CyberZoo Biological Hazard    


PE executable

The worm has a WinZip icon pretending to be a self-extracting ZIP archive.
The Plage worm arrives as an e-mail attachment and being run installs itself to system as INETD.EXE to root Windows folder.

When a recepient gets this message and clicks on the attachment (which, he thinks is a ZIP archive) the worm infects his system as well. First the worm outputs a WinZip Self-Extractor -like dialog.
Being active the worm checks date and time and on Wednesdays right after midnight it tries to display a dialog with the following message: