Worm

Worm:Win32/Rebhip.A removal instruction

Malware Removal

The Worm:Win32/Rebhip.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Rebhip.A virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Worm:Win32/Rebhip.A?


File Info:

crc32: 3EE65A5E
md5: a6512e80a4655f9fc9c20c4cb6e62145
name: server.exe
sha1: 4b25195b19a2dd5b6e90e718c00267b111b6a773
sha256: d687b69115f3390366ff83aa19d0a59e8cd889dc3048d2bc3bada425d4988176
sha512: 29c7530d8f1c3c3ad1230231f4988630654e20f89a0fe7a49b9a04750f02f28c7f7cbfc3c20ad1e17513ca769c920ec8659fc04df928148ed25312631f9ad61e
ssdeep: 768:XN0txCv8Y5gZBFT2lil6Mu24zs03VPg2psVx:9exCEY5gol46MuHzs0Vpsj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Worm:Win32/Rebhip.A also known as:

BkavW32.eHeur.Malware08
MicroWorld-eScanGeneric.Rebhip.8933E057
CMCTrojan.Win32.Llac!O
CAT-QuickHealWorm.Rebhip.A8
McAfeeGeneric PWS.di
MalwarebytesBackdoor.SpyNet
VIPREWorm.Win32.Rebhip.A (v)
TheHackerPosible_Worm32
K7GWTrojan ( 000174ea1 )
K7AntiVirusTrojan ( 000174ea1 )
TrendMicroTSPY_SPATET.SMT
BaiduWin32.Trojan.Agent.co
CyrenW32/Trojan.DNXI-5341
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.A
TrendMicro-HouseCallTSPY_SPATET.SMT
AvastWin32:AutoRun-CIN [Trj]
ClamAVWin.Trojan.Agent-36200
KasperskyTrojan.Win32.Llac.kzfk
BitDefenderGeneric.Rebhip.8933E057
NANO-AntivirusTrojan.Win32.Llac.crkzmz
AegisLabW32.W.SpyBot.lm6Z
TencentTrojan.Win32.Downloader.aat
Ad-AwareGeneric.Rebhip.8933E057
SophosW32/Rebhip-AR
ComodoTrojWare.Win32.PSW.Delf.~JHN
F-SecureBackdoor:W32/Spyrat.A
DrWebBackDoor.Cybergate.1
Invinceabackdoor.win32.xtrat.a
McAfee-GW-EditionBehavesLike.Win32.Dropper.mc
EmsisoftGeneric.Rebhip.8933E057 (B)
F-ProtW32/Trojan2.JRCA
JiangminTrojan/Generic.svbh
AviraTR/Spy.Gen
FortinetW32/Llac.GFU!tr
Antiy-AVLTrojan/Win32.Llac.bdm
ArcabitGeneric.Rebhip.8933E057
ViRobotTrojan.Win32.A.Llac.483197[UPX][h]
MicrosoftWorm:Win32/Rebhip.A
AhnLab-V3Trojan/Win32.Llac.R856
ALYacGeneric.Rebhip.8933E057
AVwareWorm.Win32.Rebhip.A (v)
VBA32Trojan.Llac
RisingMalware.Heuristic!ET#99% (rdm+)
YandexWorm.DR.Rebhip.Gen
IkarusTrojan.Win32.Llac
GDataGeneric.Rebhip.8933E057
AVGGeneric16.BNOB
PandaTrj/Ransom.AB
Qihoo-360HEUR/QVM11.1.0000.Malware.Gen

How to remove Worm:Win32/Rebhip.A?

Worm:Win32/Rebhip.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment