Pages in the Historical section of this site are provided for historical purposes, they are no longer maintained. Links may not work.

The CERT Coordination Center publishes incident notes to provide information about incidents to the Internet community.

Happy99.exe Trojan Horse

Monday, March 29, 1999

Overview

Around January 20, 1999, we began receiving reports of a Trojan horse program named Happy99.exe. Anti-virus vendors have given this program the following names: SKA, WSOCK32.SKA, SKA.EXE, I-Worm.Happy, PE_SKA, Trojan.Happy99, Win32/SKA, and Happy99.Worm.

Description

The first time Happy99.exe is executed, a fireworks display saying "Happy 99" appears on the computer screen and, at the same time, modifies system files. The executable affects Microsoft Windows 95/98 and NT machines by

  • copying the WSOCK32.DLL file to WSOCK32.SKA
  • modifying the WSOCK32.DLL file, which is used for Internet connectivity
  • creating files called SKA.EXE and SKA.DLL in the system directory
  • creating an entry in the registry to start SKA.EXE

Once Happy99 is installed, every email and Usenet posting sent by an affected user triggers Happy99 to send a followup message containing Happy99.exe as a uuencoded attachment. Happy99 keeps track of who received the Trojan horse message in a file called LISTE.SKA in the system folder. Note that messages containing the Trojan horse will generally appear to come from someone you know.

Solutions

You can prevent the spread of the Happy99 by setting the WSOCK32.DLL file attributes to "read only".

Most virus scanning tools will detect and clean Happy99 from a system. Happy99 can be manually removed from affected systems. You can find the steps for this procedure at the following site:

http://www.symantec.com/avcenter/venc/data/happy99.worm.html

To detect and remove current viruses, you must update your scanning tools with the latest virus signatures or definitions. We also recommend you contact all of the people listed in the LISTE.SKA file. This file lists of other people that may have received the Happy99 Trojan horse from you.

It is important to take great caution with any email or Usenet attachments that contain executable content. If attachments are in a message, we recommend that you save the file to the local drive and scan the file with a virus scanning product before you open or run the file. Be aware that this is not a guarantee that the contents of the file are safe, but it will check for viruses and Trojan horses that your scanning software can detect.

Not the Same as Melissa

Happy99 is not a macro virus and should not be confused with the Melissa Word macro virus. Further information about the Melissa Word macro virus can be found at the following site:

http://www.cert.org/advisories/CA-99-04-Melissa-Macro-Virus.html

Happy99 vs. Melissa Word Macro Virus
Happy 99 Melissa
How does it propagate? email or Usenet attachment email or Usenet attachment
Where does it reside? Modified WSOCK32.DLL Macro in Microsoft Word documents
Who is it sent to? The recipients of the last message you sent out that are not in the LISTE.SKA file First 50 entries in each address book

Copyright 1999 Carnegie Mellon University.

  • No labels