Malware

Win32/Toolbar.Crossrider.S potentially unwanted removal tips

Malware Removal

The Win32/Toolbar.Crossrider.S potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Toolbar.Crossrider.S potentially unwanted virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • Authenticode signature is invalid

How to determine Win32/Toolbar.Crossrider.S potentially unwanted?


File Info:

name: D9FE905EA8A370E290AF.mlw
path: /opt/CAPEv2/storage/binaries/9b5d9969d758b6703161a8deabbbb151e31e1265ae949f10263d1044815f77bf
crc32: 92976116
md5: d9fe905ea8a370e290aff835c4d9c9bc
sha1: a724bb914aaa80e023f8da7bdd0933be43606a51
sha256: 9b5d9969d758b6703161a8deabbbb151e31e1265ae949f10263d1044815f77bf
sha512: 5538539e24ca941909fe61fcca8aeb07372aa0653ddfe3ffc3a86fc39491489310cb53fffd87d6bf884f540f861b7355cb114218eb5081bbffec385d41a87d07
ssdeep: 24576:FpVf+fcAnF6xE7C+Ph+WDmKlyLT+gSxwkQncTM0h:N90D7fh+WDmKlyLzkQncTM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185254A4166429531D4A1087383EC8B2954FC7772A762A8D7E7DD2EDC4BA08D2E638F37
sha3_384: 4a8bd4d1709e0212059c2531b0f706013defe2ff99509accc67f965bd55bb70b3992bd3495749ae58902884deeb033b3
ep_bytes: e8d7f30000e97ffeffffcccccccccc55
timestamp: 2014-01-20 13:29:10

Version Info:

CompanyName: Nero
FileDescription: Apps Hat Mini exe
FileVersion: 1000.1000.1000.1000
InternalName: Apps Hat Mini
LegalCopyright: Copyright 2011
OriginalFilename: Apps Hat Mini.exe
ProductName: Apps Hat Mini
ProductVersion: 1000.1000.1000.1000
Translation: 0x0409 0x04b0

Win32/Toolbar.Crossrider.S potentially unwanted also known as:

BkavW32.Common.AA3E76BD
LionicAdware.Win32.CrossRider.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Application.Heur.7u0@mSP670mO
FireEyeGeneric.mg.d9fe905ea8a370e2
SkyhighBehavesLike.Win32.Infected.dh
Cylanceunsafe
ZillyaAdware.CrossRider.Win32.35350
SangforAdware.Win32.CrossRider.Vhmr
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/CrossRider.b1cf42b6
VirITAdware.Win32.Generic.X
SymantecAdware.Crossid
ESET-NOD32a variant of Win32/Toolbar.Crossrider.S potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.CrossRider.gen
BitDefenderGen:Application.Heur.7u0@mSP670mO
NANO-AntivirusTrojan.Win32.Crossrider.cxrnva
SUPERAntiSpywareAdware.CrossRider/Variant
AvastWin32:Crossrider-AI [PUP]
TencentMalware.Win32.Gencirc.1154aa8c
EmsisoftGen:Application.Heur.7u0@mSP670mO (B)
F-SecureAdware.ADWARE/CrossRider.Gen2
DrWebAdware.Toolbar.862
VIPREGen:Application.Heur.7u0@mSP670mO
TrendMicroADW_RIDECROSS
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusAdWare.Plush
GDataWin32.Adware.Crossrider.N
JiangminWebToolbar.CroRi.we
WebrootPua.Add.Lyrics
GoogleDetected
AviraADWARE/CrossRider.Gen2
KingsoftWin32.Troj.CrossRider.gen
XcitiumApplication.Win32.CrossRider.KVA@5qxald
ArcabitApplication.Heur.E1E1CF
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.CrossRider.gen
MicrosoftPUAAdvertising:Win32/CrossRider
VaristW32/Trojan.FWI.gen!Eldorado
McAfeePUP-XRZ-RA
MAXmalware (ai score=100)
VBA32BScope.Adware.CroRi
MalwarebytesGeneric.Malware.AI.DDS
PandaPUP/CrossRider
TrendMicro-HouseCallADW_RIDECROSS
RisingPUF.Crossrider!8.84 (TFE:5:tlFFRHq6iEC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.12116206.susgen
FortinetRiskware/Toolbar_CrossRider
AVGWin32:Crossrider-AI [PUP]
DeepInstinctMALICIOUS

How to remove Win32/Toolbar.Crossrider.S potentially unwanted?

Win32/Toolbar.Crossrider.S potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment