Threat Database Worms Worm:Win32/Rebhip.gen!A

Worm:Win32/Rebhip.gen!A

By ZulaZuza in Worms

Worm:Win32/Rebhip.gen!A is a worm that is proliferates via removable drives by replicating itself. Worm:Win32/Rebhip.gen!A strives to steal confidential information from the victim. While being installed on the corrupted machine, Worm:Win32/Rebhip.gen!A makes system changes by downloading malevolent files and modifying the Windows Registry. Worm:Win32/Rebhip.gen!A creates the registry entry so that it can load automatically whenever Windows is started. Worm:Win32/Rebhip.gen!A may also open the Internet Explorer process 'iexplore.exe' and embed a malevolent code into it. Worm:Win32/Rebhip.gen!A then writes an Autorun configuration file called 'autorun.inf', which points to the copy of Worm:Win32/Rebhip.gen!A. If the drive is accessed from a computer, which supports the Autorun feature, Worm:Win32/Rebhip.gen!A runs automatically. Worm:Win32/Rebhip.gen!A steals private details by gathering various data about the victimized PC, such as what anti-virus program is installed, and which processes or services are presently running. Worm:Win32/Rebhip.gen!A may also log keystrokes and grab passwords. Worm:Win32/Rebhip.gen!A transfers its collected data to a remote attacker.

File System Details

Worm:Win32/Rebhip.gen!A may create the following file(s):
# File Name Detections
1. [system folder]\install\system.exe
2. %windir%\install\update.exe
3. [system folder]\WinDefence\windefence32.exe
4. [system folder]\backup\winbackup.exe
5. [system folder]\taskmanager\task.exe
6. [system folder]\windows\windows.exe
7. %Temp%\uuu.uuu
8. %Temp%\xxx.xxx

Registry Details

Worm:Win32/Rebhip.gen!A may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\SlysBitch "FirstExecution" = "[current date and time]" (for example: "21/12/2009 -- 03:58")
HKEY_CURRENT_USER\Software\SlysBitch "FirstExecution" "NewIdentification" = "SlysBitch"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run "WinDefence" = "[system folder]\WinDefence\windefence32.exe"

Trending

Most Viewed

Loading...