Malware

Should I remove “WebToolbar.Win32.MultiPlug.crh”?

Malware Removal

The WebToolbar.Win32.MultiPlug.crh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WebToolbar.Win32.MultiPlug.crh virus can do?

  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

How to determine WebToolbar.Win32.MultiPlug.crh?


File Info:

name: A7FC7985AFAB4FE8673A.mlw
path: /opt/CAPEv2/storage/binaries/eb83e7b83e5fdbd9a7b50fbf75298401db01c41bc65de92a8b2d6486f5dd0e47
crc32: 4C3BBDEF
md5: a7fc7985afab4fe8673a7ccb7980ed1f
sha1: 11dfd24c401dba9400a215ce330525693928a6e3
sha256: eb83e7b83e5fdbd9a7b50fbf75298401db01c41bc65de92a8b2d6486f5dd0e47
sha512: 1acfc40edfcdb8cbeff143c847adc6e8504179656c42df1488884e0fdf513eac65f982f2050f49593ef9746a5ee53bd5d05d0988e950eb50164dd6fc712394d4
ssdeep: 12288:m1ile69UpOmLhFSEg8eKciITyNrMpKDdkJ0F3I67:m1iQ69UpOMh4ZKATyFMp0dLF467
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8D49F12E6E0B437D17227F0DD36A3E95AB6BD100D35898B72CC760D9935A50EA3E363
sha3_384: 42d66665b83430fda2a45996a8eb85a58cb0ba5a628b5aea0de6b8ec3b4f01c3ffa872ead1d0189db216cd8d66e29e03
ep_bytes: 558bec6aff6888704700688003460064
timestamp: 2009-11-25 00:21:01

Version Info:

CompanyName: BitTorrent, Inc.
FileDescription: µTorrent
FileVersion: 1.8.5.17414
InternalName: uTorrent.exe
OriginalFilename: uTorrent.exe
LegalCopyright: ©2009 BitTorrent, Inc. All Rights Reserved.
ProductName: µTorrent
ProductVersion: 1.8.5.17414
Translation: 0x0409 0x04e4

WebToolbar.Win32.MultiPlug.crh also known as:

BkavW32.Common.AE5CDCC7
SkyhighArtemis
Cylanceunsafe
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:WebToolbar.Win32.MultiPlug.crh
Trapminemalicious.high.ml.score
JiangminWebToolbar.MultiPlug.fm
ZoneAlarmnot-a-virus:WebToolbar.Win32.MultiPlug.crh
McAfeeArtemis!A7FC7985AFAB
VBA32Trojan.Agent
RisingTrojan.Generic@AI.98 (RDML:rYxEmlpZS2MPogLxuFp+pg)

How to remove WebToolbar.Win32.MultiPlug.crh?

WebToolbar.Win32.MultiPlug.crh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment