Malware

How to remove “Generic.Rebhip.7F9D51C4”?

Malware Removal

The Generic.Rebhip.7F9D51C4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rebhip.7F9D51C4 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
hellodadd.ddns.net

How to determine Generic.Rebhip.7F9D51C4?


File Info:

crc32: C1D95259
md5: bd80bab40e031fffef040d30290cedc0
name: BD80BAB40E031FFFEF040D30290CEDC0.mlw
sha1: 1069b2a511c7bade2e9176bdb97d71931fdd38f0
sha256: bf4d738ca10ac89eedef58ef072961bca7b7a6c3b680a1c2f365f35fac57644f
sha512: 33c8f8b7feb618ee537841d42c026b4d1cbd03a4ac9a1fa152d98b823726118f76deeb49dcd085a08543196340727383434f178c1d5b35d1f28d313b549a6b58
ssdeep: 98304:HXCM/kcIjAIAx6nHFXVDNBA2uimEs4AqsuUTvfZuvSnMhUlV46dRQRvKRgLPtFv:DF+k
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Rebhip.7F9D51C4 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 000174ea1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Cybergate.1
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.A8
ALYacGeneric.Rebhip.7F9D51C4
CylanceUnsafe
ZillyaTrojan.Llac.Win32.3683
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Rebhip.5703162a
K7GWTrojan ( 000174ea1 )
Cybereasonmalicious.40e031
BaiduWin32.Trojan.Agent.co
CyrenW32/Trojan.DNXI-5341
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.A
ZonerTrojan.Win32.60048
APEXMalicious
AvastWin32:AutoRun-CIN [Trj]
ClamAVWin.Trojan.Llac-7
KasperskyTrojan.Win32.Llac.lgnr
BitDefenderGeneric.Rebhip.7F9D51C4
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472
MicroWorld-eScanGeneric.Rebhip.7F9D51C4
TencentTrojan.Win32.Downloader.aat
Ad-AwareGeneric.Rebhip.7F9D51C4
SophosML/PE-A + W32/Rebhip-AR
ComodoTrojWare.Win32.PSW.Delf.~JHN@1l9grm
BitDefenderThetaAI:Packer.977EE0531B
VIPREWorm.Win32.Rebhip.A (v)
TrendMicroTSPY_SPATET.SMT
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeGeneric.mg.bd80bab40e031fff
EmsisoftGeneric.Rebhip.7F9D51C4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Delf.kux
AviraTR/Agent.598022
eGambitRAT.CyberGate
Antiy-AVLTrojan/Generic.ASBOL.DB8
KingsoftHeur.SSC.3218.1216.(kcloud)
MicrosoftTrojanSpy:Win32/Rebhip.A!upx
GridinsoftBackdoor.Win32.Rebhip.ka!s1
ZoneAlarmTrojan.Win32.Llac.lgnr
GDataGeneric.Rebhip.7F9D51C4
AhnLab-V3Win-Trojan/Llac.Gen
Acronissuspicious
McAfeeGeneric PWS.di
MAXmalware (ai score=100)
VBA32Trojan.Llac
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Ransom.AB
TrendMicro-HouseCallTSPY_SPATET.SMT
RisingWorm.Rebhip!1.A338 (CLASSIC)
IkarusTrojan.Win32.Llac
MaxSecureTrojan.W32.LLAC.BDM
FortinetW32/Llac.GFU!tr
AVGWin32:AutoRun-CIN [Trj]
Paloaltogeneric.ml

How to remove Generic.Rebhip.7F9D51C4?

Generic.Rebhip.7F9D51C4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment