BitDefender Antivirus

Win32.Worm.Doomjuice.A

( Worm.Win32.Doomjuice )
Spreading: very low
Damage: very low
Size: 36864 bytes
Discovered: 2004 Feb 09

SYMPTOMS:

The following file in Windows System directory (%SYSDIR%):
INTRENAT.EXE

Registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
with the value:
Gremlin = %SYSDIR%\INTRENAT.EXE

Activity on port 3127.

TECHNICAL DESCRIPTION:

This virus was especially designed to drop an archive that looks like the source-code of the Novarg/Mydoom worm.

After copying itself to System directory with the name INTRENAT.EXE, it creates an archive file called sync-src-1.00.tbz (28569 bytes) to all fixed or remote drives, as well as in the Windows and System directories, in the current Temporary folder and current user home folder, containing files that seem to be source-code of the Mydoom worm.

Also it creates the following registry key, so as to run each time Windows starts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
with the value:
Gremlin = %SYSDIR%\INTRENAT.EXE

It spreads using the backdoor installed on port 3127 by the first Mydoom variant.

The worm also attempts to attack www.microsoft.com in months: March until December, or if the day is greater than 8, except January.

Removal instructions:

Let BitDefender delete all files found infected with this worm.

ANALYZED BY:

Mihai Neagu BitDefender Virus Researcher