How to remove PathMaxx virus?

What is PathMaxx?

PathMaxx is an advertising application which purpose is to display unwanted content and open pop-up windows:
Pop-up window example
PathMaxx belongs to BrowseFox family of virus programs and can be named by different malware scanners also as:
  • Adware.BrowseFox (Gridinsoft Trojan Killer) 
  • Win.Adware.Browsefox
  • Trojan.Siggen6
  • Trojan.BPlug
  • Adware.Win32.BrowseFox
  • ADWARE/BrowseFox
  • MSIL/BrowseFox
  • Trojan.Yontoo
  • Gen:Variant.Adware.Jaik
  • AdWare.Win32.Kranet
  • Program.BrowseFox-FVX
  • Win32/NetFilter
  • Win.Adware.Swiftbrowse

How to figure out that your computer is infected with PathMaxx?

Here are some symptoms that indicate that your computer is infected with PathMaxx virus:
  • you see a lot of advertising in your browsers;
  • diffirent pop-up windows appear when you clicking on the elements of web pages. Example list of addresses:
    • hXXp://search.webssearches.com
    • hXXp://yxo.warmportrait.com
    • hXXp://f54d6bf2b1.se
    • hXXps://www.favbet.com
    • hXXp://www.freelotto.com/
    • hXXp://ww12.ulayout.com/
    • hXXp://softwaresupermyuk.in/
    • hXXp://www.top-free-to-play.com/
    • hXXp://albumsuper.info/
    • hXXp://ads.adsrvmedia.net/
    • hXXp://www.quickprofitssystem.co/
    • hXXp://lp.ilividnewtab.com/
  • at least one of the following folders is present on your computer: 
    • C:\Program Files\PathMaxx
    • C:\Program Files (x86)\PathMaxx
  • at least one of the following registry items is present on your computer:
    • HKCU\Software\PathMaxx
    • HKLM\SOFTWARE\PathMaxx
    • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PathMaxx
    • HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
    • HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
    • HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
    • HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    • HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
    • HKCR\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
  • at least one of the following files is running on your computer:
    • {61bc9620-8c15-4bf6-b992-006d0996a7bb}Gw64.sys
    • {3e8df589-8978-47fb-b852-51e65d6286ca}Gw64.sys
    • {c9b41a3a-ffd8-4839-a7f5-4167345d7600}Gw64.sys
    • 3e8df589897847fbb852.dll
    • 3e8df589897847fbb85251e65d6286ca.dll
    • 3e8df589897847fbb85251e65d6286ca64.dll
    • 3e8df589897847fbb85264.dll
    • 61bc96208c154bf6b992.dll
    • 61bc96208c154bf6b992006d0996a7bb.dll
    • 61bc96208c154bf6b992006d0996a7bb64.dll
    • 61bc96208c154bf6b99264.dll
    • c9b41a3affd84839a7f5.dll
    • c9b41a3affd84839a7f54167345d7600.dll
    • c9b41a3affd84839a7f564.dll
    • PathMaxx.BrowserAdapter
    • PathMaxx.BrowserAdapter64.exe
    • PathMaxx.expext.exe
    • PathMaxx.expextdll.dll
    • PathMaxx.PurBrowse64.exe
  • at least one file with the following services is installed on your computer:
    • {3e8df589-8978-47fb-b852-51e65d6286ca}Gw64
    • {61bc9620-8c15-4bf6-b992-006d0996a7bb}Gw64
    • {c9b41a3a-ffd8-4839-a7f5-4167345d7600}Gw64
  • at least one file with the following MD5 hashes is present on your computer:
    • F46042F866EBB4F11A159CC0792DDC45
    • 19DDCD3FA850E1B58D4E8F617CEEF1FE
    • 3A6E65EDE5B01DA2B9918D1BE4E27C73
    • 579C046758B6D69393C2CEE1F8D1CB9A
    • 8AFF90DC64BF765B9E50595DE27CC597
    • 16AF0F09E04BE897B468323F111BD545
    • 79AB79F0207BE5B390F0946B8097490F
    • C3E30EF781D07E6430C851390C215E68
    • F1E114C85F959F11AE277B0880A7C2E4
    • F62113E6FEA8FF033C74FBD86208FBB6
    • BDC54A1BCB4B546B16FEC3A478B63B4B
    • 32044332D702B89D8A0E34867D8203E3
    • 128C36FF3C06C956DF96DDCF9BDD6F16
    • 2E1BA1D68A92F9EF813EFA67C473A1ED
    • 58015B194A1993B132334958C705C9ED
    • A00F2F59DDC863BB297BBED0E856BC2D
    • 4017786B1270D8A7D57F81A96914C80D

    How to get rid of PathMaxx?

    Follow this guide to remove PathMaxx from your computer completely.

    Step 1.  Try to remove PathMaxx using tools of Windows operating system.

    If you have installed Windows 8, press Start button on the screen or Windows button on your keyboard, start typing "programs and features" and choose "Programs and Features" in the appeared menu:
    Programs and Features
    If you are using Windows 7, press Start button and choose "Control panel": 
    Windows 7 start menu

    Look for PathMaxx in the list of installed programs, select it and press Uninstall button:
    Example of the list of installed programs
    Now reboot your computer and check the result. If the advertising is still present, please move to the next step.

    Step 2. Remove PathMaxx completely using Gridinsoft Trojan Killer tool

    Gridinsoft Trojan Killer is a powerful all-in-one tool aimed to kill diffirent kinds of malware. It has no analogues on the quality of malware and browser hijackers removal. Gridinsoft Trojan Killer also has professional support team that can resolve your problem remotely even though Trojan Killer didn't find any threat on your PC.
    Please, follow the guide below to remove PathMaxx malware from your computer.
    • Close all your programs and browsers
    • Install Gridinsoft Trojan Killer and run it by double-clicking on the icon on your desktop 
      Trojan Killer icon on the desktop
    • Run Standart scan using Scan tab of your Trojan Killer
      Scan tab of Trojan Killer
    • After the scanning completed mark all items as Move to quarantine and press Apply button to remove all dangerous items from your computer. Reboot your PC if Trojan Killer asks about it:
      Scan results
    • Now you have to clean all your browsers. Go to Tools tab and press Reset browser settings button:
      Tools tab of Trojan Killer
    • Mark all your browsers as shown below and press Reset button:
      Resetting browser settings
    • Reboot your PC and check the result
    Now your computer should be cleaned of PathMaxx virus. 

    If you still notice any signs of PathMaxx, please send your request to the Trojan Killer Support. Specialists from Gridinsoft will help you to remove any kind of threats *

    * Please notice that Trojan Killer Support service is able for registred users only

    No comments:

    Post a Comment