Snow White Virus (TROJ_HYBRIS.M)
Moderator: Wiz Feinberg
- Bill Rowlett
- Posts: 860
- Joined: 4 Aug 1998 11:00 pm
- Location: Russellville, AR, USA
Snow White Virus (TROJ_HYBRIS.M)
I got several email messages with the Snow White Virus (TROJ_HYBRIS.M) virus today. The sender is shown as HaHaHa, however when I traced them they appear to have originated from a member of this forum. I think that it is likely that a virus has taken over his machine and is using his address book to send copies of itself.
I have emailed the person that I think the message originated from and will not reveal his name, however if other forum members are getting these messages today, please respond to the board so we can verify the virus is active.
Bill
I have emailed the person that I think the message originated from and will not reveal his name, however if other forum members are getting these messages today, please respond to the board so we can verify the virus is active.
Bill
- Bill Rowlett
- Posts: 860
- Joined: 4 Aug 1998 11:00 pm
- Location: Russellville, AR, USA
The person I suspected confirmed that he had received this email header for several months. He said that he had opened the first one (.exe file) and did nothing with it because it appeared to be porno related. He has since been receiving these emails regularly. I seem to remember that this was an ugly virus that propagates via email. I'll research it and post further updates. I suspect that it is now resident on his machine either as a trogan or worm.
Bill
Bill
- Bill Rowlett
- Posts: 860
- Joined: 4 Aug 1998 11:00 pm
- Location: Russellville, AR, USA
This is a trojan virus that propogates via email.
http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=TROJ_HYBRIS.M
TROJ_HYBRIS.M
Risk rating:
Virus type: Trojan
Destructive: No
Aliases:
HYBRIS.M, Snow White, W32.Hybris.gen, W32/Hybris-M, I-Worm.Hybris.M, W32/Hybris.gen@
Description:
This non-destructive worm is a variant of TROJ_HYBRIS.C. It propagates via email, by sending itself as an attachment to every user listed in the address book of the infected user.
I'll try to explain it to him and maybe he can find a way to clean his system.
Bill <FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Bill Rowlett on 14 September 2001 at 02:25 PM.]</p></FONT>
http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=TROJ_HYBRIS.M
TROJ_HYBRIS.M
Risk rating:
Virus type: Trojan
Destructive: No
Aliases:
HYBRIS.M, Snow White, W32.Hybris.gen, W32/Hybris-M, I-Worm.Hybris.M, W32/Hybris.gen@
Description:
This non-destructive worm is a variant of TROJ_HYBRIS.C. It propagates via email, by sending itself as an attachment to every user listed in the address book of the infected user.
I'll try to explain it to him and maybe he can find a way to clean his system.
Bill <FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Bill Rowlett on 14 September 2001 at 02:25 PM.]</p></FONT>
-
- Posts: 533
- Joined: 4 Aug 1998 11:00 pm
- Location: Paducah, KY, R.I.P.
- George Rozak
- Posts: 591
- Joined: 26 Feb 2000 1:01 am
- Location: Braidwood, Illinois USA
-
- Posts: 6870
- Joined: 27 Nov 2000 1:01 am
- Location: Oklahoma City, OK USA, (deceased)
- Contact:
I have received the Snow White Ha Ha thing once or twice a month for the past year, including two or three times this month, but Norton always intercepts it.
It doesn't even annoy me anymore, as I just see it as routine housekeeping like sweeping the floor. When I turn on my computer and find one there, I just automatically do the procedure to get rid of it (4 or 5 seconds), and then forget about it.
P.S. Forgot to mention that I got my last one about a week ago, so apparently they are coming from more than one source.<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Gene Jones on 15 September 2001 at 05:02 PM.]</p></FONT>
It doesn't even annoy me anymore, as I just see it as routine housekeeping like sweeping the floor. When I turn on my computer and find one there, I just automatically do the procedure to get rid of it (4 or 5 seconds), and then forget about it.
P.S. Forgot to mention that I got my last one about a week ago, so apparently they are coming from more than one source.<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Gene Jones on 15 September 2001 at 05:02 PM.]</p></FONT>
- Bill Rowlett
- Posts: 860
- Joined: 4 Aug 1998 11:00 pm
- Location: Russellville, AR, USA
I got one at work today from another source too. I just realized that I upgraded computers and did not transfer my kill list from the old browzer to the new one. That is why I suddenly began to see that HaHaHa email again. Same thing for all the Viagra, mortage and credit card spam again.
The new Nimda virus appears to be a real problem one. I noticed a ton of port probes against my firewall last night. According to McAfee, that is one of the characteristics of Nimda transmission over the internet. I hope that I did not pick it up from one of the websites that I visited overnight. I'll have to go home and look for the signs of infection. I keep a seperate hard drive just for internet surfing and email. I don't want the kids to pick up a trogan or virus that could wipe out my family data disk.
The new Nimda virus appears to be a real problem one. I noticed a ton of port probes against my firewall last night. According to McAfee, that is one of the characteristics of Nimda transmission over the internet. I hope that I did not pick it up from one of the websites that I visited overnight. I'll have to go home and look for the signs of infection. I keep a seperate hard drive just for internet surfing and email. I don't want the kids to pick up a trogan or virus that could wipe out my family data disk.