Home Malware Programs Adware Xaven

Xaven

Posted: October 24, 2013

Threat Metric

Ranking: 16,993
Threat Level: 2/10
Infected PCs: 5,881
First Seen: October 24, 2013
Last Seen: September 7, 2023
OS(es) Affected: Windows

Xaven is a browser add-on that claims to provide useful search engine-related functions, but also makes use of unnecessary advertisements to the point of forcing malware experts to categorize Xaven as adware. As adware, Xaven doesn't possess functions designed to attack your computer directly but may unintentionally endanger it or harm its performance by displaying advertisements from third parties without offering ways of disabling this extra content. The limited benefits related to Xaven safely can be said not to be worth the price Xaven asks for them, and deleting Xaven with a good anti-malware scanner is recommended as the safest reaction to its presence on your computer.

Xaven: a Little Something Extra in Your Web Searches

As one of the easiest to design 'features' for simple browser plugins and toolbars, consolidated search engine results and links to various major search sites often are exploited for making Potentially Unwanted Programs and adware seem useful. One such example of this questionable work ethic in action is Xaven, which has been marketed in past incarnations under other brand names including Illoxum and Bomlabio. While Xaven is marketed as a supposed improvement to your ability to find relevant search results that are sorted by appropriate ranking metrics, Xaven actually is primary designed as a form of adware.

Xaven, as an adware program, modifies your browser to display injected advertisements, pop-ups, text links and other forms of advertisements. These attacks disregard any advertisement-related settings that you may currently be using and may affect more than one browser. At this time, malware researchers have confirmed Xaven's compatibility for the major Windows trio: Internet Explorer, Chrome and Firefox – but other browsers also may be affected.

Taking Wing from Xaven's Advertising Experience

Although there may be some minor advantages to your Web-browsing experience legitimately provided through Xaven, SpywareRemove.com malware research team always advises the removal of software that displays excessive advertisements unrelated to its primary functions, and Xaven certainly qualifies under that consideration. Because normal uninstall methods may not remove all of Xaven's software or system changes, the use of anti-malware products while deleting Xaven is commendable as good maintenance protocol for your PC.

Xaven and other Potentially Unwanted Programs essentially identical to Xaven tend to be distributed through software bundles and illicit file-downloading sources that tend to be unsafe for your computer. Always research a file download before installing software from it, and make a habit of examining the installation options offered to you, and SpywareRemove.com malware researchers would be happy to rate your PC as safe from the bulk of Xaven-installing hazards.
Xaven currently is estimated to be limited to Windows PCs, although similar adware programs for Mac and Linux-based operating systems also have been rising in popularity slowly, but steadily.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\Xaven\updateXaven.exe File name: updateXaven.exe
Size: 66.32 KB (66328 bytes)
MD5: ad31d1af69218046900726034919af29
Detection count: 1,991
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Xaven\updateXaven.exe
Group: Malware file
Last Updated: November 1, 2021
%PROGRAMFILES%\Xaven\updateXaven.exe File name: updateXaven.exe
Size: 350.48 KB (350488 bytes)
MD5: 113932827e409f2951a05a183cb47443
Detection count: 719
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Xaven
Group: Malware file
Last Updated: May 5, 2015
%PROGRAMFILES%\Xaven\bin\utilXaven.exe File name: utilXaven.exe
Size: 65.81 KB (65816 bytes)
MD5: 96e035ab1ac1a4275213496d5acea27e
Detection count: 604
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Xaven\bin
Group: Malware file
Last Updated: May 5, 2015
%PROGRAMFILES%\Xaven\updateXaven.exe File name: updateXaven.exe
Size: 317.72 KB (317720 bytes)
MD5: c4c68bf31fb5e3908665514409b00d0f
Detection count: 485
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Xaven
Group: Malware file
Last Updated: May 5, 2015
%PROGRAMFILES%\Xaven\bin\utilXaven.exe File name: utilXaven.exe
Size: 350.48 KB (350488 bytes)
MD5: a0aa3abe2fd3da49c89639f651e7908a
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Xaven\bin
Group: Malware file
Last Updated: May 5, 2015
%PROGRAMFILES%\Xaven\updateXaven.exe File name: updateXaven.exe
Size: 348.95 KB (348952 bytes)
MD5: 3c7dd7eb62851872b1aea0556159468b
Detection count: 124
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Xaven
Group: Malware file
Last Updated: May 5, 2015

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{09A08FC6-0BAE-43AA-9465-332FA630A374}SOFTWARE\Microsoft\Tracing\updatexaven_RASAPI32SOFTWARE\Microsoft\Tracing\updatexaven_RASMANCSSOFTWARE\Microsoft\Tracing\utilxaven_RASAPI32SOFTWARE\Microsoft\Tracing\utilxaven_RASMANCSSOFTWARE\Microsoft\Tracing\xaven_RASAPI32SOFTWARE\Microsoft\Tracing\xaven_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{09A08FC6-0BAE-43AA-9465-332FA630A374}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09A08FC6-0BAE-43AA-9465-332FA630A374}SOFTWARE\Wow6432Node\Microsoft\Tracing\updatexaven_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatexaven_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilxaven_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilxaven_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\xaven_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\xaven_RASMANCSSOFTWARE\Wow6432Node\xavenSOFTWARE\xavenSYSTEM\ControlSet001\services\eventlog\Application\Update xavenSYSTEM\ControlSet001\services\eventlog\Application\Util xavenSYSTEM\CurrentControlSet\services\eventlog\Application\Update xavenSYSTEM\CurrentControlSet\services\eventlog\Application\Util xavenHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}xaven

Additional Information

The following directories were created:
%PROGRAMFILES%\xaven%PROGRAMFILES(x86)%\xaven
Loading...