Event ID - 119

Port No119
Service NameHappy99
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows 95 and 98. Starts on Windows NT, but does not copy itself.
Reference LinkHappy99 Trojan
AttackIt autoloads the Registry:
HLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\

It does the following :
1. Worm / Mail trojan
2. Alters WSock32.dll. Disguised as picture with fireworks and the message ""Happy New Year 1999!". ; "Replaces your current winsock in order to attach the trojan to outgoing email."

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.