound connectivity.

Software Behaviors

Services:
  • Cadenza.NativeDevices.dll runs as a service named 'Wajam Internet Enhancer Service' (Wajam Internet Enhancer Service).
Firewall:
  • Steam.exe is added as a firewall exception for 'C:\Program Files\Steam\Steam.exe'.
  • RetrovirusLauncher.exe is added as a firewall exception for 'C:\Program Files\Steam\STEAMY\SteamApps\common\Retrovirus\RetrovirusLauncher.exe'.
  • SteamTmp.exe is added as a firewall exception for 'C:\Programas\Steam\Steam.exe'.
Scheduled tasks:
  • Steam.exe is scheduled as a task with the class '{CC29CBDA-1EA3-44CC-882F-AFADB7D351AB}' (runs on registration).
  • SteamTmp.exe is scheduled as a task with the class '{694711D6-27A0-4D68-8836-D5F25B163A59}' (runs on registration).

Startup Entries

Startup tasks:
  • Retrovirus.exe is automatically launched at startup through a scheduled task named 1ecc71f2-97a5-4467-a6ba-a33d21ec2cf4-5.
  • Steam.exe is automatically launched at startup through a scheduled task named Steam Login.
Registry entries:
  • Steam.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)' and executes as C:\Program Files\Steam\Steam.exe.
  • SteamTmp.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Steam' and executes as "C:\Program Files\Steam\Steam.exe" -silent.

Software Details

URL:
https://cadenzainteractive.com/games/retrovirus
Support:
https://support.steampowered.com
Installation path:
C:\tSteam\steamapps\common\Retrovirus
Uninstaller:
"C:\tSteam\steam.exe" steaC://uninstall/227800
Size:
1.00 GB
Language:
English

Retrovirus Executable Details

Primary executable:
Cadenza.ReportProvider.exe
Name:
Retrovirus
Path:
C:\tSteam\steamapps\common\Retrovirus\Cadenza.ReportProvider.exe
MD5:
162fca2fea3e0137442b27614f5bed05
SHA-1:
SHA-256:
Files installed by Retrovirus
File Type Filename MD5
DLL
1cf4d20e36ff02178eaac531730145e1
DLL
00b863f2d8366a5bd5e340595f9bd1cf
DLL
2c7f8e76c7715df658db7ea44d0b9069
DLL
c50f9cec69c907dff45bfc7e83255fa2
DLL
c6cda85b2137d1d2d81572398ae630ad
DLL
ae6fac1335f253dacb6836b3fd35df88
DLL
2f36484e310a1cbf7d7068778578a665
EXE
9aaab8451da4d04926c9f73c289c282c
EXE
8f53ada5f97ba99e2f4b6e0cb7a6f977
DLL
b19e94dbb6a6fe370afa6d0086087b60