Beware of maxathon cloud browser

Aggravatorx

Level 5
Thread author
Verified
Well-known
Jan 30, 2013
210
First wanted to say hello to all Im from NJ and i want to let all you know to beware of Maxathon cloud browser.I installed a few days ago and they now have skins in there addons today ie10 and Maxathon were crashing and freezing.new something was not right.and i have windows 8 64 version and just read earlier on here about Norton 2013 not fully protecting 64 versions
of windows.well I have Norton and it (did not) protect me. I was also noticing how sometimes Norton sonar would tell me downloads were safe and alot of times it stopped giving file rep on downloads with Waterfox and IE 10 64 versions.. so i scanned with backup defense Hitman pro and it found (four) ransomeware trojans (sorry) i did not save but deleted asap.so be careful on maxathon cloud browser or skins from there .and the thread of Norton not fully protecting 64 systems is true i must say.hope it helps someone out.
 

Fiery

Level 1
Jan 11, 2011
2,007
Welcome to MalwareTips! :)

I googled Maxathon cloud browser and didn't seem to find anything about it distributing malware. The browser is also available in reputable download sites. Perhaps you got the trojans elsewhere through a drive-by exploit?

Do you still have the HitmanPro log of the 4 detections?
 

Aggravatorx

Level 5
Thread author
Verified
Well-known
Jan 30, 2013
210
C:\Users\mark\AppData\Roaming\Maxthon3\Public\Apps\{39E07680-FED3-4333-BCEB-BFA869D14AF4}\ -> Deleted
C:\Users\mark\AppData\Roaming\Maxthon3\Public\Apps\{5DC7501B-E433-46B1-BAC2-95D23A1E368D}\ -> Deleted
C:\Users\mark\AppData\Roaming\Maxthon3\Public\Apps\{9FD411BE-B3AC-41D2-997F-E399DAD2DEA4}\ -> Deleted
C:\Users\mark\AppData\Roaming\Maxthon3\Public\Apps\{A378711C-4C1C-427E-AA9B-C9DF04F2E9A1}\ -> Delete
Fiery said:
Welcome to MalwareTips! :)

or perhaps there skins to customize browser

I googled Maxathon cloud browser and didn't seem to find anything about it distributing malware. The browser is also available in reputable download sites. Perhaps you got the trojans elsewhere through a drive-by exploit?

Do you still have the HitmanPro log of the 4 detections?


exterminator20 said:
Welcome to MT :)

thank you
 

Fiery

Level 1
Jan 11, 2011
2,007
Thanks for the log :)

Interesting, I can't find any information on it. Thanks for the heads up.
 

Aggravatorx

Level 5
Thread author
Verified
Well-known
Jan 30, 2013
210
Fiery said:
Thanks for the log :)

Interesting, I can't find any information on it. Thanks for the heads up.

no problem I downloaded Maxathon from there site and the only thing i can think of was perhaps the browser or there addons page for themes.but one thing is certain
norton did nothing.so until g-data 2014 comes out thought i would give comodo 2013 a try.

thanks for replying
 

Littlebits

Retired Staff
May 3, 2011
3,893
I very serious doubt that you got any malware from Maxthon or their website. I have it install and I have absolutely no malware. More then likely Hitman Pro is detecting false positives or you got the malware from some other source and it happened to be located in Maxthon's AppData folder.

The current version is 4.0.0.2000, it looks like you are using an older version 3. It maybe open to vulnerabilities which could have caused you to get exploited while visiting a malicious site.

The best place to get answers and report this issue is the Maxthon Forums.

Maxthon is a community based project with a lot of supporters.

Maxthon is certified 100% clean of adware by Softpedia

You can even download Softpedia's own edition of it or a portable version.
Softpedia has even giving it a 5 star rating in its reviews.

If Maxthon was the cause of the malware then you would be able to see more reports, so far there isn't any others that I can find.

