Skip to main content
Skip to main content
Published May 23, 2005 | Updated Mar 25, 2007

Win32/Hybris

Detected by Microsoft Defender Antivirus

Aliases: Win32.Hybris (CA) Hybris (F-secure) W32/Hybris.gen@MM (McAfee) W95.Hybris.gen (Symantec) WORM_HYBRIS (Trend Micro)

Summary

Win32/Hybris includes both a virus and a worm component. The virus component infects WSOCK32.DLL, enabling the virus to activate when an Internet connection is established. The worm component spreads by monitoring outgoing e-mail traffic and, when a legitimate e-mail is sent, follows that by sending a second email to the same addresses. That email contains a copy of the worm. Win32/Hybris can download plug-ins via anonymous binary postings made to a particular newsgroup, thus changing the functionality.
Follow us