PUA

PUA:Win32/BroSafe removal instruction

Malware Removal

The PUA:Win32/BroSafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/BroSafe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Uses suspicious command line tools or Windows utilities

How to determine PUA:Win32/BroSafe?


File Info:

name: D2411954BE3F6F0F6592.mlw
path: /opt/CAPEv2/storage/binaries/33bb558ed3eaba5ceed90cd0bef5f7943095fed94e81858aad77dfb1799819b0
crc32: 021C8AF7
md5: d2411954be3f6f0f65928dbe7c14c86d
sha1: e2bfe6a8b231ff5a92929fd2fe8c9a4c8705cefd
sha256: 33bb558ed3eaba5ceed90cd0bef5f7943095fed94e81858aad77dfb1799819b0
sha512: c19854746316165c9f458e97d84d52b47bfb30377bdd15f6b3b6c26610c8ca20764154ad434ca9a3280e8f5d8372736ab0fd020858385a538950bd29ba644d86
ssdeep: 49152:N/uzgs/e994AKIwu9+8dkeL171sRrUdlYee5PCRI2AQD8jxWR:Buzgs/k94AKIwu9dko7CxUT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0E517D0F9DF40F6D2078D7188A2923FAA34460883F5DAC7DE642E5AED1BAD1097B315
sha3_384: 4a68d8ab328f76ec98e9194413b2d9ca3d7ca5f1f7953f69dcae498f19afb4b192a1d847c0f9a112899c00823a9d927c
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Creative Software Solutions GmbH.
FileVersion: 1, 4, 1, 0
Translation: 0x0409 0x04b0

PUA:Win32/BroSafe also known as:

LionicAdware.Win32.BroSafe.2!c
FireEyeGeneric.mg.d2411954be3f6f0f
CylanceUnsafe
ZillyaAdware.BroSafe.Win32.4
SangforTrojan.Win32.Occamy.8
AlibabaAdWare:Win32/BroSafe.1819ab81
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Agent.NTU
TrendMicro-HouseCallTROJ_GEN.R002H0CK921
Kasperskynot-a-virus:AdWare.Win32.BroSafe.f
NANO-AntivirusTrojan.Win32.Mlw.faeyxx
TencentMalware.Win32.Gencirc.114cde07
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA OC (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Agent.fmfu
WebrootW32.Adware.Installcore
AviraTR/Dldr.Agent.symbf
MAXmalware (ai score=98)
Antiy-AVLTrojan/Generic.ASMalwS.25AD366
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPUA:Win32/BroSafe
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Generic.C2464252
McAfeeGenericRXAA-AA!D2411954BE3F
VBA32BScope.Adware.BroSafe
MalwarebytesMalware.AI.1892668765
PandaTrj/RnkBend.A
APEXMalicious
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusAdWare.BroSafe
FortinetW64/Agent.PH!tr.dldr
AVGFileRepMalware
AvastFileRepMalware

How to remove PUA:Win32/BroSafe?

PUA:Win32/BroSafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment