PUA.Malware Crusher - What Is it and How to Remove It Completely
THREAT REMOVAL

PUA.Malware Crusher – What Is it and How to Remove It Completely

OFFER

SCAN YOUR MAC
with Combo Cleaner

Scan Your System for Malicious Files
Note! Your system might be affected by PUA.Malware Crusher and other threats
Threats such as PUA.Malware Crusher may be persistent. They tend to re-appear if not fully deleted. A malware removal tool like Combo Cleaner will help you to remove malicious programs, saving you the time and the struggle of tracking down numerous malicious files.
Combo Cleaner’s scanner is free but the paid version is needed to remove the malware threats. Read Combo Cleaner’s EULA and Privacy Policy.

This article has been created in order to explain what is Malware Crusher PUP and how to remove it completely from your computer.

A potentially unwanted program, known as PUA.Malware Crusher has been detected and analysed by malware experts at Symantec. The software has been reported to exhibit a potentially unwanted type of behavior on the computers on which it has been installed. Users have reported it to run automatic scans on the computers it has been installed on and show fake malware detections and to remove it, the app demands a purchase of it’s full version. If you have Malware Crusher installed on your computer, we advise you to read the following article and learn how to remove this software from your computer.

Threat Summary

NamePUA.Malware Crusher
TypeHoax Antivirus / PUP
Short DescriptionAims to display fake detections on the computer it is installed on in order to convince victims to purchase it’s full version to remove them.
SymptomsRuns automatic scans, runs on system startup, displays fake virus detection messages.
Distribution MethodBundled installers, fake setups, fake detection web pages.
Detection Tool See If Your System Has Been Affected by PUA.Malware Crusher

Download

Malware Removal Tool

User ExperienceJoin Our Forum to Discuss PUA.Malware Crusher.

Malware Crusher – How Did I Get It

This unwanted software can find itself installed on your computer via several different methods, the primary of which is if your PC has already had been affected by an unwanted program, like browser hijacker or adware. Such programs may redirect your to fake error detection messages which deceive that your computer is under threat and ask to download a fixing tool, for example the fake web page below:

In addition to this, another way via which Malware Crusher can slither onto your computer is if the software comes alongside other third-party applications, such as an installer for drivers, for different freeware apps you look for to download on a regular basis, like your favorite media player, etc. Such apps are often published on free software providing websites which add the automatic installation of unwanted apps, like Malware Crusher in their setup wizards. And it is not easy to find it too, because the prompt which asks if you want to add Malware Crusher alongside your current install is usually concealed within the “Advanced” or “Custom” installation modes of your current setup.

Malware Crusher – Analysis and Activity Report

Once installed on your computer, the program drops the following files in the folders it automatically creates on your computer:

→ %ProgramFiles%\Malware Crusher\7z.dll
%ProgramFiles%\Malware Crusher\7z.exe
%ProgramFiles%\Malware Crusher\Application_icon.png
%ProgramFiles%\Malware Crusher\danish_iss.ini
%ProgramFiles%\Malware Crusher\Dutch_iss.ini
%ProgramFiles%\Malware Crusher\english_iss.ini
%ProgramFiles%\Malware Crusher\finish_iss.ini
%ProgramFiles%\Malware Crusher\French_iss.ini
%ProgramFiles%\Malware Crusher\german_iss.ini
%ProgramFiles%\Malware Crusher\ICSharpCode.SharpZipLib.dll
%ProgramFiles%\Malware Crusher\Interop.IWshRuntimeLibrary.dll
%ProgramFiles%\Malware Crusher\italian_iss.ini
%ProgramFiles%\Malware Crusher\japanese_iss.ini
%ProgramFiles%\Malware Crusher\langs.db
%ProgramFiles%\Malware Crusher\mclog.xsl
%ProgramFiles%\Malware Crusher\mcr.exe
%ProgramFiles%\Malware Crusher\mcr.exe.config
%ProgramFiles%\Malware Crusher\Microsoft.Win32.TaskScheduler.dll
%ProgramFiles%\Malware Crusher\Microsoft.WindowsAPICodePack.dll
%ProgramFiles%\Malware Crusher\Microsoft.WindowsAPICodePack.Shell.dll
%ProgramFiles%\Malware Crusher\Newtonsoft.Json.dll
%ProgramFiles%\Malware Crusher\norwegian_iss.ini
%ProgramFiles%\Malware Crusher\portuguese_iss.ini
%ProgramFiles%\Malware Crusher\PresentationCore.dll
%ProgramFiles%\Malware Crusher\russian_iss.ini
%ProgramFiles%\Malware Crusher\spanish_iss.ini
%ProgramFiles%\Malware Crusher\swedish_iss.ini
%ProgramFiles%\Malware Crusher\System.Data.SQLite.DLL
%ProgramFiles%\Malware Crusher\System.Windows.Controls.Input.Toolkit.dll
%ProgramFiles%\Malware Crusher\System.Windows.Controls.Layout.Toolkit.dll
%ProgramFiles%\Malware Crusher\TAFactory.IconPack.dll
%ProgramFiles%\Malware Crusher\unins000.dat
%ProgramFiles%\Malware Crusher\unins000.exe
%ProgramFiles%\Malware Crusher\unins000.msg
%ProgramFiles%\Malware Crusher\upload.log
%ProgramFiles%\Malware Crusher\WpfAnimatedGif.dll
%ProgramFiles%\Malware Crusher\WPFToolkit.dll
%ProgramFiles%\Malware Crusher\x64\SQLite.Interop.dll
%ProgramFiles%\Malware Crusher\x86\SQLite.Interop.dll
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Buy Malware Crusher.lnk
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Buy Malware Crusher.lnk
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Malware Crusher.lnk
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Malware Crusher.lnk
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Uninstall Malware Crusher.lnk
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Uninstall Malware Crusher.lnk
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Browsers.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\ChromeExtentions.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\ChromeFiles.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\ChromeSearch.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\CLSID.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\CompleteDatabase.db
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FileNames.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FilesPath.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FirefoxExtentions.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FirefoxFiles.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FirefoxSearch.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FolderNames.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FoldersPath.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\IEExtension.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\IESearch.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\MalwareDetails.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Md5Hash.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Plugins.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Registry.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\RegistrySetting.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Services.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\StartupTask.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\223completedatabase.zip
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\224update.db
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\224update.zip
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\225update.db
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\225update.zip
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\226update.db
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\226update.zip
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\227update.db
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\227update.zip
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\228update.db
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\228update.zip
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\URLS.cb
%SystemDrive%\ProgramData\MalwareCrusher.com\Malware Crusher\QTine.cb
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\DatabaseUpdate.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\Errorlog.txt
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\icon\124700.ico
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\intel_desktop.gif
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\LogBackups\mcbackup_22122017_123917.bin
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\LogBackups\mcbackup_22122017_124700.bin
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\logbkp.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\notifier.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\Result.cb
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\Temp\1eb6cf0736574d5e9fe337f65f9503a2.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\Temp\4b35584bb2b642529b3ceb2e5baca563.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\Temp\8dc80c0443854e29ae1a555adf6d9cba.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\Temp\c2977b9095fe446880c3cfe55c0a91e8.xml
%AppData%\Roaming\MalwareCrusher.com\Malware Crusher\update.xml
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Buy Malware Crusher.lnk
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Buy Malware Crusher.lnk
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Malware Crusher.lnk
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Malware Crusher.lnk
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Uninstall Malware Crusher.lnk
%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Uninstall Malware Crusher.lnk
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Browsers.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\ChromeExtentions.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\ChromeFiles.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\ChromeSearch.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\CLSID.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\CompleteDatabase.db
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FileNames.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FilesPath.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FirefoxExtentions.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FirefoxFiles.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FirefoxSearch.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FolderNames.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\FoldersPath.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\IEExtension.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\IESearch.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\MalwareDetails.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Md5Hash.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Plugins.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Registry.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\RegistrySetting.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Services.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\StartupTask.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\223completedatabase.zip
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\224update.db
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\224update.zip
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\225update.db
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\225update.zip
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\226update.db
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\226update.zip
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\227update.db
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\227update.zip
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\228update.db
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\Update\228update.zip
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\Definition\URLS.cb
%AllUsersProfile%\MalwareCrusher.com\Malware Crusher\QTine.cb
%UserProfile%\Public\Desktop\Malware Crusher.lnk

After it’s program files are dropped on your PC, Malware Crusher begins to directly modify your Windows Registry Editor. The app performs this by adding the following registry sub-keys with entries on them, allowing it to perform different activities without asking for permission:

→ HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Buy Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Buy Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Buy Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\”Buy Malware Crusher.lnk” = “1”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”utm_source” = “mcrsite2″
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”utm_campaign” = “mcrsite2″
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”utm_medium” = “mcrsite2″
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”affiliateid” = “”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”pxl” = “mcr2083_mcr2039_mcr1075″
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”utm_pubid” = “”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”Installstring” = “%ProgramFiles%\Malware Crusher”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”Installstring” = “%ProgramFiles%\Malware Crusher”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\malwarecrusher.com\Malware Crusher\”LangCod” = “en”
HKEY_USERS\S-1-5-21-156198121-423029172-7828763-500\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\678d533b_0\”” = “{0.0.0.00000000}.{65bd4179-e5d9-4ab5-ad83-86cf5a6c8cb3}|\Device\HarddiskVolume1\Program Files\Malware Crusher\mcr.exe%b{00000000-0000-0000-0000-000000000000}”

Modifying those registry sub-keys allows Malware Crusher to run automatic scans on your computer system, and to display information, which makes it seem as if your computer is under threat:

What is more, Malware Crusher is the type of program which does not remove the possibly non-existent malware detections it has discovered on your computer for free. This is because Malware Crusher’s end goal, like any other PUP (Potentially Unwanted Program) is to convince you to purchase the full version of the software in order to remove the threats from your PC. If you are facing such a decision, researchers strongly advise not to thing twice and remove this believed-to-be hoax antivirus from your computer system.

How to Remove Malware Crusher from Your Computer

In order to get rid of this unwanted application, we recommend that you follow the removal instructions down below. They are separated in manual and automatic removal manuals, whose primary purpose is to help you isolate Malware Crusher from your system and then delete it. If manual removal does work for you, keep in mind that security experts always outline that the best way to fully remove programs, like Malware Crusher from computers is to perform a scan with an advanced anti-malware software, which will make sure that the all of the related objects to Malware crusher are gone from your PC and it stays protected against future intrusive programs as well.

Note! Your computer system may be affected by PUA.Malware Crusher and other threats.
Scan Your MAC with Combo Cleaner
Combo Cleaner is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of threats such as PUA.Malware Crusher.
Keep in mind, that Combo Cleaner needs to purchased to remove the malware threats. Click on the corresponding links to check Combo Cleaner’s EULA and Privacy Policy.

Manually delete PUA.Malware Crusher from your Mac

1. Uninstall PUA.Malware Crusher and remove related files and objects
2. Remove PUA.Malware Crusher – related extensions from your Mac’s browsers

Automatically remove PUA.Malware Crusher from your Mac

When you are facing problems on your Mac as a result of unwanted scripts and programs such as PUA.Malware Crusher, the recommended way of eliminating the threat is by using an anti-malware program. Combo Cleaner offers advanced security features along with other modules that will improve your Mac’s security and protect it in the future.


Download

Combo Cleaner

Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...