Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


FriendMess


Aliases:


FriendMess

Malware
Worm
VBS

Summary

VBS/FriendlyMess is a worm similar to VBS/LoveLetter. More information about VBS/LoveLetter is available at http://www.F-Secure.com/v-descs/love.shtml



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details


Variant:FriendMess.A

The e-mail message that this worm sends looks like this:

  Subject:    FRIEND MESSAGE
    Body:       A real friend send this message to you.
    Attachment: FRIEND_MESSAGE.TXT.vbs

If the user executes the attachment, the worm copies itself to the Windows System directory as "FRIEND_MESSAGE.TXT.vbs".

After that, it overwrites autoexec.bat so that the next time the machine is rebooted it will try to delete all files from the Windows directory, from the Windows System directory and from the Temporary directory. This payload will not work in NT.

Then it shows a message box with the following text:

  If you receive this message remember forever: A precious friend in
    all the world like only you! So think that!

Then the worm starts Outlook application in order to send itself via e-mail to all addresses in all address books. The worm adds a marker in the registry for each address so that the e-mail message is sent only once to each recipient.





Technical Details: Katrin Tocheva and Sami Rautiainen, F-Secure



Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.

Scan and clean your PC




F-Secure Online Scanner will scan and clean your PC in just a few minutes for free