W32.Frethem.A@mm

Risk Level 2: Low

Download Removal Tool | Printer Friendly Page

Discovered: June 3, 2002
Updated: February 13, 2007 11:39:08 AM
Also Known As: WORM_FRETHEM.A [Trend]
Type: Worm



W32.Frethem.A@mm is an Internet worm which uses its own SMTP engine to spread. It obtains email addresses from the Microsoft Windows Address Book and from .dbx files. It retrieves the infected computer user's SMTP server information from the registry. It then sends itself to all the email addresses that it finds in a message with the following characteristics:
Subject: Re: Do your Windows looks like Windows XP? I have found very nice desktop themes!
Attachment: www.freedesktopthemes[plus a random number].[a random extension chosen from com, .exe, .bat, or .cmd]

The size of worm is about 31 KB. It is packed with both PE-Pack and UPX.


Protection

  • Initial Rapid Release version June 4, 2002
  • Latest Rapid Release version June 4, 2002
  • Initial Daily Certified version June 4, 2002
  • Latest Daily Certified version June 4, 2002
  • Initial Weekly Certified release date June 5, 2002

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: High

Writeup By: Yana Liu
Search by name
Example: W32.Beagle.AG@mm
File Your Taxes Worry-Free
ThreatCon Widget