Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

REJOICE91.EXE is Backdoor Gpigeon.yho

$
0
0

The program REJOICE91.EXE is used for hidden penetration into PC and its remote administration.
UnHackMe is recommended as a reliable program for solving the problem with REJOICE91.EXE.
Download for free: http://www.unhackme.com

Malware Analysis of REJOICE91.EXE
Full path on a computer: %Program Files Common%\Microsoft Shared\MSInfo\rejoice91.exe

Detected by UnHackMe:

REJOICE91.EXE
Default location: %Program Files Common%\Microsoft Shared\MSInfo\rejoice91.exe

Removal Results: Success
Number of reboot: 1

REJOICE91.EXE is known as:

Backdoor.Gpigeon.yho, MalwareScope.Backdoor.Hupigon.17

REJOICE91.EXE hash:

  • MD5: 8b7afdb2f75f183aef4ab393f800adb3
How to quickly detect REJOICE91.EXE presence?
Registry:
  • HKLM\System\CurrentControlSet\Services\Windows\Type: 0×00000110
  • HKLM\System\CurrentControlSet\Services\Windows\Start: 0×00000002
  • HKLM\System\CurrentControlSet\Services\Windows\ErrorControl: 0×00000000
  • HKLM\System\CurrentControlSet\Services\Windows\ImagePath: “%Program Files Common%\Microsoft Shared\MSINFO\rejoice91.exe”
  • HKLM\System\CurrentControlSet\Services\Windows\DisplayName: “Windows”
  • HKLM\System\CurrentControlSet\Services\Windows\ObjectName: “LocalSystem”
  • HKLM\System\CurrentControlSet\Services\Windows\Description: “Windows”
Files:
  • %Program Files Common%\Microsoft Shared\MSInfo\rejoice91.exe
  • %SysDir%\_rejoice91.exe
  • C:\AutoRun.inf
  • C:\rejoice91.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>