Malware

Generic.Rebhip.E69BC30C removal tips

Malware Removal

The Generic.Rebhip.E69BC30C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rebhip.E69BC30C virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

spylaura.duckdns.org

How to determine Generic.Rebhip.E69BC30C?


File Info:

crc32: 0DE893B7
md5: ad6248289ee5ed7b35c6d5c8170f3358
name: AD6248289EE5ED7B35C6D5C8170F3358.mlw
sha1: 8012bb6f78b33300aa0f147f37407afb0505fe9b
sha256: 03aa80423bf7c386abf21710440c7622151ed816d19a76f48525eb4a39b461a1
sha512: 036bfe4b132a71dc921f119caaae758bda7773b6cecbb87a8db8d323cf7fea9f3d01e159bb2984b67321e576aa0ba2699b4ac310118f7805136197a2c3d9c565
ssdeep: 24576:/FRRRcwIfUKDNhjWzRRRcwIfUKDNhjWyZOklu:tRRRcwIfUKDNhjWzRRRcwIfUKDNhjWOM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Rebhip.E69BC30C also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 000174ea1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Cybergate.1
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.A8
ALYacGeneric.Rebhip.E69BC30C
CylanceUnsafe
ZillyaTrojan.Llac.Win32.3683
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Rebhip.b338c673
K7GWTrojan ( 000174ea1 )
Cybereasonmalicious.89ee5e
BaiduWin32.Trojan.Agent.co
CyrenW32/Trojan.DNXI-5341
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.A
ZonerTrojan.Win32.60048
APEXMalicious
AvastWin32:AutoRun-CIN [Trj]
ClamAVWin.Trojan.Llac-7
KasperskyTrojan.Win32.Llac.lgnr
BitDefenderGeneric.Rebhip.E69BC30C
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472
SUPERAntiSpywareWorm.Rebhip
MicroWorld-eScanGeneric.Rebhip.E69BC30C
Ad-AwareGeneric.Rebhip.E69BC30C
SophosML/PE-A + W32/Rebhip-AR
ComodoTrojWare.Win32.PSW.Delf.~JHN@1l9grm
BitDefenderThetaAI:Packer.CE2BDB2E21
VIPREWorm.Win32.Rebhip.A (v)
TrendMicroTSPY_SPATET.SMT
McAfee-GW-EditionBehavesLike.Win32.Dropper.fm
FireEyeGeneric.mg.ad6248289ee5ed7b
EmsisoftGeneric.Rebhip.E69BC30C (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Delf.kux
WebrootWorm:Win32/Rebhip.A
AviraTR/Agent.598022
eGambitRAT.CyberGate
Antiy-AVLTrojan/Generic.ASBOL.DB8
KingsoftHeur.SSC.3218.1216.(kcloud)
MicrosoftTrojanSpy:Win32/Rebhip.A!upx
GridinsoftBackdoor.Win32.Rebhip.ka!s1
ArcabitGeneric.Rebhip.E69BC30C
GDataGeneric.Rebhip.E69BC30C
AhnLab-V3Win-Trojan/Infostealer.410624
Acronissuspicious
McAfeeGeneric PWS.di
MAXmalware (ai score=88)
VBA32Trojan.Llac
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Ransom.AB
TrendMicro-HouseCallTSPY_SPATET.SMT
RisingWorm.Rebhip!1.A338 (CLASSIC)
YandexTrojan.GenAsa!PLs8jFFaXyw
IkarusTrojan.Win32.Llac
MaxSecureTrojan.W32.LLAC.BDM
FortinetW32/Llac.GFU!tr
AVGWin32:AutoRun-CIN [Trj]
Paloaltogeneric.ml

How to remove Generic.Rebhip.E69BC30C?

Generic.Rebhip.E69BC30C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment