Content

W32/Plage.worm

Type
Virus
SubType
Worm
Discovery Date
01/13/2000
Length
Minimum DAT
4062 (01/26/2000)
Updated DAT
4062 (01/26/2000)
Minimum Engine
5.1.00
Description Added
01/13/2000
Description Modified
01/13/2000 12:00 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This is an Internet worm which can autoreply to unread email messages of MAPI installed email clients. The autoreply message contains a brief note along with an attachment of random EXE names. The email message will be replied to in Unix-style format such as the example below:



Sent: Thursday, January 13, 2000 12:08 PM
To: SMTP:sender@domain.com
Subject: Re: original subject line

'Lastname, Firstname' wrote:
====
-
-
-
====

P2000 Mail auto-reply:
' I'll try to reply as soon as possible.
Take a look to the attachment and send me your opinion! '

> Get your FREE P2000 Mail now! <


The attachment is any of the following names:
billgt.exe
card.exe
docs.exe
fun.exe
hamster.exe
humor.exe
images.exe
joke.exe
midsong.exe
news_doc.exe
pics.exe
PsPGame.exe
searchURL.exe
SETUP.EXE
s3msong.exe
tamagotxi.exe

The size of the file is 102,400 bytes and has an icon similar to PKLite self extracting, very similar to W32/ExploreZip.worm. There is one noticeable difference however in that this worm was not witnessed to have removed files from the system.

When the attachment is executed, it will give a phony error message and then install itself on Windows 9x and NT systems. In Windows 9x, it copies itself to the Windows folder as "INETD.EXE" and modify the WIN.INI to load at next Windows startup. In Windows NT, the worm creates a key in the registry:

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] "run"="Inetd"

Strings within the EXE suggest it was coded by a member of the virus group 29A.

Symptoms

Existence of file INETD.EXE as mentioned above, recipients of autoreplied email notifying you of unsolicited attachment.

Method of Infection

Running attached executable will install itself as mentioned above.

Removal

All Users :
Script,Batch,Macro and non memory-resident:
Use current engine and DAT files for detection and removal.

PE,Trojan,Internet Worm and memory resident :
Use specified engine and DAT files for detection. To remove, boot to MS-DOS mode or use a boot diskette and use the command line scanner:

SCANPM /ADL /CLEAN /ALL

Additional Windows ME/XP removal considerations


Users should not trust file icons, particularly when receiving files from others via P2P clients, IRC, email or other mediums where users can share files.

AVERT Recommended Updates :

* Office2000 Updates

* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch )

* scriptlet.typelib/Eyedog vulnerability patch

* Outlook as an email attachment security update

* Exchange 5.5 post SP3 Information Store Patch 5.5.2652.42 - this patch corrects detection issues with GroupShield

For a list of attachments blocked by the Outlook patch and a general FAQ, visit this link .
Additionally, Network Administrators can configure this update using an available tool - visit this link for more information .

It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Aliases

  • I-Worm.P2000
  • Plage2000
  • W95/Plage.worm

Characteristics

Characteristics -

This is an Internet worm which can autoreply to unread email messages of MAPI installed email clients. The autoreply message contains a brief note along with an attachment of random EXE names. The email message will be replied to in Unix-style format such as the example below:



Sent: Thursday, January 13, 2000 12:08 PM
To: SMTP:sender@domain.com
Subject: Re: original subject line

'Lastname, Firstname' wrote:
====
-
-
-
====

P2000 Mail auto-reply:
' I'll try to reply as soon as possible.
Take a look to the attachment and send me your opinion! '

> Get your FREE P2000 Mail now! <


The attachment is any of the following names:
billgt.exe
card.exe
docs.exe
fun.exe
hamster.exe
humor.exe
images.exe
joke.exe
midsong.exe
news_doc.exe
pics.exe
PsPGame.exe
searchURL.exe
SETUP.EXE
s3msong.exe
tamagotxi.exe

The size of the file is 102,400 bytes and has an icon similar to PKLite self extracting, very similar to W32/ExploreZip.worm. There is one noticeable difference however in that this worm was not witnessed to have removed files from the system.

When the attachment is executed, it will give a phony error message and then install itself on Windows 9x and NT systems. In Windows 9x, it copies itself to the Windows folder as "INETD.EXE" and modify the WIN.INI to load at next Windows startup. In Windows NT, the worm creates a key in the registry:

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] "run"="Inetd"

Strings within the EXE suggest it was coded by a member of the virus group 29A.

Symptoms

Symptoms -

Existence of file INETD.EXE as mentioned above, recipients of autoreplied email notifying you of unsolicited attachment.

Method of Infection

Method of Infection -

Running attached executable will install itself as mentioned above.

Removal -

Removal -

All Users :
Script,Batch,Macro and non memory-resident:
Use current engine and DAT files for detection and removal.

PE,Trojan,Internet Worm and memory resident :
Use specified engine and DAT files for detection. To remove, boot to MS-DOS mode or use a boot diskette and use the command line scanner:

SCANPM /ADL /CLEAN /ALL

Additional Windows ME/XP removal considerations


Users should not trust file icons, particularly when receiving files from others via P2P clients, IRC, email or other mediums where users can share files.

AVERT Recommended Updates :

* Office2000 Updates

* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch )

* scriptlet.typelib/Eyedog vulnerability patch

* Outlook as an email attachment security update

* Exchange 5.5 post SP3 Information Store Patch 5.5.2652.42 - this patch corrects detection issues with GroupShield

For a list of attachments blocked by the Outlook patch and a general FAQ, visit this link .
Additionally, Network Administrators can configure this update using an available tool - visit this link for more information .

It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.

Variants

Variants -

    N/A