Xmas

Xmas is an adware bundler that installs several other adware with itself like Congoo Netpass, Outerinfo. Degrades and negatively impact your system.

General information:

Malware Name: Xmas
Malware Type: Adware Bundler
Company Name: 7art-screensavers.com
Company URL: http://www.7art-screensavers.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

7art-screensavers.com provides you the software Xmas that can decorate your desktop on the eve of Christmas. Experience a sense of delight in a nice clock screensaver, full of the Christmas spirit and joy for the upcoming celebration of a great and uniting holiday. We wish you a merry Xmas and a Happy New Year!

Spyware Description:

Xmas is an adware bundler that installs several other adware with itself like Congoo Netpass, Outerinfo. Degrades and negatively impact your system.

Characteristics/Symptoms:

    -> It installs several other adware with itself like Congoo Netpass, Outerinfo. -> Degrades and negatively impact your system.

Additional information might be found here:

google Search at Google for Xmas
bing Search at Bing for Xmas
yahoo Search at Yahoo for Xmas

Processes Running:

Xmas.scr

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\All Users\Start Menu\Programs\7art\Xmas\Run Xmas.lnk 1647 Shortcut
C:\Documents and Settings\[USER]\Application Data\CongooNetpass\News_icon.gif 1040 GIF Image
C:\Documents and Settings\[USER]\Application Data\CongooNetpass\cff.bin 109627 BIN File

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\7art\Xma
C:\Documents and Settings\[USER]\Start Menu\Programs\Outerinf

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\Interface\{6C8F4C7C-4B0E-4844-94C6-4F45FB75B6C6}
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\Interface\{C4202B66-B8BE-49FE-A964-E488637818F8}
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\congootb.WindowData.1