PUP.Optional.MalwareCrusher is Malwarebytes’ detection name for a rogue scanner. This potentially unwanted program exaggerates or invents problems on users’ computers, which they promise to solve if you buy their software.
Users will see the main GUI of the software and may spot some Scheduled Tasks it uses to gain persistence. The PUP also leaves an entry in the list of installed programs and features.
Malware Crusher GUI
Malware Crusher Scheduled Tasks
Installed Programs and Features entry for Malware Crusher
PUP.Optional.MalwareCrusher is a system optimizer that is often bundled with cracks and keygens, but can also be downloaded from their site.
Malware Crusher bundled with a crack
Promotion on website for Malware Crusher
Malwarebytes blocks Malware Crusher with its real-time protection engine.
Malwarebytes blocks the bundler from installing Malware Crusher and other PUPs
Malwarebytes can detect and remove PUP.Optional.MalwareCrusher without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/14/18 Scan Time: 8:36 AM Log File: 5f4f9758-275a-11e8-826b-080027235d76.json Administrator: Yes -Software Information- Version: 3.3.1.2183 Components Version: 1.0.262 Update Package Version: 1.0.4348 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 243716 Threats Detected: 128 Threats Quarantined: 128 Time Elapsed: 2 min, 55 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\mcr.exe, Quarantined, [14673], [500145],1.0.4348 Module: 9 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\x64\SQLite.Interop.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Interop.IWshRuntimeLibrary.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\System.Data.SQLite.DLL, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\TAFactory.IconPack.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\WpfAnimatedGif.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\WPFToolkit.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\mcr.exe, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Microsoft.Win32.TaskScheduler.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Newtonsoft.Json.dll, Quarantined, [14673], [500145],1.0.4348 Registry Key: 9 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FA2268FD-F787-4DD3-B6F1-CA4F706F481E_is1, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Malware Crusher, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{1575C6A7-75E1-4238-9E8F-9C102A66A42E}, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{1575C6A7-75E1-4238-9E8F-9C102A66A42E}, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Malware Crusher_Logon, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0CDA9845-9797-47D2-9EE2-CF82A77C06C0}, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{0CDA9845-9797-47D2-9EE2-CF82A77C06C0}, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, HKCU\SOFTWARE\malwarecrusher.com, Quarantined, [14673], [500149],1.0.4348 PUP.Optional.MalwareCrusher, HKLM\SOFTWARE\malwarecrusher.com, Quarantined, [14673], [500151],1.0.4348 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 14 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\x64, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\x86, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\PROGRAM FILES\MALWARE CRUSHER, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MALWARE CRUSHER, Quarantined, [14673], [500147],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\PROGRAMDATA\MALWARECRUSHER.COM, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\LogBackups, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\smico, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\icon, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\Temp, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\USERS\{username}\APPDATA\ROAMING\MALWARECRUSHER.COM, Quarantined, [14673], [500146],1.0.4348 File: 95 PUP.Optional.MalwareCrusher, C:\PROGRAM FILES\MALWARE CRUSHER\UNINS000.DAT, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\x64\SQLite.Interop.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\x86\SQLite.Interop.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\italian_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\7z.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\7z.exe, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Application_icon.png, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\danish_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Dutch_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\english_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\finish_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\French_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\german_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\ICSharpCode.SharpZipLib.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Interop.IWshRuntimeLibrary.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\norwegian_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\portuguese_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\PresentationCore.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\russian_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\spanish_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\swedish_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\System.Data.SQLite.DLL, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\System.Windows.Controls.Input.Toolkit.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\System.Windows.Controls.Layout.Toolkit.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\TAFactory.IconPack.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\unins000.exe, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\unins000.msg, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\WpfAnimatedGif.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\WPFToolkit.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\japanese_iss.ini, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\langs.db, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\mclog.xsl, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\MCPro.ttf, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\mcr.exe, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\mcr.exe.config, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Microsoft.Win32.TaskScheduler.