As of October 24, 2003, due to a decreased rate of submissions, Symantec Security Response has downgraded the threat level of this worm from Category 3 to Category 2 as of October 24, 2003.
The VBS.Haptime.A@mm worm:
- Is a Visual Basic Script (VBS) worm.
- Infects the .htm, .html, .vbs, .asp, and .htt files.
- Replicates using MAPI objects to spread itself as an attachment.
- Attaches itself to all the outgoing messages using the stationery feature of Outlook Express.
The worm uses a known Microsoft Outlook Express security hole so that the worm is executed without having to run any attachments.
Microsoft has patched this security hole that eliminates security vulnerabilities in "Scriptlet.TypLib" ActiveX controls. The patch is available at:
http://www.microsoft.com/technet/security/bulletin/ms99-032.mspx
If you have a patched version of Outlook Express, this worm will not automatically work.
Definitions dated before May 4, 2001, detect the worm as VBS.Help.A@mm.
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.