FRISK Software International


Summary of VBS/Haptime
Alias:VBS/Help, Happytime
Discovered: 29 Apr 2001
Definition files: 29 Apr 2001
 
Jump to:
Brief description
Technical description

Brief Description
VBS/Happytime is a VBS worm that propagates in two different ways - as a slow worm similar to JS/Kak, and as a fast worm - mass mailer.


Technical Description
VARIANT: Happytime.A

Happytime first drops following files that contain the virus code:

    help.hta
    help.htm
    help.vbs
Then it executes its payload, that activates if the sum of the day and the month is 13. At this time it deletes all files with extension ".dll" or ".exe".

Happytime.A uses a counter, and when it reaches number 366, then the worm sends itself replying to all messages listed in Outlook Inbox with a following message:

    Subject:    Fw: 
    Attachment: Untitled.htm
or

    Subject:     Help
    Attachment: Untitled.htm
where "Untitled.htm" is another file where the virus saves its code.

Next the worm replaces the current wallpaper with "Help.htm" via registry.

Happytime.A then prepares the system to send itself as a slow worm using Outlook Express 5.0. To do this, it creates a stationary that contains the worm code.

Finally the worm infects all files with ".htt" extension in the "\WEB" directory located in the Windows installation directory. Therefore the worm is executed each time when a folder viewed as a web page.

On the top of its code, the worm contains the following commented line:

    I am sorry! happy time


[Analysis: Katrin Tocheva and Sami Rautiainen, F-Secure; May 2001]
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is