
Hybris Virus
Information
about Hybris virus:
Hybris
is a complex deadly worm, it will update
the plugins from the virus author's site
or through a virus conference news group
alt.comp.virus. The worm uses Win95/Babylonia
virus
technique to download plugins, but it
uses strong encryption on plugins using
RSA 128 bit keys. The worm patches
WSOCK32.DLL to email automatically.

The
plugins are designed to do different
tasks like infect files inside the
archives like RAR and ZIP, post messages
to alt.comp.virus group, etc. The
worm uses different file names, message
subject and message body to infect the
host PC. Users are advised not
to open attachments with .EXE, PIF and
SCR extensions.
Still
now more than 32 plug-ins of
hybris worm detected including
NEWS.DAT, DOSEXE.DAT, ENCR.DAT, HTTP.DAT,
AVINET.DAT, PRON.DAT, SPIRALE.DAT,
SUB7.DAT. Fire detects and
removes I-Worm/Hybris and its variants
without problems.
Remvoing
Hybris worm from your system:
Fire has
incorporated Hybris worm and its variants
into its virus signature file, with the
aim of helping users affected by this
worm attack to detect and eliminate it
from their systems. Fire anti-virus users
can update this signature file by using online
update facility. It is available
with the registered version of Fire
anti-virus Kit. After cleaning
the Hybris worm, Fire recovers patched
WSOCK32.DLL file also. So Fire
users need not search for pure copy of
WSOCK32.DLL file.
A
free download
of FireLite
[ 1100KB
]
version is also available to detect
Navidad, Hybris and Prolin internet
worms. If you find this virus, use
registered version of Fire to remove. To
get the registered version of Fire call
us at 044-28170440 or mail to service@fireav.com
or purchase Fire online using 
[Analysis:
Mr.Ramesh, Stanley Rakesh, Prognet
Technologies Pvt. Ltd, Nov. 2000]

|