Нужен совет? Обратитесь за помощью к сообществу или специалистам.
Перейти к Avira Answers
Alias:Happy99, I-Worm.Happy, W32/Ska.dll, W32/Ska.dll@m, W32/Ska@M
Type:Worm 
Size: 
Origin: 
Date:00-00-0000 
Damage:Sent by email. 
VDF Version:  
Danger:Low 
Distribution:Low 

DistributionThe email sent by the worm has the attachment:Happy99.EXE.

Technical DetailsWhen activated, Worm/Happy displays the message "Happy New Year 1999!!" and fireworks on the screen.

It can spread through email attachments or using its own SMTP engine for sending emails. Such an email is followed by a second one, with the attachment:

>X-Spanska: Yes
>
>begin 644 Happy99.exe
>M35I0`
`(````$``\`__\``+@`````````0``:````````````````````````
>M``````````````````````$``+H0``X?M`G-(;@!3,TAD)!4:&ES('!R;V= R

When the attachment HAPPY99.EXE is opened, the worm is copied in %WinDIR%\%SystemDIR% as SKA.EXE.

Then, it checks if WSOCK32.SKA exists in %WinDIR%\%SystemDIR%. If it doesn't, but there is an WSOCK32.DLL file, the worm copies the file WSOCK32.DLL into WSOCK32.SKA.

The worm makes the registry autostart entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Ska.exe = Ska.exe
Описание добавил Crony Walker в(о) вторник, 15 июня 2004 г.

Назад . . . .
https:// Это окно зашифровано для вашей безопасности.