Malware

Generic.Rebhip.3356BA74 removal guide

Malware Removal

The Generic.Rebhip.3356BA74 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rebhip.3356BA74 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

kauan0802.duckdns.org

How to determine Generic.Rebhip.3356BA74?


File Info:

crc32: E05B6284
md5: 02d37ed4bc3422b573fce8265a434d1b
name: 02D37ED4BC3422B573FCE8265A434D1B.mlw
sha1: 57c2ff77566afcfbf5d75c5912a22a19656afa29
sha256: 571a708504cf085b54eaed702a6c95b3189426dc20c78e42a3f1e1096d6bf044
sha512: cb33ce0df6ce4dcc093f821e08cbd4307540c03cf239e89934e267457705d8ae911004d411555ff95189413f93f9b09105f800e86a74d3bf9e06462133651cc1
ssdeep: 12288:epLNX61Sz03E02kEHLNeYl0AshrWbFJeV7IdaneHKDuUbtH:4BX4S0ESEHQYeAeypJeV68eqLhH
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Rebhip.3356BA74 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00193f571 )
Elasticmalicious (high confidence)
DrWebBackDoor.Cybergate.1
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.A8
ALYacGeneric.Rebhip.3356BA74
CylanceUnsafe
ZillyaTrojan.Llac.Win32.65920
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Rebhip.9125442f
K7GWTrojan ( 00193f571 )
Cybereasonmalicious.4bc342
BaiduWin32.Trojan.Agent.co
CyrenW32/Rebhip.B.gen!Eldorado
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.A
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Agent-36200
KasperskyTrojan.Win32.Llac.lgnr
BitDefenderGeneric.Rebhip.3356BA74
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472[UPX]
MicroWorld-eScanGeneric.Rebhip.3356BA74
TencentTrojan.Win32.Downloader.aat
Ad-AwareGeneric.Rebhip.3356BA74
SophosML/PE-A + W32/Rebhip-AR
ComodoTrojWare.Win32.MalPack.~ULR@1qgdfh
BitDefenderThetaAI:Packer.817E064F21
VIPREWorm.Win32.Rebhip.A (v)
TrendMicroTSPY_SPATET.SMT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hc
FireEyeGeneric.mg.02d37ed4bc3422b5
EmsisoftGeneric.Rebhip.3356BA74 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Llac.kzj
AviraTR/Spy.Gen
eGambitRAT.CyberGate
MicrosoftTrojanSpy:Win32/Rebhip
ArcabitGeneric.Rebhip.3356BA74
AegisLabTrojan.Win32.Llac.lqUL
GDataGeneric.Rebhip.3356BA74
AhnLab-V3Trojan/Win32.Llac.R856
Acronissuspicious
McAfeeArtemis!02D37ED4BC34
MAXmalware (ai score=81)
VBA32Trojan.Llac
MalwarebytesSpyware.PasswordStealer
PandaTrj/Spy.YM
TrendMicro-HouseCallTSPY_SPATET.SMT
RisingWorm.Rebhip!1.A338 (CLOUD)
YandexTrojan.GenAsa!1nY3u3qKVEI
IkarusTrojan.Win32.Llac
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Llac.GFU!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generic.Rebhip.3356BA74?

Generic.Rebhip.3356BA74 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment