Skip to main content

New Versions of The Worm "Frethem" Are Loose On The Internet!

17 July 2002

Kaspersky Labs warns all computer users of a large number of registered infections from new modifications to the "Frethem" Internet-worm (modifications K and L). For penetration "Frethem" exploits a 1 1/2-year-old vulnerability in the Internet Explorer security system (the...

Kaspersky Lab warns all computer users of a large number of registered infections from new modifications to the "Frethem" Internet-worm (modifications K and L). For penetration "Frethem" exploits a 1 1/2-year-old vulnerability in the Internet Explorer security system (the IFRAME-vulnerability). Due to this vulnerability a system becomes infected at the moment the infected e-mail is read. The message has the following characteristics:
Subject: Re: Your password! Text: ATTENTION! You can access very important information by this password DO NOT SAVE password to disk use your mind now press cancel Attached files: decrypt-password.exe, password.txt
After an infected file is launched the worm registers itself in the Windows system registry's start-up directory and scans the system for files of the WAB (Windows Address Book) and DBX formats and sends out its copies to e-mail addresses found there. In addition "Frethem" installs on infected machines a utility allowing hidden remote administration, giving an intruder the chance to manage a users system and install new versions of the "Frethem" worm family. The procedure defending against this malicious program has already been added to the Kaspersky Anti-Virus database. More detailed information about the "Frethem" family of Internet-worms can be found in the Kaspersky Virus Encyclopedia. Kaspersky Lab strongly recommends users install the Internet Explorer patch that eliminates the browser's security system vulnerability. This will allow users to protect their computers against not only current threats but future worms as well, which target the IFRAME-vulnerability. You can download the free-of-charge patch (included in the service pack) here.

New Versions of The Worm "Frethem" Are Loose On The Internet!

Kaspersky Labs warns all computer users of a large number of registered infections from new modifications to the "Frethem" Internet-worm (modifications K and L). For penetration "Frethem" exploits a 1 1/2-year-old vulnerability in the Internet Explorer security system (the...
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases