SpyCrush - A New Variant, but with a Bad Intent
SpyCrush is an extremely
dangerous rogue anti-spyware program creating
productivity losses for thousands of computer users. It enters your
computer system in a surreptitious manner using Trojans and system exploits. By nature, SpyCrush
is very inefficient as a spyware removal program. Although this program can detect the presence of some malicious
parasites and scripts in your system, it fails to properly protect your online privacy
or provide sufficient system security as a legitimate anti-spyware
program should.
Quick SpyCrush Removal
- Download XoftSpySE
- Run XoftSpySE and remove all infections.
- Reboot your PC.
- Run XoftSpySE again to verify.
What is SpyCrush?
SpyCrush is a Trojan
that displays some distinctive properties such as:
- It displays an icon that produces fake warnings about the
presence of dangerous spyware, adware and other parasites.
- It will prompt the user to download and install a paid,
full version of the spyware removal program to remove the reported parasites.
- Once the user clicks on the pop-up message box, the
Trojan opens the web site that distributes the questionable program.
- Under normal circumstances, once you click on the
message box the downloading starts immediately without your permission
or consent.
- Another illegal activity performed by this malicious
program is to change the default settings of your web browser (mostly
Internet Explorer) and later redirect it to visit the host web site at http://www.spycrush.com.
- Spycrush also has the ability to run automatically on
every windows start-up operation
SpyCrush belongs to the class of “Potentially Unwanted
Programs”, also known as PUP’s. These programs can affect your consent,
awareness or control over usual computer operations like:
·
Installation of other software programs,
·
Any type of modification carried out on your
computer system,
·
Normal behavioral aspects of the program,
·
Normal processing of personal data and details,
·
Un-installation procedures for all computer
programs
SpyCrush can affect personal and professional
productivity and it can prevent you from carrying out even the mundane tasks.
Soon after infection, it can display many pop-up windows and fake security
warnings that reduce the overall security of the computer system. SpyCrush
needs some sort of carrier to infect your computer system. It always needs your
consent and permission to reach and infect the innermost parts of your hard
disc. The modes of transmission used for infection may include, using infected
floppy disks, CD-ROMs, email messages with attached infected files, FTP
servers, IRC relay channels and peer-to-peer (P2P) file sharing systems.
It is quite easy to recognize the symptoms of a SpyCrush
infection. Some the classical symptoms of an infection are:
·
A suspicious looking icon in your system tray
that is usually red shield with a white cross, very similar to Windows Update
icon,
·
Fake security alert messages like:
ü
System Alert!
ü
“System has detected a number of active spyware applications that may influence the performance of your computer.
Click the icon to get rid of unwanted spyware by downloading an up-to-date anti-spyware
solution.”
Example SpyCrush false alert:
·
As Windows loads you see programs like, spycrush.exe, spycrush 3.1.exe or spycrush 3.2.exe running in the
system.
It is possible to remove all traces of SpyCrush
from your computer system using an effective automatic spyware removal tool
such as ParetoLogic's XoftSpySE.
To remove SpyCrush using a manual procedure you
will need to remove and delete all SpyCrush related processes, files, folders
and registry values. This can prove to be cumbersome and difficult if you're not computer savvy.
Ensure that you are not meddling with your computer system files and folders
without a proper understanding, as you may damage computer’s operating system.
Following is a brief procedure for removing SpyCrush from your computer
using a manual procedure (use at own risk):
Navigate to Start icon on your desktop and Click.
Then, click on the “Run” button to open the dialog box. Type “regedit” in the
dialog box and click OK. The Registry Editor will open now on the desktop. Now,
you will need to find and delete the following processes, folders, files and
registry values, manually and one-by-one.
Malicious files in C:\WINDOWS\System32 or
C:\WINNT\System32:
ü
ckimzeb.dll
ü
gbjkog.dll
ü
gsrnxgh.dll
ü
iauoi.dll
ü
syycum.dll
ü
yesgnhr.dll
Malicious files in C:\Program Files\SpyCrush: spycrush.exe
Malicious files in C:\Program Files\SpyCrush
3.1: spycrush 3.1.exe
Malicious files in C:\Program Files\SpyCrush 3.2: spycrush 3.2.exe
Delete the following directories:
ü
C:\Program Files\SpyCrush
ü
C:\Program Files\SpyCrush 3.1
ü
C:\Program Files\SpyCrush 3.2
Once you've made sure that you have all the infected
files and folders out of the system, then you may need to restore your system settings
with new SpyCrush-free values. To prevent future infections you should follow basic security guidelines as recommended by experts and professionals in the field. Also, protect your system using a reputable anti-spyware program such as XoftSpySE. If you do need any further assistance removing SpyCrush please upload your XoftSpySE log file from within XoftSpySE software. A support ticket will be automatically generated for you.