Malware

How to remove “Generic.Rebhip.15D87B56”?

Malware Removal

The Generic.Rebhip.15D87B56 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rebhip.15D87B56 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

www.server.com

How to determine Generic.Rebhip.15D87B56?


File Info:

crc32: 5D90507E
md5: 848d8b512c48229b0e4af0b7a52ea0d5
name: 848D8B512C48229B0E4AF0B7A52EA0D5.mlw
sha1: 5d534d6af63597b20b6155538bd52ad1fb62336a
sha256: 8d3f36e8b1cd54143a15fa935d8f5bab0644451fe3d5ab4cc5a3a8ef2b4449a2
sha512: 05626c05fca7382d50640eb90379ad0994cc80cec4cd05127509c0c0a6865f548db30cd149804480119b03266f2f1a472bd4727e4968743f1627094757b276d5
ssdeep: 6144:1t6BXt8i/snCvTKXaTinQx3XcpRwEO+SDUNoNfccGe6YcndL:j6ki/sQTiqyRwYSVAYc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Rebhip.15D87B56 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0038fc811 )
LionicWorm.Win32.Fearso.lDrx
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.33235
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.A8
ALYacGeneric.Rebhip.15D87B56
CylanceUnsafe
ZillyaTrojan.Llac.Win32.3683
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/Bublik.b4670487
K7GWTrojan ( 0038fc811 )
Cybereasonmalicious.12c482
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.AA
APEXMalicious
AvastWin32:AutoRun-CIN [Trj]
ClamAVWin.Trojan.Cybergate-5744895-0
KasperskyTrojan.Win32.Bublik.aeac
BitDefenderGeneric.Rebhip.15D87B56
NANO-AntivirusTrojan.Win32.Autoruner1.bfzvkb
MicroWorld-eScanGeneric.Rebhip.15D87B56
TencentWin32.Trojan.Spy.Eadp
Ad-AwareGeneric.Rebhip.15D87B56
SophosML/PE-A + W32/Rebhip-AR
ComodoMalware@#2auhvkmh5a6yi
BitDefenderThetaAI:Packer.C8C2116A21
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_REBHIP.SMT
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
FireEyeGeneric.mg.848d8b512c48229b
EmsisoftGeneric.Rebhip.15D87B56 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.asmdh
AviraTR/Spy.Gen
eGambitRAT.Greame
Antiy-AVLTrojan/Generic.ASMalwS.125F0B
MicrosoftWorm:Win32/Rebhip.A
GDataGeneric.Rebhip.15D87B56
AhnLab-V3Trojan/Win32.Llac.R1740
Acronissuspicious
McAfeeGenericRXCU-LR!848D8B512C48
MAXmalware (ai score=89)
VBA32BScope.Backdoor.Cybergate
MalwarebytesBackdoor.SpyNet
PandaTrj/Ransom.AB
TrendMicro-HouseCallWORM_REBHIP.SMT
RisingBackdoor.SpyNet!1.CA8E (CLASSIC)
YandexTrojan.Spatet!yZjQJ3xqoc8
IkarusTrojan.Win32.Llac
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Llac.ALO!tr
AVGWin32:AutoRun-CIN [Trj]
Paloaltogeneric.ml

How to remove Generic.Rebhip.15D87B56?

Generic.Rebhip.15D87B56 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment