Virus.Win32.HLLP.Hantaner.a (Kaspersky Lab)
is also known as:
Win32.HLLP.Hantaner.a (Kaspersky Lab),
W32/HLLP.Hantaner.a.worm (McAfee), W32.HLLP.Handy (Symantec), Win32.HLLP.Hanta.24064 (Doctor Web), W32/Hantaner-A (Sophos), Win32/HLLP.Hantaner (RAV), PE_HANTANER.A (Trend Micro), W32/Hantaner (H+BEDV), W32/HLLP.Hantaner.A (FRISK), Win32:Hantaner (ALWIL), Win32/Hantaner.A (Grisoft), Win32.HLLP.Hantaner.E (SOFTWIN), W32.Hantaner (ClamAV), W32/EnerKaz (Panda), Win32/HLLP.Hantaner.A (Eset)
| Description added |
Nov 29 2002 |
| Behavior |
Virus |
It is a harmless nonmemory resident parasitic Win32 virus. The virus itself
is PE EXE file
(Win32 executable file), it is written in Delphi and has the length about 47K
(not compressed)
or 24K (compressed by UPX).
It searches for *.EXE files (any files with .EXE filename extension) in the
KaZaa download directory
and writes itself to the beginning of the files. As a result the virus is able
to spread
through KaZaa files sharing network (being downloaded from infected machine).
The virus does not manifest itself in any way.
The virus also contains the text strings:
HANTA-Vjoiner ,si que lo hice yo, ErGrone/GEDZAC...
eso va para los seÓoritos de PER, en especial a Machado, que no tiene la educaciÕn
necesaria para responder un E-Mail.
y para los que se enojaron con CPL, jeje, pa que ocupan Hotmail!!!, teniendo
miles de mailbox gratis y con mas espacio.
FallÕ la Heuristica y contra una tÊcnica antigua JoJOjOO-Escrito en Delphi
6!-