Find a Partner
This window is encrypted for your security.
Need help? Ask the community or hire an expert.
Go to Avira Answers
Sent by email.
An email sent by the worm looks like this:
The attachment UNTITLED.HTM contains the wormcode.
HappyTime is a VBS worm, with two damage routines: it deletes all .DLL and.EXE files in Windows directory and sends its wormcode via Outlook or Outlook Express.
When an infected file is opened, the worm copies itself in
and creates the following files in Windows directory, containing the wormcode:
Then in the registry directory
the worm makes the following registry entry: Stationery Name = C:\\WINDOWS\\Untitled.htm
Then, the worm checks if the sum of the day and month is 13. If so, HappyTime deletes all .exe and .dll files from Windows directory (including subfolders).
The worm HappyTime keeps an Internet counter. When the counter reaches 366, the worm sends itself to all email addresses found in Outlook/ Outlook Express Inbox or folder.
Description inserted by Crony Walker on Tuesday, June 15, 2004