Home > Threat descriptions >

Happytime

Classification

Category: Malware

Type: Worm

Aliases: Happytime, VBS/Help, VBS/Haptime@MM

Summary


VBS/Happytime is a VBS worm that propagates in two different ways - as a slow worm similar to JS/Kak, and as a fast worm - mass mailer.

Removal


Automatic action

Based on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the detected program or file, or ask you for a desired action.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details



Variant:Happytime.A

Happytime first drops following files that contain the virus code:

help.hta

 help.htm

 help.vbs

Then it executes its payload, that activates if the sum of the day and the month is 13. At this time it deletes all files with extension ".dll" or ".exe".

Happytime.A uses a counter, and when it reaches number 366, then the worm sends itself replying to all messages listed in Outlook Inbox with a following message:

  Subject:    Fw:      Attachment: Untitled.htm  

or

Subject:

Fw:Attachment: Untitled.htm

where "Untitled.htm" is another file where the virus saves its code.

Next the worm replaces the current wallpaper with "Help.htm" via registry.

Happytime.A then prepares the system to send itself as a slow worm using Outlook Express 5.0. To do this, it creates a stationary that contains the worm code.

Finally the worm infects all files with ".htt" extension in the "\WEB" directory located in the Windows installation directory. Therefore the worm is executed each time when a folder viewed as a web page.

On the top of its code, the worm contains the following commented line:

Subject:

Fw:Attachment: Untitled.htm