Snow White

Information about the 'Snow White' worm.

Virus name:   Snow White.

Status:   Real.

Example:   [Collected on the Internet, 2002]

From: Hahaha []
Subject: Snowhite and the Seven Dwarfs - The REAL story!

Today, Snowhite was turning 18. The 7 Dwarfs always where very educated and polite with Snowhite. When they go out work at mornign, they promissed a *huge* surprise. Snowhite was anxious. Suddlently, the door open, and the Seven Dwarfs enter...

(This message is accompanied by an attachment with a .SCR or .EXE file extension .)
Origins:   Snow White (also known as W95.Hybris.gen) is a worm activated when a victim receives a message like the one quoted above and executes its attachment. The worm modifies (or replaces) the recipient's wsock32.dll file, then replicates by sending the same message (with a forged return address of to addresses found in the recipient's e-mail (both inbound and outbound messages) or addresses found in web pages browsed by the recipient.

See the links below for more information on how to detect and remove Snow White.

Additional Information:
    W95.Hybris.gen W95.Hybris.gen
(Symantec Security Response)
    W32/Hybris.gen@MM W32/Hybris.gen@MM
(McAfee Virus Information Library)
Last updated:   29 January 2008


David Mikkelson founded in 1994, and under his guidance the company has pioneered a number of revolutionary technologies, including the iPhone, the light bulb, beer pong, and a vaccine for a disease that has not yet been discovered. He is currently seeking political asylum in the Duchy of Grand Fenwick.