Max Spyware defender

Status
Not open for further replies.
Do you have the Farbar Recovery Scan Tool icon still on your desktop?

Please, if you do we need to do this:

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

start
Folder:C:\Documents and Settings\sta\Local Settings\Application Data\Max Secure Software
Folder:c:\program files\Max Spyware Detector
Folder:C:\Program Files\DoctoAntivirus
File:c:\windows\system32\drivers\MaxProtector64.sys
File:c:\windows\system32\drivers\MaxProc64.sys
File:c:\windows\system32\drivers\SDActMon2K.sys
File:C:\Program Files\DoctoAntivirus\MaxWatchDogService.exe
end
After you place the newest Fixlog.txt beside the FRST icon,
Just open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Please post this log when done.
 
Farbar Scan Log - 2014_02_28

:rockon:Juliet: Have a nice weekend.

The log follows.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-02-2014 02
Ran by John at 2014-02-28 20:46:15 Run:3
Running from C:\Users\John\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
Folder:C:\Documents and Settings\sta\Local Settings\Application Data\Max Secure Software
Folder:c:\program files\Max Spyware Detector
Folder:C:\Program Files\DoctoAntivirus
File:c:\windows\system32\drivers\MaxProtector64.sys
File:c:\windows\system32\drivers\MaxProc64.sys
File:c:\windows\system32\drivers\SDActMon2K.sys
File:C:\Program Files\DoctoAntivirus\MaxWatchDogService.exe
end
*****************

========================= Folder:C:\Documents and Settings\sta\Local Settings\Application Data\Max Secure Software ========================
Directory Not Found
====== End of Folder: ======

========================= Folder:c:\program files\Max Spyware Detector ========================
Directory Not Found
====== End of Folder: ======

========================= Folder:C:\Program Files\DoctoAntivirus ========================
Directory Not Found
====== End of Folder: ======

========================= File:c:\windows\system32\drivers\MaxProtector64.sys ========================
MD5: 06C061901EC64CD8AA77667124B05A64
Creation and modification date: 2014-02-08 19:36 - 2014-02-07 11:20
Size: 0077792
Attributes: ----A
Company Name: Max Secure Software
Internal Name: MaxProtector64.sys
Original Name: MaxProtector64.sys
Product Name: Max Secure Software Self Protection Driver
Description: Max Secure Software Self Protection Driver
File Version: 2, 0, 1, 1
Product Version: 19, 0, 2, 1
Copyright: (c) Max Secure Software. All rights reserved.
====== End Of File: ======

========================= File:c:\windows\system32\drivers\MaxProc64.sys ========================
MD5: A748B6BBEA5CA57F41168767523C76A3
Creation and modification date: 2014-02-08 19:36 - 2014-02-07 11:20
Size: 0068576
Attributes: ----A
Company Name: Max Secure Software
Internal Name: MaxProc64.sys
Original Name: MaxProc64.sys
Product Name: Max Secure Software Self Protection Driver
Description: Max Secure Software Self Protection Driver
File Version: 1, 0, 0, 1
Product Version: 19, 0, 2, 1
Copyright: (c) Max Secure Software. All rights reserved.
====== End Of File: ======

========================= File:c:\windows\system32\drivers\SDActMon2K.sys ========================
MD5: E65428520D0ED2DEE370B7104B9FE1F5
Creation and modification date: 2014-02-08 19:36 - 2014-02-07 11:20
Size: 0074208
Attributes: ----A
Company Name: Max Secure Software
Internal Name: SDActMon2K
Original Name: SDActMon2K.sys
Product Name: Max Secure Software Active Monitor
Description: Max Secure Software Active Monitor Driver
File Version: 2, 0, 1, 1
Product Version: 19, 0, 2, 1
Copyright: (c) Max Secure Software. All rights reserved.
====== End Of File: ======

========================= File:C:\Program Files\DoctoAntivirus\MaxWatchDogService.exe ========================
"C:\Program Files\DoctoAntivirus\MaxWatchDogService.exe" not found.
====== End Of File: ======

==== End of Fixlog ====

John
 
I want to try this one more time using it a different way.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

start
c:\windows\system32\drivers\MaxProtector64.sys
C:\Documents and Settings\sta\Local Settings\Application Data\Max Secure Software
c:\program files\Max Spyware Detector
C:\Program Files\DoctoAntivirus
c:\windows\system32\drivers\MaxProc64.sys
c:\windows\system32\drivers\SDActMon2K.sys
end
Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
 
3/32014 Fixlog

:rockon:

