My Bitdefender
  • 0 Shopping Cart

SHARE
THIS ON

Facebook Twitter Google Plus

Win32.Worm.Doomjuice.A

VERY LOW
VERY LOW
36864 bytes
(Worm.Win32.Doomjuice)

Symptoms

The following file in Windows System directory (%SYSDIR%):
INTRENAT.EXE

Registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
with the value:
Gremlin = %SYSDIR%\INTRENAT.EXE

Activity on port 3127.

Removal instructions:

Let BitDefender delete all files found infected with this worm.

Analyzed By

Mihai Neagu BitDefender Virus Researcher

Technical Description:

This virus was especially designed to drop an archive that looks like the source-code of the Novarg/Mydoom worm.

After copying itself to System directory with the name INTRENAT.EXE, it creates an archive file called sync-src-1.00.tbz (28569 bytes) to all fixed or remote drives, as well as in the Windows and System directories, in the current Temporary folder and current user home folder, containing files that seem to be source-code of the Mydoom worm.

Also it creates the following registry key, so as to run each time Windows starts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
with the value:
Gremlin = %SYSDIR%\INTRENAT.EXE

It spreads using the backdoor installed on port 3127 by the first Mydoom variant.

The worm also attempts to attack www.microsoft.com in months: March until December, or if the day is greater than 8, except January.