Hybris Virus Information and
Removal Help
"Snowhite and the Seven Dwarfs virus"
What is Hybris Virus and How Did
I Get It?
Along with the email are any of the following attachments:
Opening the attachment, starts the worm and infects the system. It corrupts WSOCK32.DLL, which needs to be replaced to repair the damage, and creates some randomly named files in the C:\WINDOWS\SYSTEM directory similar to the ones below:
This worm patches the WSOCK32.DLL file in the Windows\System folder. When it is executed, it modifies the WSOCK32.DLL file and adds its virus code onto it. Then it sends emails similar to the ones at the top of this document. How to avoid infection The worm infects WSOCK32.DLL and when an e-mail is sent, also sends a seperate e-mail with the From: header that reads "Hahaha <hahaha@sexyfun.net>", and places the worm as an attachment to the message. As usual, DO NOT execute that file! Just delete it! Signs of infection Hyris is one of the few worms that can download "plugins". It does this by making NNTP connections to one of a list of news servers in a list, and reading the newsgroup alt.comp.virus, where plugins are posted. It can also post any plugins on an infected system to alt.comp.virus, as the plugins are not transmitted along with the worm via e-mail. Depending on what plugins are on an infected system, you may notice some or all of the following occuring: Altered ZIP and RAR archives where EXE files have been renamed to have an extension of .EX$, and a copy of Hybris replacing the original filename. Scanning other machines, and infecting machines that have the SubSeven backdoor on them. Affecting EXE files on the local system so that they become "droppers" of the worm. This can cause re-infection of a system after you think you have eradicated the worm. Display a back and white "spiral" on the screen on the 59th minute of each hour, starting in 2001. Here is a list of known plugins for the virus: HTTP.DAT, NEWS.DAT, AVINET.DAT, ENCR.DAT, PR0N.DAT, SPIRALE.DAT , SUB7.DAT, AND DOSEXE.DAT. How to Clean/Delete the Hybris Virus? Because of the nature of the virus and the various plug-ins associated with the virus, manual removal of it really isn't possible. To clean the virus from an infected system. Use this basic gameplan below: First, restore the corrupted WSOCK32.DLL file so that the virus stops sending emails and causing havoc and unexpected errors in your computer. Follow the steps below to restore the file from Windows 95 or 98 To restore WSOCK32.DLL in Windows 95
To restore WSOCK32.DLL in Windows 98
or
Next, reboot your computer into Windows and do one of the following:
or
Click
Here to go to
|
Tools for Removing Spyware, Adware, and Malware PC HELL Welchia (Dllhost.exe and SVCHost.exe) Worm Removal Uninstall Antivir Instructions How to Manually Run the Microsoft Malicious Software Removal Tool Bloodhound.Exploit.6 Virus Removal Backdoor SDBot.H Trojan Removal
|
| Recommended Software for PC Hell Visitors | |||||
![]() Start FREE Scan... |
FREE Registry
Scan! Clean, repair, and optimize your system with the leading and award-winning Registry Booster from Uniblue. Registry Booster is the safest and most trusted solution to clean and optimise your system, free it from registry errors and fragmented entries. Through Advanced Error Detection Technology, Registry Booster automatically identifies missing, corrupt, or invalid items in your Windows registry and dramatically enhances performance and general stability. |
![]() Start FREE Scan... |
FREE Performance Scan! Now, you can get a faster, cleaner, and safer PC within minutes - without being a Windows expert! SpeedUpMyPC automatically finds the best settings for your PC and carefully controls your system resources to give you the best performance. Easy to use, this award-winning utility has all the features you could ever need to clean up your system, monitor resources, and improve performance. |
![]() Start FREE Scan... |
Free Spyware Scan! |
![]() including Ad-Aware SE, Norton Antivirus, and Mozilla Firefox |
![]() Perfect Uninstaller |
![]() Spy Sweeper |
|
Search PCHELL.COM |
|
|