Home Malware Programs Adware PathMaxx

PathMaxx

Posted: February 19, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 632
First Seen: February 19, 2014
Last Seen: July 1, 2023
OS(es) Affected: Windows


PathMaxx is adware that may show non-stop pop-up ads, discount coupons, offers, sponsored links, deals and sales via a pop-up box on various online shopping websites or other websites. The pop-up ads of PathMaxx may be shown as boxes, which may carry numerous discount coupons and sale deals, which, if clicked, may show pop-up advertisements and banners on the PC that supposedly come to the computer user from PathMaxx. PathMaxx may embed a browser extension, plug-in or add-on in Internet Explorer, Mozilla Firefox and Google Chrome Web browsers when the computer user installs various free programs from questionable download websites on the Internet that might had packed into their installation PathMaxx. When the PC user installs any free app, he may also install PathMaxx on the computer system.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{cf6bd74e-5c54-4129-8b10-c931bc156fe8}{F6A014F2-42AC-46DE-B38C-2841A7E31CBE}{FB6EB5E6-4D16-4461-9C01-D74247281D5A}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{cf6bd74e-5c54-4129-8b10-c931bc156fe8}Software\Microsoft\Internet Explorer\Approved Extensions\{d11b6b8a-27ce-431b-bd5e-8a3c49528f75}SOFTWARE\Microsoft\Tracing\Pathmaxx_RASAPI32SOFTWARE\Microsoft\Tracing\Pathmaxx_RASMANCSSOFTWARE\Microsoft\Tracing\updatePathmaxx_RASAPI32SOFTWARE\Microsoft\Tracing\updatePathmaxx_RASMANCSSOFTWARE\Microsoft\Tracing\utilPathmaxx_RASAPI32SOFTWARE\Microsoft\Tracing\utilPathmaxx_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{cf6bd74e-5c54-4129-8b10-c931bc156fe8}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cf6bd74e-5c54-4129-8b10-c931bc156fe8}SOFTWARE\PathmaxxSOFTWARE\Wow6432Node\Microsoft\Tracing\Pathmaxx_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Pathmaxx_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatePathmaxx_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatePathmaxx_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilPathmaxx_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilPathmaxx_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{cf6bd74e-5c54-4129-8b10-c931bc156fe8}SOFTWARE\Wow6432Node\PathmaxxSYSTEM\ControlSet001\services\eventlog\Application\Update PathmaxxSYSTEM\ControlSet001\services\eventlog\Application\Util PathmaxxSYSTEM\ControlSet001\services\Update PathmaxxSYSTEM\ControlSet001\services\Util PathmaxxSYSTEM\ControlSet002\services\eventlog\Application\Util PathMaxxSYSTEM\ControlSet002\services\Update PathMaxxSYSTEM\ControlSet002\services\Util PathMaxxSYSTEM\CurrentControlSet\services\eventlog\Application\Update PathmaxxSYSTEM\CurrentControlSet\services\eventlog\Application\Util PathmaxxSYSTEM\CurrentControlSet\services\Update PathmaxxSYSTEM\CurrentControlSet\services\Util PathmaxxHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Pathmaxx

Additional Information

The following directories were created:
%PROGRAMFILES%\Pathmaxx%PROGRAMFILES(x86)%\Pathmaxx%Temp%\Pathmaxx
The following URL's were detected:
PathMaxx
Loading...