Additional Details
When the attached file is executed, the worm will mail itself to the
each recipient in every address book. After mass mailing the following
key is added to the registry:
HKEY_CURRENT_USER\software\Cindy\mailed
This variant also replicates using mIRC and Pirch IRC clients. It replaces
the "script.ini" from mIRC and "events.ini" from Pirch installation
directories, causing that the worm will send itself to the IRC user
that joins the channel where an infected user is.
VBSWG.V also goes trough all local and network drivers from the
system, and replaces every file with either ".vbs" or ".vbe" extension
with itself. It also attempts to locate mIRC and Pirch installations
from these drives.
This variant shows the following message box upon execution:
Error Decompressing JPEG Picture
Information about the original VBS/Onthefly.A (also known as
I-Worm.Lee.o and VBS/VBSWG) is available at:
http://www.F-Secure.com/v-descs/onthefly.shtml
[Analysis: Katrin Tocheva and Sami Rautiainen, F-Secure; March 2001]