Summary
Frethem.K is a new variant of Frethem worm that appeared in the
middle of July 2002. This worm variant is close to Frethem.E
variant, but it has some additional features. The worm's file is
packed with PE-Pack and UPX file compressors and is about 47
kilobytes long.
The worm sends itself from an infected computer as with the
following message:
Subject:
Re: Your password!
Body:
ATTENTION!
You can access
very important
information by
this password
DO NOT SAVE
password to disk
use your mind
now press
cancel
(<infected user name>)
Attachment:
decrypt-password.exe
password.txt
The executable attachment contains the worm's body. The
'password.txt' attachment contains the following text:
Your password is W8dqwq8q918213
The worm installs itself to system as TASKBAR.EXE and creates a
startup key in System Registry to make this file start every time
a user logs on. Also the worm copies itself as SETUP.EXE to
\Start Menu\Programs\Startup\ folder.
To remove the worm from a system, all its files should be
deleted. Also it is recommended to delete all infected messages
from e-mail databases and to apply the latest security patches to
Microsoft e-mail browsers.
Detection of Frethem.K worm in F-Secure Anti-Virus was published
on July 15th, 2002:
[FSAV_Database_Version]
Version=2002-07-15_03
| VARIANT: | Frethem.L | I-Worm.Frethem.L |