This is a trojan. DON'T EXECUTE IT.

Some more information follows.
This info is not from me, I didn't test what it suggests. In fact I don't even
know exactly who it is from. Anyway: it seems useful.

Ska Virus
Information

This virus is attached to newsgroup and e-mail messages as an
attachment called Happy99.exe. You cannot get infected with this virus
just by reading a newsgroup or e-mail message. If you execute an
infected attachment, it will display a firework display. This display
will look like this:

It will create two files in the Windows System folder, SKA.EXE and
SKA.DLL. SKA.EXE will be a copy of HAPPY99.EXE. It will make a backup
of WSOCK32.DLL under the name of WSOCK32.SKA. If it is unable to
modify WSOCK32.DLL, then it will add SKA.EXE to the RunOnce section of
the registry and WSOCK32.DLL will be modified next time the computer
starts. The modified WSOCK32.DLL will attach HAPPY99.EXE to a second
copy of outgoing newsgroup and e-mail messages. In my tests(sending an
e-mail to myself:) this virus attached itself to a second copy of the
e-mail message, with no problems and a barely
noticeable delay. This virus will keep a list of message recipients in
the file LISTE.SKA in the Windows System folder.

Some people have asked whether it is always called HAPPY99.EXE. This
virus doesn't contain any code to change the name. However, it would
be simple for a person to change it to anything they like.

It contains the text:

"Is it a virus, a worm, a trojan? MOUT-MOUT Hybrid (c) Spanska 1999."
Removal

Click Start, then Shut Down, then "Restart Computer in MS-DOS mode"
At the DOS prompt type:
CD \WINDOWS\SYSTEM
Delete SKA.EXE, SKA.DLL, and WSOCK32.DLL by typing
DEL SKA.EXE
DEL SKA.DLL
DEL WSOCK32.DLL
Rename WSOCK32.SKA to WSOCK32.DLL by typing
REN WSOCK32.SKA WSOCK32.DLL
Return to Windows by typing
EXIT

Optional Click Start, then Run, then type regedit in the text box,
then click OK. Click HKEY_LOCAL_MACHINE, then Software, then
Microsoft, then Windows, then CurrentVersion. Under RunOnce check for
SKA.EXE and select it if it is there. Press delete and then click Yes.
Close Regedit.  Optional Start Notepad and open the file LISTE.SKA.
Warn the people on the list, then delete LISTE.SKA



Mark Minnoye wrote:

>                   Name: Happy99.exe
>    Happy99.exe    Type: unspecified type (application/octet-stream)
>               Encoding: x-uuencode
>
> ___________________________________________________________________________
> To unsubscribe, send email to [EMAIL PROTECTED] and include in the body
> of the message "signoff SERVLET-INTEREST".
>
> Archives: http://archives.java.sun.com/archives/servlet-interest.html
> Resources: http://java.sun.com/products/servlet/external-resources.html
> LISTSERV Help: http://www.lsoft.com/manuals/user/user.html

--
- - - - - - - - - - - - - - - - - - - - - - - -
 The WebApp Framework ~ http://www.webapp.de/

___________________________________________________________________________
To unsubscribe, send email to [EMAIL PROTECTED] and include in the body
of the message "signoff SERVLET-INTEREST".

Archives: http://archives.java.sun.com/archives/servlet-interest.html
Resources: http://java.sun.com/products/servlet/external-resources.html
LISTSERV Help: http://www.lsoft.com/manuals/user/user.html

Reply via email to