Event ID - 119

Port No119
Service NameHappy99
RFC Doc0
ProtocolTCP
DescriptionThis worm propagates in networks via email and newsgroup postings. It does not destroy or infect any file, but replicates on networks. It sends email messages and newsgroup postings with a copy of itself as the attachment, Happy99.exe (Year 1999 version) or Happy00.exe (Year 2000 version).
Reference LinkHappy99 Trojan
AttackSOLUTION :
AUTOMATIC REMOVAL INSTRUCTIONS
To automatically remove this malware from your system, please refer to the Trend Micro Damage Cleanup Engine and Template.

MANUAL REMOVAL INSTRUCTIONS

1.Scan your system with Trend Micro antivirus and delete all files detected as WORM_SKA.A. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users may use HouseCall, Trend Micro's free online virus scanner. 2.Click Start>Search>Files or folders. Look for and then delete these files:
WORM_SKA.A
WORM_SKA.DLL
HAPPY99.EXE
HAPPY00.EXE
Look for these files and modify their attributes from READ ONLY to ARCHIVE. To achieve this, run ATTRIB.EXE:
WSOCK32.SKA
WSOCK32.DLL
3.Delete WSOCK32.DLL and rename WSOCK32.SKA as WSOCK32.DLL. If WSOCK32.DLL cannot be deleted because it is being used by other programs, restart the computer in DOS mode and then delete WSOCK32.DLL there with this command: del c:\Windows\System WSOCK32.DLL
4.Type, REGEDIT, then hit the Enter key.
5.In the left panel, double click the following:HKEY_CURRENT_USER>Software>Microsoft>Windows
6.In the right panel, look for and then delete this entry: SKA.EXE

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.