Techno-News Blog Ray Schroeder, editor, OTEL - University of Illinois at Springfield

Link to Web Counter at www.digits.com

Bobby Approved (v 3.2)
Wednesday, July 17, 2002

http://www.f-secure.com/v-descs/frethem.shtml

Frethem - THIS VIRUS IS RANKED AS LEVEL 2 ALERT UNDER F-SECURE RADAR.

There are 12 different variants of Frethem worm known so far (A-L). The K and L variants of the worm became widespread in the middle of July 2002.... Frethem is a mass-mailer worm that started to spread on June 11th. The worm arrives in an e-mail as an attachment. When the attachment is opened it copies itself to the user's Startup folder as 'setup.exe'. After the installation it collects e-mail addresses from the Windows Address Book and files with '*.DBX' extensions. It uses it's own SMTP engine to send infected messages. All the information needes to send e-mail is collected from the registry. The worm uses the user's account data that includes the SMTP server name, e-mail address, etc. This way the infected message will look like it was sent by the user....

 


Comments: Post a Comment

Fair Use