The virus modifies local files only. It has no ability to send itself in email or over local network. It has not been reported in the wild yet.
Perrun was written in Visual Basic and it is compressed with the UPX EXE compressor.
When the virus is started in it's EXE form it drops two files:
'extrk.exe' - the program that extracts the virus code from the JPEG files
'reg.mp3' - registry file that adds the extractor program as the handler for opening JPEG files
After this it looks for '*.jpg' files in the current directory and appends itself to them. It does not tuch the file if it has 'alco' as the four last bytes. This way it does not append itself to a file twice.
Since from here the JPEG files are opened with the special extractor the viral code can be started from the JPEG files. The extractor extracts the virus code to 'x.exe' in the current directory and runs it. After that the JPEG file itself is opened with the original handler.