Home Malware Programs Potentially Unwanted Programs (PUPs) PUP.BrowserSafeGuard

PUP.BrowserSafeGuard

Posted: October 7, 2013

Threat Metric

Ranking: 12,269
Threat Level: 1/10
Infected PCs: 464,078
First Seen: August 15, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

PUP.BrowserSafeGuard is a potentially unwanted application, which may be linked to adware, embed unwanted toolbars or have other uncertain goals. PUP.BrowserSafeGuard is not a security threat, but it may include various malevolent functionalities specific to other malware infections. PUP.BrowserSafeGuard may uses tricky techniques to boost traffic of the certain commercial website and make a profit from the pay-per-click technique. PUP.BrowserSafeGuard may infiltrate into the compromised PC packaged with freeware and shareware programs (video recording/streaming, download-managers or PDF creators). PUP.BrowserSafeGuard may also be packed within the custom installer on many unprotected download websites, so if the computer user has downloaded a particular application from these unprotected download websites, he might also installed PUP.BrowserSafeGuard througout the setup process of the particular application.

Aliases

Adware-Bsafeg!CA46EC59E2D8 [McAfee]Win32.Trojan.Agent.UIKNCT [GData]TR/Spy.2375680.16 [AntiVir]WS.Reputation.1 [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\System Volume Information\_restore{0521E745-05F2-466A-A52E-66D2EF5F1037}\RP274\A0021256.exe File name: A0021256.exe
Size: 563.2 KB (563200 bytes)
MD5: 09669ff47664a66fdc45c4a018fdc4cf
Detection count: 44,851
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{0521E745-05F2-466A-A52E-66D2EF5F1037}\RP274\A0021256.exe
Group: Malware file
Last Updated: August 10, 2021
C:\System Volume Information\_restore{0521E745-05F2-466A-A52E-66D2EF5F1037}\RP277\A0021954.exe File name: A0021954.exe
Size: 2.37 MB (2375680 bytes)
MD5: 340de8e4f50a3748d116c3a98aeb97f6
Detection count: 40,935
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{0521E745-05F2-466A-A52E-66D2EF5F1037}\RP277\A0021954.exe
Group: Malware file
Last Updated: January 4, 2022
C:\System Volume Information\_restore{82F15B29-B35B-41ED-829A-D4B1EAFDEDB5}\RP6\A0001600.exe File name: A0001600.exe
Size: 573.95 KB (573952 bytes)
MD5: c2b530df986f7c5cc8aeff8efb482d68
Detection count: 12,219
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{82F15B29-B35B-41ED-829A-D4B1EAFDEDB5}\RP6\A0001600.exe
Group: Malware file
Last Updated: July 9, 2024
C:\Backup\Documents and Settings\PropriƩtaire\Local Settings\Temporary Internet Files\Content.IE5\O96LVVEV\installer[1].exe File name: installer[1].exe
Size: 3.35 MB (3352576 bytes)
MD5: 0b3afdf52cd67bf0bd8e42dfe962ca6d
Detection count: 1,822
File type: Executable File
Mime Type: unknown/exe
Path: C:\Backup\Documents and Settings\PropriƩtaire\Local Settings\Temporary Internet Files\Content.IE5\O96LVVEV\installer[1].exe
Group: Malware file
Last Updated: April 8, 2023
C:\Users\<username>\AppData\Local\Temp\rtinstaller.exe File name: rtinstaller.exe
Size: 4.47 MB (4472320 bytes)
MD5: 2e1c618e96f0a932d5e0c98a8a80cf8b
Detection count: 637
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\rtinstaller.exe
Group: Malware file
Last Updated: August 18, 2022
C:\Program Files (x86)\BrowserSafeguard\uninstall.BrowserSafeguard.exe File name: uninstall.BrowserSafeguard.exe
Size: 4.59 MB (4599296 bytes)
MD5: d17946a23cad0c21c6fd1daa92c39a32
Detection count: 466
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\BrowserSafeguard\uninstall.BrowserSafeguard.exe
Group: Malware file
Last Updated: February 12, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathBrowserSafeguard.lnkRegexp file mask%WinDir%\System32\Tasks\BrowserSafeguard Update TaskHKEY..\..\..\..{RegistryKeys}SOFTWARE\BrowsersafeguardSoftware\BrowsersafeguardInstalledSOFTWARE\Microsoft\Tracing\BrowserSafeguard_RASAPI32SOFTWARE\Microsoft\Tracing\BrowserSafeguard_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserSafeguard Update TaskSOFTWARE\Microsoft\Windows\CurrentVersion\Run\BrowserSafeguardSOFTWARE\Microsoft\Windows\CurrentVersion\Run\BrowserSafeguard Update TaskSOFTWARE\Wow6432Node\BrowsersafeguardSOFTWARE\Wow6432Node\Microsoft\Tracing\BrowserSafeguard_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowserSafeguard_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\BrowserSafeguardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Browsersafeguard

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\BrowserSafeguard%LOCALAPPDATA%\BrowserSafeguard%ProgramFiles%\Browsersafeguard%ProgramFiles(x86)%\Browsersafeguard%UserProfile%\Local Settings\Application Data\BrowserSafeguard
Loading...