[Next Message in Time] | [Previous Message in Time] | [Next Message in Topic] | [Previous Message in Topic]

Message ID: 2459
Date: Thu Mar 1 21:06:17 GMT 2001
Author: Yodason
Subject: RE: [EQ_Tinkering] please read, I picked up a virus


hmmm i think i might have that too, what scanner picks it up
-----Original Message-----
From: Funky T. Munky [mailto:toking@...]
Sent: Thursday, March 01, 2001 12:30 AM
To: Rainpudle@...; R. Schilling; Naninna; Miss Spot; marie; kinanmer@...; Kelley Allred; JesikaHarrison@...; jenna turner; J. Shafer; EQ_Tinkering@yahoogroups.com; Echo Vane
Subject: [EQ_Tinkering] please read, I picked up a virus

Hiya all, I'm a moron and managed to pick up a virus, I really had no idea it was there until i started getting strange crashes (IEXPLORE cause a general protection fault in module wsock32.dll) and a bunch of my everquest log files and opt files started showing up on my desktop. If you arent running any antivirus software/havent run it in a while, please do so soon.

Below you will find some info on the nasty little bug that got me. Sorry all, I"ll try and be a little more vigilant in the future

Joe

Win32:Hybris

Win32:Hybris is an Internet worm which has the capability to update itself via Internet. There is a kernel part and separate "plugins" which can be swaped or even upgraded via Internet. These plugins are encrypted with quite strong cryptography.

When executed, Win32:Hybris infects WSOCK32.DLL and sends itself in a separate message complementary  to any meassage sent from the infected computer.  The subject, text of the message and the name of the attached file are part of the plugin so they could be changed via upgrade mechanism. The basic version can contain the texts in English, French, Spanish and Portugese. The English message has sometimes the subject "Snowhite and the Seven Dwarfs - The REAL story!" and the body contains the adult version of the well known tale. 

The upgrade mechanism of this worm is very flexible and could be changed in the future via the special plugins. Currently it can download the plugins from the dedicated web page and it can get them from the special Usenet discussion group called alt.comp.virus. All instances of worm can upload and download the encrypted plugins in a special format with identifier and version number into this mailing group. Another plugins are responsible for ZIP and RAR infections. There could be some more in the future.



Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.