Category :


Type :


Aliases :

Hard, HardHead, VBS/Hard.A@MM


Hard is a Visual Basic Script mass mailer (worm) that tries to disguise a virus warning.


Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details


Hard.A worm spreads to all resipients listed in Outlook Express address book. It arrives in a message that looks as follows:

----- Original Message -----
 Subject: FW: Symantec Anti-Virus Warning
 There is a new worm on the Net.
 This worm is very fast-spreading and very dangerous!
 Symantec has first noticed it on April 04, 2001.
 The attached file is a description of the worm and how it
 replicates itself.
 With regards,
 F. Jones
 Symantec senior developer

Hard.A contaians a payload that activates on November 24. Then the worm shows a message box with the following title and text:

	Some shocking news 	Don't look surprised! 	It is only a warning about your stupidity
	Take care!