Juliet: Not much happened. Farbar ran for less tha 145econds. Ask to reboot and generate the fixlog.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-03-2014
Ran by John at 2014-03-03 06:45:54 Run:4
Running from C:\Users\John\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
c:\windows\system32\drivers\MaxProtector64.sys
C:\Documents and Settings\sta\Local Settings\Application Data\Max Secure Software
c:\program files\Max Spyware Detector
C:\Program Files\DoctoAntivirus
c:\windows\system32\drivers\MaxProc64.sys
c:\windows\system32\drivers\SDActMon2K.sys
end
*****************
Could not move "c:\windows\system32\drivers\MaxProtector64.sys" => Scheduled to move on reboot.
"C:\Documents and Settings\sta\Local Settings\Application Data\Max Secure Software" => File/Directory not found.
c:\program files\Max Spyware Detector => Moved successfully.
"C:\Program Files\DoctoAntivirus" => File/Directory not found.
Could not move "c:\windows\system32\drivers\MaxProc64.sys" => Scheduled to move on reboot.
Could not move "c:\windows\system32\drivers\SDActMon2K.sys" => Scheduled to move on reboot.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-03-03 06:47:20)<=
"c:\windows\system32\drivers\MaxProtector64.sys" => File could not move.
"c:\windows\system32\drivers\MaxProc64.sys" => File could not move.
"c:\windows\system32\drivers\SDActMon2K.sys" => File could not move.
==== End of Fixlog ====


John
 
Computer Reboot

:rockon:

Juliet: Yes, it rebooted. Could not have run for more than 10 seconds beforee the reboot message appeared. As far as I can tell, all is fine. Everything seems to be working.

John
 
what a stinker that was!

Let's run these 2 scans that are quick to check ofr anything that might be left over.


-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.



  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


thisisujrt.gif

Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
adW and Jrt Scans

:rockon:

Juliet: Ran both scans. Logs below. One noteworthy observation: while JRT was scanning the Registry ther were 4 access is denied messages.

JRT[\u]

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by John on Tue 03/04/2014 at 11:33:52.22
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 03/04/2014 at 11:39:03.92
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



adw

# AdwCleaner v3.020 - Report created 04/03/2014 at 11:18:13
# Updated 27/02/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : John - JOHN-PC
# Running from : C:\Users\John\Desktop\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16533

*************************
AdwCleaner[R0].txt - [6373 octets] - [17/02/2014 19:39:50]
AdwCleaner[R1].txt - [563 octets] - [04/03/2014 11:18:13]
AdwCleaner[S0].txt - [6710 octets] - [17/02/2014 19:40:45]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [682 octets] ##########
 
Well, looking good so far.

One last scan to check for remnants.
The below can take quite a while to run depending on how full your computer is, also don't be alramed if it finds things since I am expecting this and I feel will already be contained in quarantine folders.

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
 
eset scan results

:rockon:
Juliet: No kidding about taking a long time. Slightly over 3.5 hours. the log follows. Seems to be some other threats to be removed.

C:\FRST\Quarantine\MaxSpywaredetector.exe17-02-2014_19-23-04 a variant of Win32/MaxPCsecure potentially unwanted application
C:\FRST\Quarantine\Max Spyware Detector03-03-2014_06-45-54\LiveUpdate.exe a variant of Win32/MaxPCsecure potentially unwanted application
C:\Users\Administrator\Desktop\ccsetup407.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\e446e9b-7b7048ea a variant of Java/Exploit.Blacole.AF trojan
C:\Users\John\Desktop\DesktopFolders\Desktop Folders & Shortcuts\SetupImgBurn_2.5.7.0.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application

Playing around with the real cool smilies.


John :cool:
 
Seems to be some other threats to be removed.

Not bad. What you see is mostly adware that came bundled with items you downloaded and a couple of files in quarantine.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

start
C:\Users\Administrator\Desktop\ccsetup407.exe
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\e446e9b-7b7048ea
C:\Users\John\Desktop\DesktopFolders\Desktop Folders & Shortcuts\SetupImgBurn_2.5.7.0.exe
Reboot:
end
Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Let me see this log when it's done.


Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
 
FRST (again) and Security Check

:rockon:

:cowboy:


:santa:
Juliet: Even I can read the Fixlog. Frst moved the stuff into quarantine. As you knew it would. You are GOOD!! Ran Security Check. Some out of date stuff (a constant battle to stay up to date) and some other useful stuf - like defrag the disk. Should I turn TeaTimer back on? As I remember things, it really slowed down my system. I'll put some new smilies in so you won't get bored. I know Christmas has come and gone; it is a ice smilie.

