Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please follow the instructions for removing W32/Frethem-P.
More Information
W32/Frethem-P is a member of the Frethem family but does not contain the email properties common amongst most of the family's variants.
W32/Frethem-P sends HTTP requests to a CGI script located at various remote locations. But at the time of writing those CGI scripts are no longer available hence this does not pose a threat.
W32/Frethem-P is intended to interpret the contents of the requested files as instructions which would likely be used to give the worm certain backdoor features.
W32/Frethem-P will not carry out any actions if the values "0843" and "0419" are found in the following registry entrys :
HKCU\Keyboard layout\preload\1
HKCU\Keyboard layout\preload\2
HKCU\Keyboard layout\preload\3
