Malware

Bredo.8 removal

Malware Removal

The Bredo.8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bredo.8 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Bredo.8?


File Info:

name: 769789A6EDD1E964BDDD.mlw
path: /opt/CAPEv2/storage/binaries/1ea7d46ff98f59f21fc7e654d25cd5678134d2be23f18fb2dd9de5989b116db9
crc32: 36F9E85E
md5: 769789a6edd1e964bddd7678043c253d
sha1: 0f080401c179da2f8d827173ea4ffc0d07fa2289
sha256: 1ea7d46ff98f59f21fc7e654d25cd5678134d2be23f18fb2dd9de5989b116db9
sha512: 71b69c62e03a992895ec796756b93b97f296acc24f3760286d38fbf2b79849e7260b699642aa821cb23d63999411cc6d075be7332a6dd24ebadf31b8b62c4919
ssdeep: 3072:IxiULWjxg8SMmfrm38BF0aPaRTiwuODwvKF2AEVoYVhKjuz:0QFMrm320tRTHvwQKVoYPK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151E312AF9F2B2474D8CC68F485BA968C11BA37B217B353EC536C4E95AC6C2B0C159C35
sha3_384: 2fcaa951bbd6cf60ab0caf017e32c7a84257d8c7e00d65329e434299ed9a0cca0d54a8a56c974db5d26ae2abd4fb12bc
ep_bytes: 60be004043008dbe00d0fcff5783cdff
timestamp: 2004-11-23 02:15:55

Version Info:

CompanyName: щкгьоеантыысьегсзмй чя
FileDescription: тищыт
FileVersion: 11.78.72.24
InternalName: рдгхюмюнющ дватрзючбуеи
LegalCopyright: 5228-1265
OriginalFilename: JSX.exe
ProductName: ркуыпфъмжжгбшъс фчфкээшкцыд
ProductVersion: 11.78.72.24
Translation: 0x04b0 0x0417

Bredo.8 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.lhyg
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bredo.8
FireEyeGeneric.mg.769789a6edd1e964
ALYacGen:Variant.Bredo.8
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.66595
SangforTrojan.Win32.Zbot.gen!Y
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojanPSW:Win32/Kryptik.fe8f1923
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.6edd1e
VirITTrojan.Win32.Packed.BECL
CyrenW32/Qakbot.A.gen!Eldorado
SymantecTrojan.Zbot!gen9
ESET-NOD32a variant of Win32/Kryptik.FMX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1282
KasperskyPacked.Win32.Krap.hm
BitDefenderGen:Variant.Bredo.8
NANO-AntivirusTrojan.Win32.Krap.cvsdlq
TencentWin32.Packed.Krap.Aiih
Ad-AwareGen:Variant.Bredo.8
EmsisoftGen:Variant.Bredo.8 (B)
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.Packed.20343
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_QAKBOT.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
SophosML/PE-A + Mal/Qbot-B
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Bredo.8
JiangminPacked.Krap.csto
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3243487
KingsoftWin32.Troj.Krap..(kcloud)
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
ZoneAlarmPacked.Win32.Krap.hm
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Vundo.R413908
Acronissuspicious
McAfeeArtemis!769789A6EDD1
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
PandaTrj/Sinowal.XEG
TrendMicro-HouseCallBKDR_QAKBOT.SMC
RisingTrojan.Win32.Generic.13BBE440 (C64:YzY0OofEmQawJfxQ)
YandexTrojan.GenAsa!qoR+1YjrEIQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1382627.susgen
FortinetW32/Krypt.A!tr.dldr
BitDefenderThetaAI:Packer.E0F2710F1F
AVGFileRepMetagen [Malware]
AvastFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bredo.8?

Bredo.8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment