Welcome to the Virus Encyclopedia of Panda Security.
|Effects: ||It displays some messages on screen.
|First detected on:||April 14, 2003|
|Detection updated on:||April 14, 2003|
Refoav is a worm without destructive payload. It is easy to identify as it always reaches computers in an infected e-mail message with the following attachment: FOAVRE.EXE.
When the infection has been carried out, Refoav displays some messages. Then, it sends itself out to all the contacts in Outlook’s Address Book and to other addresses it finds on the affected computer. Finally, it deletes itself from the computer.
Refoav is easy to identify, as it always reaches computers in an infected e-mail message with the following attachment: FOAVRE.EXE.
When the infection has been carried out, it consecutively displays the following messages on screen, as the user clicks on the Aceptar button (in Spanish):