Virus Profile: W32/Frethem.m@MM

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Low-Profiled | Corporate Low-Profiled
Date Discovered: 7/15/2002
Date Added: 7/16/2002
Origin: Unknown
Length: 48,128 bytes
Type: Virus
Subtype: E-mail worm
DAT Required: 4208
Removal Instructions
   
 
 
   

Description

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Indication of Infection

  • Presence of the file %WinDir%\Taskbar.exe
  • Presence of the file %WinDir%\Winstat.ini

Methods of Infection

This worm exploits an Internet Explorer vulnerability to automatically run on unpatched systems. Once run, the worm sends itself to email addresses found on the local system.

Aliases

I-Worm.Frethem.n (AVP) , W32.Frethem.M@mm (Symantec), WORM_FRETHEM.M (TrendMicro)
   

Virus Characteristics

This W32/Frethem variant is considered a Low-Profiled threat due to the fact that it has low prevalence, and one of the variants in the W32/Frethem family reached Medium risk assessment status. This W32/Frethem variant is detected as W32/Frethem.gen@MM with the 4208 - 4211 DATs and current scan engine (when the scan compressed files option is enabled), and W32/Frethem.m@MM with the 4212+ DATs and 4.0.70+ scan engine.

This mass-mailing worm gathers email addresses from Microsoft Outlook Express mailbox files (.DBX files), the Windows Address Book (.WAB file), .MBX, .EML, and .MDB files to send itself via SMTP using the following information:

Subject: Re: Your password!
Body: ATTENTION!

You can access
very important
information by
this password

DO NOT SAVE
password to disk
use your mind

now press
cancel

Attachments:
  • Decrypt-password.exe
  • Password.txt

    The worm exploits the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability in Microsoft Internet Explorer (ver 5.01 or 5.5 without SP2), to automatically execute the virus on vulnerable systems. The exe file copies itself to the %WinDir% directory and creates the following registry run keys so that it runs each time Windows is loaded.

    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
      Run\Task Bar=C:\Windows\Taskbar.exe
    The default SMTP Server, SMTP Email Address, and SMTP Display Name are gathered from the Internet Account Manager:
    • HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\
      Accounts\00000001
    This information is used by the worm to carry out its propagation routine.

    The worm hooks Internet Explorer to send requests to various websites.

    The PASSWORD.TXT file the virus sends simply contains the text:
    • Your password is W8dqwq8q918213
  •    
    All Windows Users:
    Use current engine and DAT files for detection and removal.

    Manual Removal Instructions

    • Restart the computer in safe mode
    • Delete the following files
      • %WinDir%\Taskbar.exe
      • %WinDir%\Winstat.ini
    • Delete the registry key values
      • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
        Run\Task Bar
      • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
        Run\Task Bar

    Additional Windows ME/XP removal considerations