Hybris Virus Information and
Removal Help
"Snowhite and the Seven Dwarfs virus"
What is Hybris Virus and How Did
I Get It?
Along with the email are any of the following attachments:
Opening the attachment, starts the worm and infects the system. It corrupts WSOCK32.DLL, which needs to be replaced to repair the damage, and creates some randomly named files in the C:\WINDOWS\SYSTEM directory similar to the ones below:
This worm patches the WSOCK32.DLL file in the Windows\System folder. When it is executed, it modifies the WSOCK32.DLL file and adds its virus code onto it. Then it sends emails similar to the ones at the top of this document. How to avoid infection The worm infects WSOCK32.DLL and when an e-mail is sent, also sends a seperate e-mail with the From: header that reads "Hahaha <hahaha@sexyfun.net>", and places the worm as an attachment to the message. As usual, DO NOT execute that file! Just delete it! Signs of infection Hyris is one of the few worms that can download "plugins". It does this by making NNTP connections to one of a list of news servers in a list, and reading the newsgroup alt.comp.virus, where plugins are posted. It can also post any plugins on an infected system to alt.comp.virus, as the plugins are not transmitted along with the worm via e-mail. Depending on what plugins are on an infected system, you may notice some or all of the following occuring: Altered ZIP and RAR archives where EXE files have been renamed to have an extension of .EX$, and a copy of Hybris replacing the original filename. Scanning other machines, and infecting machines that have the SubSeven backdoor on them. Affecting EXE files on the local system so that they become "droppers" of the worm. This can cause re-infection of a system after you think you have eradicated the worm. Display a back and white "spiral" on the screen on the 59th minute of each hour, starting in 2001. Here is a list of known plugins for the virus: HTTP.DAT, NEWS.DAT, AVINET.DAT, ENCR.DAT, PR0N.DAT, SPIRALE.DAT , SUB7.DAT, AND DOSEXE.DAT. How to Clean/Delete the Hybris Virus? Because of the nature of the virus and the various plug-ins associated with the virus, manual removal of it really isn't possible. To clean the virus from an infected system. Use this basic gameplan below: First, restore the corrupted WSOCK32.DLL file so that the virus stops sending emails and causing havoc and unexpected errors in your computer. Follow the steps below to restore the file from Windows 95 or 98 To restore WSOCK32.DLL in Windows 95
To restore WSOCK32.DLL in Windows 98
or
Next, reboot your computer into Windows and do one of the following:
or
Click
Here to go to
|
![]()
Tools for Removing Spyware, Adware, and Malware PC HELL Welchia (Dllhost.exe and SVCHost.exe) Worm Removal Uninstall Antivir Instructions How to Manually Run the Microsoft Malicious Software Removal Tool Bloodhound.Exploit.6 Virus Removal Backdoor SDBot.H Trojan Removal
iPadastic - News, Tutorials, Help, Tips, and Hints for the iPad Download Hoyle Games |
Recommended Software for PC Hell Visitors | |||||
![]() Malwarebytes Anti-Malware |
iolo System Mechanic® |
![]() Emsisoft Anti Malware |
|||
![]() |
|||||
Search PCHELL.COM |
|