Win32.Worm.Doomjuice.A
VERY LOW
VERY LOW
36864 bytes
(Worm.Win32.Doomjuice)
Symptoms
The following file in Windows System directory (%SYSDIR%):
INTRENAT.EXE
Registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
with the value:
Gremlin = %SYSDIR%\INTRENAT.EXE
Activity on port 3127.
Removal instructions:
Let BitDefender delete all files found infected with this worm.
Analyzed By
Mihai Neagu BitDefender Virus Researcher
Technical Description:
This virus was especially designed to drop an archive that looks like the source-code of the Novarg/Mydoom worm.
After copying itself to System directory with the name INTRENAT.EXE, it creates an archive file called sync-src-1.00.tbz (28569 bytes) to all fixed or remote drives, as well as in the Windows and System directories, in the current Temporary folder and current user home folder, containing files that seem to be source-code of the Mydoom worm.
Also it creates the following registry key, so as to run each time Windows starts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
with the value:
Gremlin = %SYSDIR%\INTRENAT.EXE
It spreads using the backdoor installed on port 3127 by the first Mydoom variant.
The worm also attempts to attack www.microsoft.com in months: March until December, or if the day is greater than 8, except January.
SHARE
THIS ON