What is Retrovirus?

Retrovirus is software application developed by Cadenza Interactive Games. It is most commonly found on computers running Windows 7 with nearly 51.72% of installations running this operating system. Retrovirus's installer is typically 1.00 GB in size and installs around 60 files.

Retrovirus is most popular in the United States with 59.57% of installations residing in this country.

Retrovirus adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Retrovirus is known to create 3 firewall exceptions to allow inbound and outbound connectivity.

Software Behaviors

Services:
  • Cadenza.NativeDevices.dll runs as a service named 'Wajam Internet Enhancer Service' (Wajam Internet Enhancer Service).
Firewall:
  • Steam.exe is added as a firewall exception for 'C:\Program Files\Steam\Steam.exe'.
  • RetrovirusLauncher.exe is added as a firewall exception for 'C:\Program Files\Steam\STEAMY\SteamApps\common\Retrovirus\RetrovirusLauncher.exe'.
  • SteamTmp.exe is added as a firewall exception for 'C:\Programas\Steam\Steam.exe'.
Scheduled tasks:
  • Steam.exe is scheduled as a task with the class '{CC29CBDA-1EA3-44CC-882F-AFADB7D351AB}' (runs on registration).
  • SteamTmp.exe is scheduled as a task with the class '{694711D6-27A0-4D68-8836-D5F25B163A59}' (runs on registration).

Startup Entries

Startup tasks:
  • Retrovirus.exe is automatically launched at startup through a scheduled task named 1ecc71f2-97a5-4467-a6ba-a33d21ec2cf4-5.
  • Steam.exe is automatically launched at startup through a scheduled task named Steam Login.
Registry entries:
  • Steam.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)' and executes as C:\Program Files\Steam\Steam.exe.
  • SteamTmp.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Steam' and executes as "C:\Program Files\Steam\Steam.exe" -silent.

Software Details

URL:
https://cadenzainteractive.com/games/retrovirus
Support:
https://support.steampowered.com
Installation path:
C:\tSteam\steamapps\common\Retrovirus
Uninstaller:
"C:\tSteam\steam.exe" steaC://uninstall/227800
Size:
1.00 GB
Language:
English

Retrovirus Executable Details

Primary executable:
Cadenza.ReportProvider.exe
Name:
Retrovirus
Path:
C:\tSteam\steamapps\common\Retrovirus\Cadenza.ReportProvider.exe
MD5:
162fca2fea3e0137442b27614f5bed05
SHA-1:
SHA-256:
Files installed by Retrovirus
File Type Filename MD5
DLL
46a565bdcc635a205b2eb6a6daddeda0
EXE
5c46af171aaada26a19c88aa9cdc57a2
EXE
25c604ed213c7e3ecc8e207ba101d802
DLL
12e41931b574efa9a40ce0bb1f470ee3
DLL
4bfc39ba623c115180e1b96ea23a2d44
DLL
1c7104c62544a80d01964612e0f388ba
EXE
162fca2fea3e0137442b27614f5bed05
DLL
cfc597cb962348ac57aa94b67b5b7f3b
EXE
dfad80eb5d4e2cc5bff39c7e3c022602
DLL
63d73bd14a90e7afb142dbb1e2085dd4