Thanks.:D
 

Fiery

Level 1
Jan 11, 2011
2,007
Littlebits said:
I very serious doubt that you got any malware from Maxthon or their website. I have it install and I have absolutely no malware. More then likely Hitman Pro is detecting false positives or you got the malware from some other source and it happened to be located in Maxthon's AppData folder.

That's my hunch as well. It's probably an add-on or some sort
 

Moose

Level 22
Jun 14, 2011
2,271
I have try Maxthon's Browser for a three month a while back and had Drive
by Trojan's enter on my system. Meaning that I have similar experience with Maxthon's Browser. Remember the browser is the weakest point of
entry in my opinion for Malware, adware, ect.....I just unistall and when to
Chrome with extensions. My secondary browser is Waterfox with extensions.
 

Littlebits

Retired Staff
May 3, 2011
3,893
Moose said:
I have try Maxthon's Browser for a three month a while back and had Drive
by Trojan's enter on my system. Meaning that I have similar experience with Maxthon's Browser. Remember the browser is the weakest point of
entry in my opinion for Malware, adware, ect.....I just unistall and when to
Chrome with extensions. My secondary browser is Waterfox with extensions.

Were you using the Trident engine or the Webkit engine?
By default it uses the same engine as Google Chrome but it is not Chromium, Safari's Webkit.

In my opinion is is just as safe as any other browser it has built-in security features if you had them enabled like AdHunter, Magic Fill, Do Not Track, it own proxy servers, Flash Block, Advanced Download Manager, disable Java, Active X Block, etc. Of coarse it is not my choice because it is somewhat complicated compared to Firefox or Google Chrome.

You can pick up malware with any browser if you don't know how to use its security features and don't watch what you download.

Thanks.:D
 

Aggravatorx

Level 5
Thread author
Verified
Well-known
Jan 30, 2013
210
Littlebits said:
Moose said:
I have try Maxthon's Browser for a three month a while back and had Drive
by Trojan's enter on my system. Meaning that I have similar experience with Maxthon's Browser. Remember the browser is the weakest point of
entry in my opinion for Malware, adware, ect.....I just unistall and when to
Chrome with extensions. My secondary browser is Waterfox with extensions.

Were you using the Trident engine or the Webkit engine?
By default it uses the same engine as Google Chrome but it is not Chromium, Safari's Webkit.

In my opinion is is just as safe as any other browser it has built-in security features if you had them enabled like AdHunter, Magic Fill, Do Not Track, it own proxy servers, Flash Block, Advanced Download Manager, disable Java, Active X Block, etc. Of coarse it is not my choice because it is somewhat complicated compared to Firefox or Google Chrome.

You can pick up malware with any browser if you don't know how to use its security features and don't watch what you download.

Thanks.:D

you can doubt but the proof is above maybe maxathon maybe ther skins
but its from there site alone.the new version just came out before i could even update.I have not had a virus in eons all security was at highest level.all im saying is beware something is not right. so be safe out there
 

Littlebits

Retired Staff
May 3, 2011
3,893
you can doubt but the proof is above maybe maxathon maybe ther skins
but its from there site alone.the new version just came out before i could even update.I have not had a virus in eons all security was at highest level.all im saying is beware something is not right. so be safe out there

You have NOT provided any proof at all, just because Hitman Pro detected some files in Maxthon's directory means nothing. Hitman Pro has high false positives and without the complete log and suspected files, you have no proof.

Like I said if this is where some real malware come from then why hasn't anyone else said anything about it? could you be the only one of a a large community that just happened to get infected and nobody else?

http://www.urlvoid.com/scan/skin.maxthon.com/
http://www.urlvoid.com/scan/extension.maxthon.com/

All of the exe's were also scanned and nothing found.

Unless you can provide some real proof like the actual detected files in question, full scan logs from Hitman Pro, the actual skins, extensions that were detected, etc. no one is going to take you serious.

Enjoy!!:D
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top