Associated Malware Groups
The filename is associated with the malware groups:
File Behavior
MEGLHE.EXE has been seen to perform the following behavior:
- Found on infected systems and resists interrogation by security products
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Creates a TCP port which listens and is available for communication initiated by other computers
- Executes a Process
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- Registers a Dynamic Link Library File
- This Process Deletes Other Processes From Disk
- Creates a new Background Service on the machine
- Injects code into other processes
- Creates new folders on the system
- This process creates other processes on disk
- Can communicate with other computer systems using HTTP protocols
- Adds products to the system registry
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
- Copies files
- Modifies firewall settings, without user permission so it is not blocked from accessing the Internet
MEGLHE.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Copied to multiple locations on the system
Country Of Origin
The filename MEGLHE.EXE was first seen on Dec 6 2009 in the following geographical regions of the Prevx community:
- Turkey on Dec 6 2009
- Saudi Arabia on Dec 7 2009
- Belgium on Dec 7 2009
- Peru on Dec 8 2009
- Italy on Dec 8 2009
- Slovenia on Dec 16 2009
- The United Kingdom on Dec 16 2009
- Morocco on Dec 30 2009
- Ireland on Dec 30 2009
File Name Aliases
MEGLHE.EXE can also use the following file names:
- IOUVVFGCD[1].HTM
- NGJSET.EXE
- NOV.EXE
- WIQYBOM.EXE
- UHJB.EXE
- UUFMDKB.EXE
- NBHPUP.EXE
- EOPSL.EXE
- ENTSPPRPEV.EXE
- SVCHOST.EXE
- LFYKUU.EXE
- PLXQW.EXE
- TMCERFSG[1].HTM
- WIND7UPD.EXE
- 70188303.EXE
Filesizes
The following file size has been seen:
- 107,008 bytes
- 20,992 bytes
- 99,328 bytes
- 39,936 bytes
- 203,264 bytes
- 23,552 bytes
File Type
The filename MEGLHE.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.