Home Malware Programs Trojans Mal/Bredo-Q

Mal/Bredo-Q

Posted: November 30, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 4,265
First Seen: November 30, 2011
Last Seen: July 15, 2022
OS(es) Affected: Windows

Mal/Bredo-Q is a harmful Trojan that is a part of the fake emails allegedly coming from USPS or Royal Mail. The spam emails use a variety of subject lines, and contain adaptions depending on whether the attackers believe they are targeting a British or American computer user (Brits are seduced to open the attachment with an email seemingly from the Royal Mail, whereas American-based recipients may believe the message is from USPS). The wording can vary, but here are some examples of both the USPS and Royal Mail versions of the bogus email. The ZIP file contained inside the malicious email is Mal/Bredo-Q, which is able to infect computers running Windows. When the infected email attachment within the ZIP file is executed, Mal/Bredo-Q copies to Windows system folder and modifies the registry to run automatically each time you start up your computer. Mal/Bredo-Q also connects to remote servers and installs several malicious applications on the compromised PC system. If you receive such emails, do not click on the attachment even if you are waiting for a package to be delivered. Delete the fraudulent email and keep your PC safe from Mal/Bredo-Q.

Aliases

W32/Yakes.B!tr [Fortinet]Gen:Variant.Kazy.53408 [BitDefender]UDS:DangerousObject.Multi.Generic [Kaspersky]Suspicious.MLApp [Symantec]Packed.Generic.349 [Symantec]Generic26.NGG [AVG]Trojan.Win32.Diple [Ikarus]Trojan/Win32.Diple [AhnLab-V3]Trojan/Win32.Diple.gen [Antiy-AVL]Mal/Bredo-Q [Sophos]TR/Kazy.46645 [AntiVir]Gen:Variant.Kazy.46645 [BitDefender]Trojan.Win32.Diple.djzk [Kaspersky]Win32:Malware-gen [Avast]Trojan.Gen.2 [Symantec]
More aliases (57)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Application Data\g9zDdAmZAoyENB.exe File name: g9zDdAmZAoyENB.exe
Size: 352 KB (352000 bytes)
MD5: 9169f80595ed8a1df01acbb3bbeb8f5f
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: December 5, 2011
Post_Label.exe File name: Post_Label.exe
Size: 56.32 KB (56320 bytes)
MD5: 2753f5a542e031e3e06e3940559809d1
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011
%USERPROFILE%\Local Settings\Temp\mstfzae.com File name: mstfzae.com
Size: 39.42 KB (39424 bytes)
MD5: 7542970b3b3d15b54ee11ce6e866a021
Detection count: 60
File type: Command, executable file
Mime Type: unknown/com
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 23, 2012
%ALLUSERSPROFILE%\Application Data\SIyHoyHlXaPT.exe File name: SIyHoyHlXaPT.exe
Size: 501.76 KB (501760 bytes)
MD5: f96d7f92e85f57f4b879c4f3236d2643
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: December 5, 2011
%ALLUSERSPROFILE%\V9u4IE0Dr6G.dll File name: V9u4IE0Dr6G.dll
Size: 84.48 KB (84480 bytes)
MD5: a631b3f3e70aa524f69f3b8ab3b6bf3d
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: December 6, 2011
Loading...