-
Discovered:
- August 29, 2002
-
Updated:
- February 13, 2007 11:52:24 AM
-
Also Known As:
- I-Worm.Melhack [AVP], VBS/VBSWG.at [McAfee], VBS/Kamil.B.Worm [CA]
-
Type:
- Worm
-
Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
VBS.Melhack@mm is a Visual Basic script worm that spreads by emailing itself to all the contacts in the Windows Address Book. It also does the following:
- It creates registry values and keys that (among other things) cause the worm to run when you start Windows.
- It visits a Web site and then downloads and runs the W32.Kamil Trojan.
- It modifies the mIRC script file to send itself over IRC.
- It creates several folders and files on the host computer.
- It overwrites files on the computer with a copy of one of its components.
NOTE: Definitions dated prior to August 30, 2002 detect this as Bloodhound.VBS.4.
Antivirus Protection Dates
-
Initial Rapid Release version August 30, 2002
-
Latest Rapid Release version September 28, 2010 revision 054
-
Initial Daily Certified version August 30, 2002
-
Latest Daily Certified version September 28, 2010 revision 036
-
Initial Weekly Certified release date September 4, 2002
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Moderate
Writeup By: Atli Gudmundsson