Worm

How to remove “Worm:Win32/Rebhip”?

Malware Removal

The Worm:Win32/Rebhip is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Rebhip virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Worm:Win32/Rebhip?


File Info:

crc32: 185DE6DF
md5: d2f5e17fde1e9b82f7e6adb63ad27aa5
name: D2F5E17FDE1E9B82F7E6ADB63AD27AA5.mlw
sha1: d9c83ec80ab62b370d5cb3417ee9a0ff267cb4b7
sha256: dd305bbec55823c8c9fbd705c23b40c87857cd7bbcaac427bdf40d368560d706
sha512: b2be77fc7ce938420db6e519f67d550998b8378e8b8be0a41df58cf1d2caff21cba500f9985cdb8415895afb9212e3688d73258eb42f762a0047d97936ebb890
ssdeep: 12288:Gi+91pEqdMsUAQ4wHPD3+a99lV+xbel6tHrNB/+FTHD6GWdOOc8/PBW:Gi457bQr+Y3Gel6tHrNqEOD8E
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: compile.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: compile.exe

Worm:Win32/Rebhip also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.147948
Qihoo-360HEUR/Malware.QVM03.Gen
McAfeeGenericRXKP-CU!D2F5E17FDE1E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Kazy.147948
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fde1e9
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:GenMalicious-KT [Trj]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.TrjGen.bycyap
AegisLabTrojan.Win32.Generic.lJ9T
Ad-AwareGen:Variant.Kazy.147948
EmsisoftGen:Variant.Kazy.147948 (B)
ComodoTrojWare.MSIL.Agent.AOJ@543vcg
F-SecureHeuristic.HEUR/AGEN.1105886
DrWebBackDoor.Siggen.49176
ZillyaDropper.Injector.Win32.57197
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.d2f5e17fde1e9b82
SophosMal/Generic-S
IkarusTrojan.MSIL.Injector
JiangminTrojanDropper.Injector.bijo
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1105886
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftWorm:Win32/Rebhip
ArcabitTrojan.Kazy.D241EC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Kazy.147948
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZemsilF.34804.Wm0@aWxK9ll
ALYacGen:Variant.Kazy.147948
MAXmalware (ai score=100)
VBA32TrojanDropper.Injector
PandaGeneric Malware
ESET-NOD32a variant of MSIL/Injector.AOI
TencentWin32.Trojan-dropper.Injector.Wstp
YandexTrojan.DR.Injector!DXo64ANBSoQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Injector.AOI!tr
AVGMSIL:GenMalicious-KT [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Worm:Win32/Rebhip?

Worm:Win32/Rebhip removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment