1. Symantec/
  2. Security Response/
  3. VBS.Melhack@mm


Risk Level 2: Low

August 29, 2002
February 13, 2007 11:52:24 AM
Also Known As:
I-Worm.Melhack [AVP], VBS/VBSWG.at [McAfee], VBS/Kamil.B.Worm [CA]
Systems Affected:

VBS.Melhack@mm is a Visual Basic script worm that spreads by emailing itself to all the contacts in the Windows Address Book. It also does the following:
  • It creates registry values and keys that (among other things) cause the worm to run when you start Windows.
  • It visits a Web site and then downloads and runs the W32.Kamil Trojan.
  • It modifies the mIRC script file to send itself over IRC.
  • It creates several folders and files on the host computer.
  • It overwrites files on the computer with a copy of one of its components.

NOTE: Definitions dated prior to August 30, 2002 detect this as Bloodhound.VBS.4.

Antivirus Protection Dates

  • Initial Rapid Release version August 30, 2002
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version August 30, 2002
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date September 4, 2002
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Atli Gudmundsson

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube