Wscript/Jer.worm

Virus Characteristics

This is a Visual Basic Script worm, originally posted within an web page encoded in HTML and VBScript. This worm attempts to distribute itself vai IRC channels and also MAPI email. This trojan also contains a registry modification routine which modifies policy settings, changing the appearance of the Desktop among other setting changes.

There have been a few variants created after the initial release of this script. It was reportedly sent as a link to several users in a chat session who reportedly visited the page where the script was hosted.

In the original web page, it was titled “THE 40 WAYS WOMEN FAIL IN BED” and contained text as well as the Internet worm scripting. Users who viewed the web with low Internet security settings were highest at risk.

The script when run writes a file to the local system and modifies the registry to load this file at Windows startup. The first version of the script wrote “ewell.htm” while another variant wrote “1on1mail.htm”. The registry location is:

HKLMSoftwareMicrosoftWindowsCurrentVersionRun

The registry is also modified with these changes (original values are ’0′):

HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer
NoClose = 1
NoDesktop = 1
NoFind = 1

HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesNetwork
NoNetSetup = 1

HKLMSoftwareMicrosoftWindowsCurrentVersion
Version = VBS.Brian_Ewell
RegisteredOwner = Did you just get this job?
RegisteredOrganization = Symantec® 2000

After modifying the registry, this worm modifies the local script files MIRC.INI or SCRIPT.INI in a method to distribute itself when joining IRC channels.

After this process, it attempts to send a message using MAPI email in this format:

Subject = “Brian Ewell Resume”
Body = “I would really like to get a new job. Please check out my resume.”
“Enjoy :-)
“Brian Ewell”
Attachments = “Ewell.htm”


VIRUS FAMILY STATISTICS – Past 30 Days

Virus Name

Infected 

Files

 

 

 


Scanned 

Files

 

 

 


% Infected 

Computers

 

 

 


Jeru.1244

0

0

0.00

Jeru.1244.a

2

33,022

0.00

Jeru.1552

0

0

0.00

Jeru.1719.b

0

0

0.00

Jeru.1960

0

0

0.00

Jeru.Anarkia.1808.a

0

0

0.00

Jeru.Antiscan.1605

0

0

0.00

Jeru.Barcelona.1792

0

0

0.00

Jeru.Clipper.1413

0

0

0.00

Jeru.Cvex3.5120

0

0

0.00

Jeru.Cvex7.1.6144

0

0

0.00

Jeru.Czech.b

0

0

0.00

Jeru.Discom.2053

0

0

0.00

Jeru.dr

0

0

0.00

Jeru.Groen.1888

0

0

0.00

Jeru.Kylie.2272

0

0

0.00

Jeru.Miky.2350

0

0

0.00

Jeru.Nov30.GR

0

0

0.00

Jeru.Sublime.1496

0

0

0.00

Jeru.Sunday.1631a

0

0

0.00

Jeru.Sunday.1631b

0

0

0.00

Jeru.Sunday.1728a

0

0

0.00

Jeru.Swiss.1808

0

0

0.00

Jeru.VTech.2358

0

0

0.00

Jeru.VTech.2880

0

0

0.00

Jeru.VTech.2886

0

0

0.00

Jeru.Yellow.1363

0

0

0.00

Jerusalem

0

0

0.00

Jerusalem.3503

0

0

0.00

Jerusalem.bd

0

0

0.00

Jerusalem.be

0

0

0.00

Jerusalem.bf

0

0

0.00

Jerusalem.bg

0

0

0.00

Jerusalem.bj

0

0

0.00

Jerusalem.bl

0

0

0.00

Jerusalem.bm

0

0

0.00

Jerusalem.bn

0

0

0.00

Jerusalem.br

0

0

0.00

Jerusalem.ca

0

0

0.00

Jerusalem.Carfield

0

0

0.00

Jerusalem.cc

0

0

0.00

Jerusalem.ch

0

0

0.00

Jerusalem.ci

0

0

0.00

Jerusalem.cj

0

0

0.00

Jerusalem.cl

0

0

0.00

Jerusalem.cm

0

0

0.00

Jerusalem.cn

0

0

0.00

Jerusalem.cp

4

33,022

0.00

Jerusalem.cq

0

0

0.00

Jerusalem.cr

0

0

0.00

Jerusalem.cs

0

0

0.00

Jerusalem.ct

0

0

0.00

Jerusalem.cw

0

0

0.00

Jerusalem.cy

0

0

0.00

Jerusalem.db

0

0

0.00

Jerusalem.dc

0

0

0.00

Jerusalem.dh

0

0

0.00

Jerusalem.GP1.1845

0

0

0.00

Pojer.GR

0

0

0.00

W97M/Jerk.gen

221

174,643

0.00

X97M/Jerk.gen

0

0

0.00
This entry was posted in Virus list & description and tagged , , , , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>