Home / malwarePDF  

Win32.Worm.Doomjuice.A


First posted on 21 November 2011.
Source: BitDefender

Aliases :

Win32.Worm.Doomjuice.A is also known as Worm.Win32.Doomjuice.

Explanation :

This virus was especially designed to drop an archive that looks like the source-code of the Novarg/Mydoom worm.

After copying itself to System directory with the name INTRENAT.EXE, it creates an archive file called sync-src-1.00.tbz (28569 bytes) to all fixed or remote drives, as well as in the Windows and System directories, in the current Temporary folder and current user home folder, containing files that seem to be source-code of the Mydoom worm.

Also it creates the following registry key, so as to run each time Windows starts:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
with the value:
Gremlin = %SYSDIR%INTRENAT.EXE

It spreads using the backdoor installed on port 3127 by the first Mydoom variant.

The worm also attempts to attack www.microsoft.com in months: March until December, or if the day is greater than 8, except January.

Last update 21 November 2011

 

TOP