PUA

PUA:Win32/CrawlerToolbar information

Malware Removal

The PUA:Win32/CrawlerToolbar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/CrawlerToolbar virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine PUA:Win32/CrawlerToolbar?


File Info:

crc32: F7C46BE4
md5: aba1d75526152942d1dc2fbba5889b32
name: inboxstoragesetup.exe
sha1: ef244ed483f74047c180042ca60db8548a9d0ea3
sha256: 8aa1a06fe2a30f7bf1afafb99701731edbc412787e945c86f184c7d741b47eb2
sha512: 5249dd89446fbac993ebc9fe397290ba2d97f6ab6a9b8759f296766c2340f0b42b055ede03e5147efc813058ac8a9e966e7b5ebec601c946c5df9023d79c7370
ssdeep: 49152:WPaXfla+WrgjlF47c7lJV+uUDp1at/mPPAsNMzmHxvZ5a2ojHcWM7SJ:WPaPI+Wk87MAuUV1aZ4PAUZ5FkHcW+SJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: copyright xa9 Inbox.com
FileVersion: 1.0.0.32
CompanyName: Xacti, LLC
Comments: This installation was built with Inno Setup.
ProductName: Inbox Storage
ProductVersion: 1.0.0.0
FileDescription: Inbox Storage Setup
Translation: 0x0000 0x04b0

PUA:Win32/CrawlerToolbar also known as:

FireEyeGeneric.mg.aba1d75526152942
CAT-QuickHealPUA.Omegapartn.Gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Generic.3!c
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Application.ToolbarCrawler.A
Kasperskynot-a-virus:HEUR:WebToolbar.Win32.Reptile.gen
AlibabaToolbar:Win32/Reptile.e6b27e94
ViRobotAdware.Agent.2552872
SophosGeneric PUA OP (PUA)
F-SecurePotentialRisk.PUA/Crawler.Gen
DrWebProgram.Unwanted.889
ZillyaAdware.1ClickDownloadCRT.Win32.263
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
EmsisoftApplication.InstallBox (A)
JiangminWebToolbar.Reptile.ae
WebrootPua.Xacti
AviraPUA/Crawler.Gen
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:HEUR:WebToolbar.Win32.Reptile.gen
MicrosoftPUA:Win32/CrawlerToolbar
McAfeeArtemis!ABA1D7552615
MalwarebytesPUP.Optional.InboxTB
TrendMicro-HouseCallTROJ_GEN.R002H0CI419
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.8104920.susgen
FortinetRiskware/Generic
AVGWin32:Malware-gen

How to remove PUA:Win32/CrawlerToolbar?

PUA:Win32/CrawlerToolbar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment