x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

Frethem.F

 
Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Frethem.F
Technical name:W32/Frethem.F
Threat level:Low
Alias:WORM_FRETHEM.F
Type:Worm
Effects:  It has no destructive effects.

Detection updated on:June 12, 2002
StatisticsNo
Proactive protection:
Yes, using TruPrevent Technologies

Brief Description 

    

Frethem.F is a worm that spreads via e-mail in a message with the subject Re: Your password!.

Both the subject and the content of the message try to trick recipients into running the attachment by making them believe that it contains a password.

However, when the file is run, Frethem.F carries out the actions necessary to send itself via e-mail through an SMTP connection.

Frethem.F is not considered dangerous, as the only action it carries out is to send itself out via e-mail. However, mass mailing of this worm could collapse mail accounts.

Visible Symptoms 

    

A clear indication that you have received Frethem.F is an e-mail message with the following characteristics:

  • Subject:
    Re: Your password!

    Message:
    ATTENTION!

    You can access
    very important
    information by
    this password

    DO NOT SAVE
    password to disk
    use your mind

    now press
    cancel
  • Attachments: it can be one of the following:
    DECRYPT-PASSWORD.EXE
    PASSWORD.TXT