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Microsoft.WindowsAPICodePack.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Microsoft.WindowsAPICodePack.Shell.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\Program Files\Malware Crusher\Newtonsoft.Json.dll, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\WINDOWS\SYSTEM32\TASKS\Malware Crusher, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\WINDOWS\SYSTEM32\TASKS\Malware Crusher_Logon, Quarantined, [14673], [500145],1.0.4348 PUP.Optional.MalwareCrusher, C:\USERS\PUBLIC\DESKTOP\MALWARE CRUSHER.LNK, Quarantined, [14673], [500148],1.0.4348 PUP.Optional.MalwareCrusher, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MALWARE CRUSHER\MALWARE CRUSHER.LNK, Quarantined, [14673], [500147],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Buy Malware Crusher.lnk, Quarantined, [14673], [500147],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher\Uninstall Malware Crusher.lnk, Quarantined, [14673], [500147],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\261completedatabase.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\262update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\262update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\263update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\263update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\264update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\264update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\265update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\265update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\266update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\266update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\267update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\267update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\268update.db, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Update\268update.zip, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Browsers.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\ChromeExtentions.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\ChromeFiles.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\ChromeSearch.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\CLSID.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\CompleteDatabase.db, Delete-on-Reboot, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FileNames.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FilesPath.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FirefoxExtentions.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FirefoxFiles.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FirefoxSearch.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FolderNames.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\FoldersPath.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\IEExtension.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\IESearch.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\MalwareDetails.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Md5Hash.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Plugins.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Registry.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\RegistrySetting.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\Services.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\StartupTask.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\Definition\URLS.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\ProgramData\MalwareCrusher.com\Malware Crusher\QTine.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\icon\082242.ico, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\LogBackups\mcbackup_14032018_082241.bin, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\common_desktop.gif, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\DatabaseUpdate.xml, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\Errorlog.txt, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\logbkp.xml, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.MalwareCrusher, C:\Users\{username}\AppData\Roaming\MalwareCrusher.com\Malware Crusher\Result.cb, Quarantined, [14673], [500146],1.0.4348 PUP.Optional.Bundler, C:\USERS\{username}\DESKTOP\MYCOMP.EXE, Quarantined, [134], [500315],1.0.4348 Generic.Malware/Suspicious, C:\USERS\{username}\APPDATA\LOCAL\TEMP\1129656\KMS.EXE, Quarantined, [0], [392686],1.0.4348 Generic.Malware/Suspicious, C:\USERS\{username}\APPDATA\LOCAL\TEMP\1161765\KMS.EXE, Quarantined, [0], [392686],1.0.4348 Generic.Malware/Suspicious, C:\USERS\{username}\APPDATA\LOCAL\TEMP\1080046\KMS.EXE, Quarantined, [0], [392686],1.0.4348 Physical Sector: 0 (No malicious items detected) (end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
If you want to allow the program to connect to the Internet, for example to fetch updates, also add an exclusion of the type Allow an application to connect to the internet and use the Browse button to select the file you wish to grant access.
You may see these entries in FRST logs:
(MalwareCrusher.com) C:\Program Files\Malware Crusher\mcr.exe C:\Users\Public\Desktop\Malware Crusher.lnk C:\Windows\System32\Tasks\Malware Crusher C:\Windows\System32\Tasks\Malware Crusher_Logon C:\Users\{username}\AppData\Roaming\MalwareCrusher.com C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malware Crusher C:\ProgramData\MalwareCrusher.com C:\Program Files\Malware Crusher Malware Crusher (HKLM\...\FA2268FD-F787-4DD3-B6F1-CA4F706F481E_is1) (Version: 1.0.0.44602 - malwarecrusher.com) Task: {0CDA9845-9797-47D2-9EE2-CF82A77C06C0} - System32\Tasks\Malware Crusher_Logon => C:\Program Files\Malware Crusher\mcr.exe [2017-12-27] (MalwareCrusher.com) Task: {1575C6A7-75E1-4238-9E8F-9C102A66A42E} - System32\Tasks\Malware Crusher => C:\Program Files\Malware Crusher\mcr.exe [2017-12-27] (MalwareCrusher.com)
Select your language