Alias:
Type:Worm 
Size:47.616 Bytes 
Origin: 
Date:07-16-2002 
Damage:Spreads by email. 
VDF Version:6.23.00.00 
Danger:Low 
Distribution:Low 

DistributionWorm/Frethem.J uses its own SMTP engine to spread to all email addresses it can find in Windows Address Book or in files of type
.dbx .wab .mbx .mdb .eml
The email sent by the virus looks like below:

Subject: Re:Your password!

Body: ATTENTION! You cann access very important information by this password DO NOT SAVE password to disk use your mind now press cancel

Attachment:
Decrypt-password.exe
Passwort.txt

Technical DetailsWorm/Frethem.J is a PE and UPX packed file of 47.616 Bytes. It spreads using its own SMTP engine.
When the attachment Decrypt-password.exe is opened, the worm is copied in Windows directory as Taskbar.exe and enters the following registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVerion\Run\Task Bar=C:\Windows\Taskbar.exe


For email spreading, Worm/Frethem.l uses the SMTP data of the local user, which it can get with the following entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001\SMTP Display Name HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001\SMTP Email Adress
Description insérée par Crony Walker le mardi 15 juin 2004

Retour . . . .