This memory-resident worm spreads copies of itself as attachments to email messages. It gathers target email addresses by searching an affected system for files with certain extensions.
The email message it sends out is written in Indonesian and has the following details:
Subject: {blank}
Message body:
— Hentikan kebobrokan di negeri ini —
1. Penjarakan Koruptor, Penyelundup, Tukang Suap, & Bandar NARKOBA
2. Stop Free Sex, Aborsi, & Prostitusi?brA( Go To HELL )
3. Stop pencemaran lingkungan, pembakaran hutan & perburuan liar.
4. SAY NO TO DRUGS !!!
— KIAMAT SUDAH DEKAT —
Terinspirasi oleh:
Elang Brontok (Spizaetus Cirrhatus) yang hampir punah
— JowoBot #VM Community —
!!! Akan Kubuat Mereka (VM lokal yg cengeng & bodoh) Terkapar !!!
Attachment: (a copy of this worm using any of the following file names)
• CCAPPS.EXE
• JANGAN DIBUKA.EXE
• KANGEN.EXE
• MY HEART.EXE
• MYHEART.EXE
• SYSLOVE.EXE
• UNTUKMU.EXE
• WINWORD.EXE
Notably, it avoids sending messages to email addresses containing strings that are related to antivirus and security companies. It does the said routine to prevent its early detection on the compromised system.
It also disables the Folder Options item in the Tools drop-down menu from the main menu bar of Windows Explorer and Control Panel. The said action prevents the affected user from changing such settings as displaying hidden folders and displaying file paths in title bars. This worm also disables the Registry Editor.
It causes the affected computer to pause during startup. It does the said action by adding the string pause in the file AUTOEXEC.BAT. It also restarts the affected system when it finds an open window with certain strings in the title bar.
Furthermore, it uses a Windows folder icon to trick affected users into thinking that it is a valid folder. When the icon is clicked, it opens the process EXPLORER.EXE to hide its execution. It also opens a document folder after its execution.
This worm also deletes the valid file RUNDLL32.EXE.