x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Frethem.R

Threat LevelLow threatDamageHighDistributionNot widespread
Common name:Frethem.R
Technical name:W32/Frethem.R
Threat level:Medium
Type:Worm
Subtype: Trojan
Effects:  

It has no destructive effects and it spreads via email.

Detection updated on:July 26, 2002
StatisticsNo

Brief Description 

    

Frethem.R is a worm that has no destructive effects. It just spreads via email in a message with the attached files DECRYPT-PASSWORD.EXE and PASSWORD.TXT.

It is automatically activated when the email message is viewed through Outlook's Preview Pane. It does this by exploiting a vulnerability in Internet Explorer, which allows email attachments to be automatically run. This vulnerability exploit is known as Exploit/iFrame.

 

It is highly recommendable to download and install the latest cumulative security update for Internet Explorer from Microsoft's official website. Access the page referring security bulletins.

Visible Symptoms 

    

Frethem.R is easy to recognize, as it reaches the computer via email in a message with the following characteristics:

  • Subject:
    Re: Your password!
  • Message:
    ATTENTION!
    You can access
    very important
    information by
    this password
    DO NOT SAVE
    password to disk
    use your mind
    now press
    cancel
  • Attachments:
    DECRYPT-PASSWORD.EXE and PASSWORD.TXT.