PLAGE2000
PE executable
2000
The worm has a WinZip icon pretending to be a self-extracting
ZIP archive.
The Plage worm arrives as an e-mail attachment and
being run installs itself to system as INETD.EXE to root Windows
folder.
When a recepient gets this message and clicks on the attachment
(which, he thinks is a ZIP archive) the worm infects his system
as well. First the worm outputs a WinZip Self-Extractor -like
dialog.
Being active the worm checks date and time and on Wednesdays
right after midnight it tries to display a dialog with the
following message:
"FOLLOW YOUR LEADER"
|