Home Malware Programs Worms WORM_MEYLME.B

WORM_MEYLME.B

Posted: September 13, 2010

WORM_MEYLME.B is a dangerous computer worm which enters a targeted system via removable drives. WORM_MEYLME.B may also be downloaded when visiting certain malicious websites.
WORM_MEYLME.B deletes files and as a result, programs and applications may not run properly. WORM_MEYLME.B will also delete registry keys. WORM_MEYLME.B uses Messaging Application Protocol Interface (MAPI) to send email messages with a copy of itself as an attachment. The worm then drops copies of itself in all removable drives to propagate via removable drives. It also drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed and then drops a copy of itself in network shares. Remove WORM_MEYLME.B before it wreaks all sorts of havoc on your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\SendEmail.dll
    2 %Windows%\ff.exe
    3 %Windows%\gc.exe
    4 %Windows%\ie.exe
    5 %Windows%\im.exe
    6 %Windows%\op.exe
    7 %Windows%\pspv.exe
    8 %Windows%\rd.exe
    9 %Windows%\re.exe
    10 %Windows%\tryme1.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HKEY..\..\..\..{RegistryKeys}HideSCAHealth = "1"Windows\CurrentVersion\policies\ExplorerWindows\CurrentVersion\policies\system
Loading...