Trojan

Trojan.Agent.BRUI removal instruction

Malware Removal

The Trojan.Agent.BRUI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BRUI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Hungarian
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.BRUI?


File Info:

crc32: 1753E031
md5: 06d2a43dc7939996d80d9d5379ab9205
name: 06D2A43DC7939996D80D9D5379AB9205.mlw
sha1: 680499f8eda732878028d36ef259774de5535c9b
sha256: d29fc59f6c7e4e95046afab9a5b3c314ffc8ac0fb4acc9eebc4f6a9859db037a
sha512: 2baad95ef63b4d898ea590f8e7971e3799c9d7e701eef81eb80666dd2f493be54acc126d35cc796c4d3a6a4bb2b2710c3dbe660410ea065ac58f797a1aa6da44
ssdeep: 6144:Scmot3Tz2MwO6lCSeyMrHIDkzt4ARPyghqpy0ExYE0vS1LeZNKy4zza72p:ttjzpoRMUYt4AR6ghqpBEx30vS8ZNIj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013
InternalName: Segregation
FileVersion: 0.120.135.206
CompanyName: PEERNET Inc.
LegalTrademarks: Tipped
ProductName: Advising Saturated
ProductVersion: 0.68.140.144
FileDescription: Stony Years Rumble
OriginalFilename: Steroidsl.EXE

Trojan.Agent.BRUI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BRUI
CAT-QuickHealRansom.Teslacrypt.OL4
McAfeeRansomware-FGN!06D2A43DC793
CylanceUnsafe
ZillyaTrojan.CryptGen.Win32.1
AegisLabTrojan.Win32.Bitman.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004e08451 )
BitDefenderTrojan.Agent.BRUI
K7GWTrojan ( 004e08451 )
Cybereasonmalicious.dc7939
CyrenW32/Trojan.SZDV-7802
SymantecRansom.TeslaCrypt
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Bitman.aeng
AlibabaRansom:Win32/Bitman.3db78bdf
NANO-AntivirusTrojan.Win32.AVKill.eazgmk
ViRobotTrojan.Win32.Ransom.393471
RisingRansom.Bitman!8.6A2 (CLOUD)
Ad-AwareTrojan.Agent.BRUI
TACHYONTrojan/W32.Bitman.393471
EmsisoftTrojan.Agent.BRUI (B)
ComodoTrojWare.Win32.Ransom.Tescrypt.BU@6b1xej
F-SecureTrojan.TR/FileCoder.65768
DrWebTrojan.AVKill.60536
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionRansomware-FGN!06D2A43DC793
FireEyeGeneric.mg.06d2a43dc7939996
SophosMal/Generic-R + Mal/Ransom-EM
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Bitman.va
AviraTR/FileCoder.65768
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Locky.A
ArcabitTrojan.Agent.BRUI
SUPERAntiSpywareRansom.Locky/Variant
ZoneAlarmTrojan-Ransom.Win32.Bitman.aeng
GDataTrojan.Agent.BRUI
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Lockycrypt.Gen
BitDefenderThetaGen:NN.ZexaF.34590.yq3@aWVOOamO
ALYacTrojan.Agent.BRUI
MAXmalware (ai score=88)
VBA32Hoax.Bitman
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ZonerTrojan.Win32.39356
ESET-NOD32Win32/Filecoder.TeslaCrypt.K
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
TencentTrojan.Win32.Kryptik.jsfc
YandexTrojan.Bitman!d0JSRH0lqFg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74068356.susgen
FortinetW32/Kryptik.EQMA!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Bitman.HwcBVE8A

How to remove Trojan.Agent.BRUI?

Trojan.Agent.BRUI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment