Malware

About “Generic.Rebhip.74CD7671” infection

Malware Removal

The Generic.Rebhip.74CD7671 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rebhip.74CD7671 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

fb-idlogin.myvnc.com

How to determine Generic.Rebhip.74CD7671?


File Info:

crc32: 69811F7D
md5: 5e8ff2d8309542dd8af7f986ce14b50d
name: 5E8FF2D8309542DD8AF7F986CE14B50D.mlw
sha1: 51839476caa2ef7bbb5b422cf62996faccb27181
sha256: b453ec326f7c5292871c186771f08f6f1dc87aca44e8f8e8ac937a03e7f930a2
sha512: da559d0630c4d864019b93af280a318dc92b1bbf0d826781338f779c86f12bce658baca0ff0cd8495d044711c2ac0bbde2961fc738aee71193f92c2e99755467
ssdeep: 6144:7k4qm8jE+tU1BsvPc2oS3LY28uR6mD+wc2R0sFFVQo:A9E3AvpYZuR6mK12NQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Rebhip.74CD7671 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00193f571 )
Elasticmalicious (high confidence)
DrWebBackDoor.Cybergate.1
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.Z.mue
ALYacGeneric.Rebhip.74CD7671
CylanceUnsafe
ZillyaTrojan.Llac.Win32.3684
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 00193f571 )
Cybereasonmalicious.830954
BaiduWin32.Trojan.Agent.co
CyrenW32/Rebhip.B.gen!Eldorado
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.A
APEXMalicious
AvastWin32:Dropper-FJG [Trj]
ClamAVWin.Trojan.Agent-36136
KasperskyTrojan.Win32.Llac.lgnr
BitDefenderGeneric.Rebhip.74CD7671
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472[UPX]
SUPERAntiSpywareTrojan.Agent/Gen-FraudLoad
MicroWorld-eScanGeneric.Rebhip.74CD7671
TencentTrojan.Win32.Downloader.aat
Ad-AwareGeneric.Rebhip.74CD7671
SophosML/PE-A + W32/Rebhip-AR
ComodoTrojWare.Win32.Llac.C@1lpak6
BitDefenderThetaAI:Packer.F385D92B1B
VIPREWorm.Win32.Rebhip.A (v)
TrendMicroTSPY_LLAC.SML
FireEyeGeneric.mg.5e8ff2d8309542dd
EmsisoftGeneric.Rebhip.74CD7671 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Llac.bsb
WebrootWorm:Win32/Rebhip.A
AviraWORM/Rebhip.V
eGambitRAT.CyberGate
MicrosoftTrojanSpy:Win32/Rebhip
GridinsoftBackdoor.Win32.Fynloski.vl!i
GDataGeneric.Rebhip.74CD7671
TACHYONTrojan/W32.DP-Swisyn.297472
AhnLab-V3Trojan/Win32.Llac.R856
Acronissuspicious
McAfeeGeneric PWS.ld
MAXmalware (ai score=87)
VBA32Trojan.Llac
MalwarebytesTrojan.Downloader
PandaTrj/Ransom.AB
TrendMicro-HouseCallTSPY_LLAC.SML
RisingWorm.Rebhip!1.A338 (RDMK:cmRtazpu/trcVfdBjF34RP8N6xm4)
IkarusTrojan.Win32.Llac
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Llac.GFU!tr
AVGWin32:Dropper-FJG [Trj]

How to remove Generic.Rebhip.74CD7671?

Generic.Rebhip.74CD7671 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment