Home Malware Programs Worms Worm:Win32/Rebhip.gen!A

Worm:Win32/Rebhip.gen!A

Posted: January 8, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 78
First Seen: January 8, 2013
OS(es) Affected: Windows

Worm:Win32/Rebhip.gen!A is a worm that circulates via removable drives by copying itself. Worm:Win32/Rebhip.gen!A attempts to steal personal information from the affected computer. Once installed on the targeted PC, Worm:Win32/Rebhip.gen!A makes system changes by dropping potentially malicious files and making registry modifications. Worm:Win32/Rebhip.gen!A creates the registry entry so that it can run automatically every time you start Windows. Worm:Win32/Rebhip.gen!A may also create copies on the victimized computer system. Worm:Win32/Rebhip.gen!A may also open the Internet Explorer process 'iexplore.exe' and insert a malicious code into it. Worm:Win32/Rebhip.gen!A then writes an Autorun configuration file called 'autorun.inf', which points to the copy of Worm:Win32/Rebhip.gen!A. If the drive is accessed from a computer, which supports the Autorun feature, Worm:Win32/Rebhip.gen!A is executed automatically. Worm:Win32/Rebhip.gen!A steals sensitive details by gathering various information about the targeted PC, for example, what security program is installed, and which processes or services are presently running. Worm:Win32/Rebhip.gen!A may also log keystrokes and collect passwords. Worm:Win32/Rebhip.gen!A transmits its gathered data to remote attackers.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[system folder]\taskmanager\task.exe File name: [system folder]\taskmanager\task.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[system folder]\WinDefence\windefence32.exe File name: [system folder]\WinDefence\windefence32.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[system folder]\install\system.exe File name: [system folder]\install\system.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[system folder]\windows\windows.exe File name: [system folder]\windows\windows.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
[system folder]\backup\winbackup.exe File name: [system folder]\backup\winbackup.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\xxx.xxx File name: %Temp%\xxx.xxx
Mime Type: unknown/xxx
Group: Malware file
%Temp%\uuu.uuu File name: %Temp%\uuu.uuu
Mime Type: unknown/uuu
Group: Malware file
%windir%\install\update.exe File name: %windir%\install\update.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run "WinDefence" = "[system folder]\WinDefence\windefence32.exe"HKEY_CURRENT_USER\Software\SlysBitch "FirstExecution" "NewIdentification" = "SlysBitch"HKEY_CURRENT_USER\Software\SlysBitch "FirstExecution" = "[current date and time]" (for example: "21/12/2009 -- 03:58")
Loading...