Rejoice 2.2
(Backdoor.Win32.Hupigon.rf)
(not-a-virus:RemoteAdmin.Win32.Rejoice.f)

by ?

Released in November 2005

Made in China

more versions


Server:
dropped files:
c:\WINDOWS\rejoice_06.exe          Size: 288,413 bytes 
c:\WINDOWS\rejoice_06.exepc.dll    Size: 26,624 bytes 

KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDOWS_REJOICE2006\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows_rejoice2006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_REJOICE2006\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows_rejoice2006


tested on Windows XP
December 26, 2005

MegaSecurity