1. /
  2. Security Response/
  3. VBS.Melhack@mm

VBS.Melhack@mm

Risk Level 2: Low

Discovered:
August 29, 2002
Updated:
February 13, 2007 11:52:24 AM
Also Known As:
I-Worm.Melhack [AVP], VBS/VBSWG.at [McAfee], VBS/Kamil.B.Worm [CA]
Type:
Worm
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


VBS.Melhack@mm is a Visual Basic script worm that spreads by emailing itself to all the contacts in the Windows Address Book. It also does the following:
  • It creates registry values and keys that (among other things) cause the worm to run when you start Windows.
  • It visits a Web site and then downloads and runs the W32.Kamil Trojan.
  • It modifies the mIRC script file to send itself over IRC.
  • It creates several folders and files on the host computer.
  • It overwrites files on the computer with a copy of one of its components.





NOTE: Definitions dated prior to August 30, 2002 detect this as Bloodhound.VBS.4.

Antivirus Protection Dates

  • Initial Rapid Release version August 30, 2002
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version August 30, 2002
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date September 4, 2002
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium

Distribution

  • Distribution Level: High
Writeup By: Atli Gudmundsson

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver