Happy Days.exe: Difference between revisions

No edit summary
No edit summary
Line 1: Line 1:
<tabber>Main=
{{DISPLAYTITLE:Happy_Days_.exe}}
[[File:Happydays.png|thumb|131x131px|The application icon]]
 
Happy_Days_.exe is a korean screamer application. It is very similar to the other Win32/Flaghost malware however the screamer picture that it shows is slightly altered. Once executed, a black popup box is shown every 5 seconds that contains the screamer picture and a blue colored text saying "^^ Happy days... please 5 seconds... to close"
<nowiki><tabber>Main=</nowiki>
[[File:Happydays.png|thumb|131x131px|The icon of <span>'''Happy_Days_.exe'''.</span>]]
 
== <span>'''Happy_Days_.exe'''</span> ==
Happy_Days_.exe is a korean [[screamer]] application. It is very similar to the other Win32/Flaghost malware however the screamer picture that it shows is slightly altered. Once executed, a black popup box is shown every 5 seconds that contains the screamer picture and a blue colored text saying "^^ Happy days... please 5 seconds... to close"


After 5 seconds the pop up will close however after more 5 seconds it will show up again and it does that in an infinite loop until the computer gets rebooted. By looking into the file assembly you will see that the application has the text "Scanregw" as the product name which is an attempt to trick the user into thinking that the application is a Registry Scanner. Since the application is coded in Visual Basic 6 Korean the file "vb6ko.dll" must be installed on the users computer or the application can not be executed.
After 5 seconds the pop up will close however after more 5 seconds it will show up again and it does that in an infinite loop until the computer gets rebooted. By looking into the file assembly you will see that the application has the text "Scanregw" as the product name which is an attempt to trick the user into thinking that the application is a Registry Scanner. Since the application is coded in Visual Basic 6 Korean the file "vb6ko.dll" must be installed on the users computer or the application can not be executed.