FriendMess

Threat description

Details

Category: Malware
Type: Worm
Platform: VBS

Summary

VBS/FriendlyMess is a worm similar to VBS/LoveLetter. More information about VBS/LoveLetter is available at https://www.F-Secure.com/v-descs/love.shtml



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details


Variant:FriendMess.A

The e-mail message that this worm sends looks like this:

  Subject:    FRIEND MESSAGE     Body:       A real friend send this message to you.     Attachment: FRIEND_MESSAGE.TXT.vbs  

If the user executes the attachment, the worm copies itself to the Windows System directory as "FRIEND_MESSAGE.TXT.vbs".

After that, it overwrites autoexec.bat so that the next time the machine is rebooted it will try to delete all files from the Windows directory, from the Windows System directory and from the Temporary directory. This payload will not work in NT.

Then it shows a message box with the following text:

  If you receive this message remember forever: A precious friend in     all the world like only you! So think that!  

Then the worm starts Outlook application in order to send itself via e-mail to all addresses in all address books. The worm adds a marker in the registry for each address so that the e-mail message is sent only once to each recipient.





Technical Details: Katrin Tocheva and Sami Rautiainen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More