Fixlog

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-03-2014
Ran by John at 2014-03-06 11:40:00 Run:5
Running from C:\Users\John\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
C:\Users\Administrator\Desktop\ccsetup407.exe
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\e446e9b-7b7048ea
C:\Users\John\Desktop\DesktopFolders\Desktop Folders & Shortcuts\SetupImgBurn_2.5.7.0.exe
Reboot:
end
*****************
C:\Users\Administrator\Desktop\ccsetup407.exe => Moved successfully.
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\e446e9b-7b7048ea => Moved successfully.
C:\Users\John\Desktop\DesktopFolders\Desktop Folders & Shortcuts\SetupImgBurn_2.5.7.0.exe => Moved successfully.

The system needed a reboot.
==== End of Fixlog ====


Security Check

Results of screen317's Security Check version 0.99.80
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Max Spyware Detector
SpywareBlaster 5.0
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java 7 Update 45
Java version out of Date!
Adobe Flash Player 11.9.900.117 Flash Player out of Date!
Adobe Reader 10.1.9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 14 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
 
Should I turn TeaTimer back on? As I remember things, it really slowed down my system.
Thats up to you, depends on if you want to deal with it or not.



http://get.adobe.com/flashplayer/
The above is for the latest version o Adobe flash, be sure to unclick McAfee security scan.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
http://get.adobe.com/reader/
Adobe Reader, be sure to unclick McAfee security scan.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Install Java:

Please go here to install Java
  • click on the Free Java Download Button
  • click on Agree and start Free download
  • click on Run
  • click on run again
  • click on install
  • when install is complete click on close

~~~~~~~~~~~~~~~~~~~~~~~~~~

Let's remove quarantine folders and tools used then I'll send you on your way.


Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

Run FRST/FRST64 and press the Fix button just once and wait.
no needed to post the log this time.


start
DeleteQuarantine:
end


~~~~~~~~~~~~~~~~~~~~~~~~

  1. Download Delfix from here
  2. Ensure Remove disinfection tools is ticked
    Also tick:
    • Create registry backup
    • Purge system restore
    delfix.jpg

  3. Click Run


Ant tools or files found left over can simply be deleted.

~~~~~~~~~~~~~~~~~

Your good to go, good job!

Please take the time to read over a few of my preventive tips.

Computer Security
http://malwareremoval.com/forum/viewtopic.php?p=557960#p557960
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Be prepared for CryptoLocker:

Cryptolocker Ransomware: What You Need To Know

CryptoLocker Ransomware Information Guide and FAQ

to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

CryptoPrevent.JPG


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please navigate to Microsoft Windows Updates and download all the "Critical Updates" for Windows.


Firefox 3
The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 3, added powerful new features that make your online experience even better. It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

AdblockPlus
  • AdblockPlus, Surf the web without annoying ads!
  • Blocks banners, pop-ups and video ads - even on Facebook and YouTube
  • Protects your online privacy
  • Two-click installation, It's free!
  • click the icon that corresponds to your browser and download.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
WOT Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.
  • Green should be good to go
  • Yellow for caution
  • Red to stop



~~~~~~~~~~~~~~~~~~~~~~~~~~~~
How to prevent Malware: Created by Miekiemoes


WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article (http://www.forbes.com/sites/eliseackerman/2013/01/11/us-department-of-homeland-security-calls-on-computer-users-to-disable-java/
and this article (http://www.nbcnews.com/technology/technolog/us-warns-java-software-security-concerns-escalate-1B7938755

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser (http://www.geekstogo.com/2600/how-to-disable-java-in-your-web-browser/) and How to unplug Java from the browser ([url]http://krebsonsecurity.com/how-to-unplug-java-from-the-browser/))[/url]


Avoid P2P

P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.
*********************************************
Please read the following safe computing articles..

Secure My Computer: A Layered Approach


Free Antivirus-AntiSpyware-Firewall Software

Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
 
Delfix

:rockon:

Juliet: Sorry. Delfix will not download or run??

Start>Control Panel>Programs and Features and there is still an entry for Spyware max. Should I worry about this?

John

:angel:
:thanks:
 
Your computer security is probably interfering. Drop into safe mode with networking and attemp it again.
If it still wont work we can manually remove those tools.

~~~~~~~~~~~~~~~~~~~~~~

Let's see if we can get rid of that last entry. It's been rendered useless and ineffective.

  • Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on Max Spyware Defender
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
.
 
Last edited:
Everything is good

:thanks::thanks:

Juliet: All programs removed. No entry in Control Panel >Programs and Features.

Thanks for sticking with me through this massive effort to remove Spyware.

I'll probably remove Java since I do not think I need it for anything.

Thanks for all the other links.

John
:bigthumb::yahoo:
 
Glad we could help. :)
sparkle.gif


Since this issue appears resolved ... this Topic is closed.
 
Status
Not open for further replies.
Back
Top