Worm

Worm.Rebhip.AH8 removal tips

Malware Removal

The Worm.Rebhip.AH8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Rebhip.AH8 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Worm.Rebhip.AH8?


File Info:

crc32: 6D502CC1
md5: 71963f9616393b8fe6f16bbfdc51a15d
name: 71963F9616393B8FE6F16BBFDC51A15D.mlw
sha1: 298f0221d59bd212e683cf526a638999b8d37049
sha256: 8a7552c36488a575e8854d7cacea68b682588f1dde0ec86591d38079894a6c1c
sha512: 59cdfd9bc0e4aca0999768f2ece5b74a29c65acfddcb97afb71d1117116121abaa26fda14383ac590d5a696b9c18c70165e6d18ceaae30009b4b8f1d948f1c10
ssdeep: 12288:BuMwaBi8vvrHxVPKyv2m77sZB07FxObO32X:BHwT8vrx52t07FQaw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm.Rebhip.AH8 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 000e9c271 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.15250
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.AH8
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 000e9c271 )
Cybereasonmalicious.616393
BaiduWin32.Trojan.Agent.co
CyrenW32/Rebhip.BRVH-2545
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.T
APEXMalicious
AvastWin32:BackDoor-ACX [Trj]
ClamAVWin.Packed.Spynet-6841468-0
KasperskyTrojan.Win32.Bublik.aeld
BitDefenderDropped:Trojan.Agent.BNNW
NANO-AntivirusTrojan.Win32.Llac.dzfflc
ViRobotTrojan.Win32.Agent.438272.K
MicroWorld-eScanDropped:Trojan.Agent.BNNW
TencentTrojan.Win32.Llac.dcro
Ad-AwareDropped:Trojan.Agent.BNNW
SophosML/PE-A + Troj/FakeAV-HCQ
ComodoTrojWare.Win32.Trojan.Amtar.~cbg@378gk7
BitDefenderThetaAI:Packer.D8AD88451E
VIPREWorm.Win32.Rebhip.ac (v)
TrendMicroWORM_REBHIP.SMAC
McAfee-GW-EditionBehavesLike.Win32.HLLP.gc
FireEyeGeneric.mg.71963f9616393b8f
EmsisoftDropped:Trojan.Agent.BNNW (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aiffg
AviraTR/Hijacker.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASBOL.234
KingsoftHeur.SSC.2667848.1216.(kcloud)
MicrosoftTrojanSpy:Win32/Rebhip.C
GridinsoftTrojan.Win32.Agent.vb!s1
ArcabitTrojan.Agent.BNNW
SUPERAntiSpywareWorm.Rebhip
GDataDropped:Trojan.Agent.BNNW
TACHYONTrojan/W32.DP-Bublik.438272
AhnLab-V3Trojan/Win32.Jorik.C163167
Acronissuspicious
McAfeeW32/Worm-FOB!71963F961639
MAXmalware (ai score=87)
VBA32BScope.Trojan.Bublik
MalwarebytesTrojan.Delf
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_REBHIP.SMAC
RisingWorm.Rebhip!1.A338 (CLASSIC)
YandexTrojan.GenAsa!8685pJIV2Xc
IkarusVirus.Win32.Dracur
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Spatet.TRR!tr
AVGWin32:BackDoor-ACX [Trj]

How to remove Worm.Rebhip.AH8?

Worm.Rebhip.AH8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment