Home Malware Programs Worms Worm.Win32.Rebhip

Worm.Win32.Rebhip

Posted: October 11, 2010

Threat Metric

Threat Level: 7/10
Infected PCs: 94
First Seen: October 8, 2010
Last Seen: June 27, 2020
OS(es) Affected: Windows

Worm.Win32.Rebhip is a dangerous computer worm that uses its small file size and other attached drives to propagate and spread. Worm.Win32.Rebhip has been known to act as a downloader imitating the download of other malware onto the infected system without a users knowledge. It is very important to detect and remove Worm.Win32.Rebhip with a spyware removal tool to ensure all remnants of Worm.Win32.Rebhip are completely removed.

Worm.Win32.Rebhip

Aliases

Generic Malware [Panda]Worm/Generic2.ANQI [AVG]W32/Injector.FHJ!tr [Fortinet]Gen.Variant.Inject [Ikarus]Win-Trojan/Agent.100352.EV [AhnLab-V3]Backdoor/Win32.Inject.gen [Antiy-AVL]Troj/Buzus-FZ [Sophos]TR/Inject.12.24 [AntiVir]Trojan.Inject.28852 [DrWeb]Heur.Suspicious [Comodo]Gen:Variant.Inject.12 [BitDefender]Win32.Injector.Fjs [eSafe]Win32:Kryptik-BAY [Avast]a variant of Win32/Injector.FJS [NOD32]BackDoor-EXI.gen.j [McAfee]
More aliases (67)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\install\winupdate.exe File name: winupdate.exe
Size: 351.23 KB (351232 bytes)
MD5: 1490f5f58ed8d3c08a4426ace01189f6
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\install
Group: Malware file
Last Updated: October 18, 2010
%APPDATA%\winlog\winlog.exe File name: winlog.exe
Size: 531.92 KB (531926 bytes)
MD5: 49a277fd66bbda545c931738c3290353
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\winlog
Group: Malware file
Last Updated: June 27, 2020
%APPDATA%\install\wimlogon.exe File name: wimlogon.exe
Size: 2.39 MB (2397184 bytes)
MD5: 43cee74b1933fe036b02704d44704180
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\install
Group: Malware file
Last Updated: May 18, 2012
%APPDATA%\WinDir\server.exe File name: server.exe
Size: 412.16 KB (412160 bytes)
MD5: 0adecd3cb9348eb448a29976a0e71291
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\WinDir
Group: Malware file
Last Updated: March 18, 2011
%APPDATA%\Defender\csrss.exe File name: csrss.exe
Size: 537.08 KB (537088 bytes)
MD5: c834627ccb82d0c918ace4597fe10905
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Defender
Group: Malware file
Last Updated: October 29, 2012

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\Microsoft\System32.exe%APPDATA%\System\System32.exe
Loading...