Home > Threat descriptions >

FriendMess

Classification

Category: Malware

Type: Worm

Aliases: FriendMess

Summary


VBS/FriendlyMess is a worm similar to VBS/LoveLetter. More information about VBS/LoveLetter is available at https://www.F-Secure.com/v-descs/love.shtml

Removal


Automatic action

Based on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the detected program or file, or ask you for a desired action.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details



Variant:FriendMess.A

The email message that this worm sends looks like this:

Subject:

FRIEND MESSAGE

 Body: A real friend send this message to you.

 Attachment: FRIEND_MESSAGE.TXT.vbs

If the user executes the attachment, the worm copies itself to the Windows System directory as "FRIEND_MESSAGE.TXT.vbs".

After that, it overwrites autoexec.bat so that the next time the machine is rebooted it will try to delete all files from the Windows directory, from the Windows System directory and from the Temporary directory. This payload will not work in NT.

Then it shows a message box with the following text:

If you receive this message remember forever: A precious friend in

 all the world like only you! So think that!

Then the worm starts Outlook application in order to send itself via email to all addresses in all address books. The worm adds a marker in the registry for each address so that the email message is sent only once to each recipient.