Spy Trojan

TrojanSpy:Win32/Rebhip.A!upx removal

Malware Removal

The TrojanSpy:Win32/Rebhip.A!upx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Rebhip.A!upx virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

nikaowed.ddns.net

How to determine TrojanSpy:Win32/Rebhip.A!upx?


File Info:

crc32: A05DF82F
md5: 1bf86670253a1aa5157a115ed2750aef
name: testando123.exe
sha1: 1e80e6adf66310530930866ff697edbbfd41c057
sha256: b49f7bc33c6f75e4576da4fb494ab6cb4cf3de10612e7aac415ab2bb98220dac
sha512: 60c1dfefe8e338d013aadcf2ff2bfccf263e7c55649c223192b35b9f18a62df3375e3f0d68ab24b8558c8ddb8a73abd6696bcff611255b5f3872c3dd95f9c426
ssdeep: 6144:Ok4qm6z4tH/vwYPc/cv7kdzW767Zslxm2YO4+0ErFwWv:R9CfvwYQCUz7ZslxN4gZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

TrojanSpy:Win32/Rebhip.A!upx also known as:

MicroWorld-eScanGeneric.Rebhip.F0E4876F
FireEyeGeneric.mg.1bf86670253a1aa5
CAT-QuickHealWorm.Rebhip.Z.mue
McAfeeGeneric PWS.ld
ALYacGeneric.Rebhip.F0E4876F
MalwarebytesTrojan.Dropper
VIPREWorm.Win32.Rebhip.A (v)
K7AntiVirusTrojan ( 00193f571 )
BitDefenderGeneric.Rebhip.F0E4876F
K7GWTrojan ( 00193f571 )
Cybereasonmalicious.0253a1
Invinceaheuristic
BaiduWin32.Trojan.Agent.co
F-ProtW32/Trojan2.JRCA
SymantecW32.Spyrat
TotalDefenseWin32/Spyrat!generic
APEXMalicious
AvastWin32:Dropper-FJG [Trj]
ClamAVWin.Trojan.Agent-36136
GDataGeneric.Rebhip.F0E4876F
KasperskyTrojan.Win32.Llac.lgnr
AlibabaWorm:Win32/Llac.0c586b32
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472[UPX]
AegisLabTrojan.Win32.Llac.4!c
RisingWorm.Rebhip!1.A338 (CLASSIC)
Endgamemalicious (moderate confidence)
SophosW32/Rebhip-AR
ComodoTrojWare.Win32.MalPack.~ULR@1qgdfh
F-SecureBackdoor:W32/Spyrat.A
DrWebBackDoor.Cybergate.1
ZillyaTrojan.Llac.Win32.3684
TrendMicroTSPY_LLAC.SML
McAfee-GW-EditionBehavesLike.Win32.Leox.dc
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Llac!O
EmsisoftGeneric.Rebhip.F0E4876F (B)
IkarusTrojan.Win32.Llac
CyrenW32/Rebhip.B.gen!Eldorado
JiangminTrojan/Llac.kzj
WebrootWorm:Win32/Rebhip.A
AviraWORM/Rebhip.V
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Llac.bdm
ArcabitGeneric.Rebhip.F0E4876F
SUPERAntiSpywareTrojan.Agent/Gen-Spyrat
ZoneAlarmTrojan.Win32.Llac.lgnr
MicrosoftTrojanSpy:Win32/Rebhip.A!upx
AhnLab-V3Trojan/Win32.Llac.R856
Acronissuspicious
VBA32Trojan.Llac
TACHYONTrojan/W32.DP-Llac.290304
Ad-AwareGeneric.Rebhip.F0E4876F
CylanceUnsafe
PandaTrj/Ransom.AB
ZonerTrojan.Win32.60048
ESET-NOD32Win32/Spatet.A
TrendMicro-HouseCallTSPY_LLAC.SML
TencentTrojan.Win32.Downloader.aat
YandexWorm.DR.Rebhip.Gen
SentinelOneDFI – Malicious PE
MaxSecureTrojan.W32.LLAC.BDM
FortinetW32/Llac.GFU!tr
AVGWin32:Dropper-FJG [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Dropper.0f4

How to remove TrojanSpy:Win32/Rebhip.A!upx?

TrojanSpy:Win32/Rebhip.A!upx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment