SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > General Computing > Internet
User Name
Password


Virus Win32/Hantaner!!! Plz help

Reply
 
Thread Tools Search this Thread Rating: Thread Rating: 3 votes, 3.67 average. Display Modes

  #1  
Old 12-24-2002, 06:42 PM
zile Offline
Junior Member
 
Join Date: Dec 2002
Posts: 5
Virus Win32/Hantaner!!! Plz help

i get this virus (Win32/Hantaner) from kazza.

i use avg as my anti-virus program. The "residential sheild" says that a virus has been dectected in C:\system_voluem_information\.... (some long code after that).

but when i run a complete test, it says that no virus was dectected.

Is the virus still in my computer? If it is how can i remove it?
Is this a dangerous virus?


Thanx

oh BTW i use window xp home edition.
Reply With Quote

  #2  
Old 12-24-2002, 07:47 PM
ESALADUANE's Avatar
ESALADUANE Offline
Senior Member
 
Join Date: Nov 2002
Location: Minneapolis, Minnesota, USA
Posts: 2,003
I got this from another site:

Win32.HLLP.Hantaner

It is a harmless nonmemory resident parasitic Win32 virus. The virus itself is PE EXE file (Win32 executable file), it is written in Delphi and has the length about 47K (not compressed) or 24K (compressed by UPX).

It searches for *.EXE files (any files with .EXE filename extension) in the KaZaa download directory and writes itself to the beginning of the files. As a result the virus is able to spread through KaZaa files sharing network (being downloaded from infected machine).

The virus does not manifest itself in any way.

The virus also contains the text strings:

HANTA-Vjoiner ,si que lo hice yo, ErGrone/GEDZAC...
eso va para los seÓoritos de PER, en especial a Machado, que no tiene la educaciÕn necesaria para responder un E-Mail.
y para los que se enojaron con CPL, jeje, pa que ocupan Hotmail!!!, teniendo miles de mailbox gratis y con mas espacio.
FallÕ la Heuristica y contra una tÊcnica antigua JoJOjOO-Escrito en Delphi 6!-
Reply With Quote

  #3  
Old 12-24-2002, 11:36 PM
zile Offline
Junior Member
 
Join Date: Dec 2002
Posts: 5
Thanx ESALADUANE. I appreciate it. And i'm glad that the virus is a harmless one.

But if i were to choose i would rather not have it on my comp.

Is there anyway to permenantly remove this nonmemory virus?


THANX
Reply With Quote

  #4  
Old 12-25-2002, 12:26 AM
ESALADUANE's Avatar
ESALADUANE Offline
Senior Member
 
Join Date: Nov 2002
Location: Minneapolis, Minnesota, USA
Posts: 2,003
oops, I forgot to add the link:

http://www.viruslist.com/eng/viruslist.html?id=58323
Reply With Quote

  #5  
Old 12-25-2002, 07:56 AM
Tobin Offline
Member
 
Join Date: Nov 2002
Location: Southern Cal
Posts: 38
McAfee Virus Information

It only says that they have a dat file that will delete it and gives you information about the amount of damage it does.
Reply With Quote

  #6  
Old 12-25-2002, 04:48 PM
zile Offline
Junior Member
 
Join Date: Dec 2002
Posts: 5
Thanx alot tabin.

i found out that the virus is still on my computer, and avg dectected it in the "c:\system volume information" directory.

I found out a way to get rid of this, so everyone that are having problem because anti-virus program can not delete a virus from this particular folder should do this:

""""""Description for disabling restore function for Windows XP:

Files placed in the _System volume information folder are source files for the system restore function that is available in Windows XP operating system. Files that were healed were moved in their original INFECTED state into this folder and it is necessary to DELETE them by following these steps:

Close all open programs. Then right-click My Computer on the Windows desktop
Click on Properties
Click on the System Restore tab
Check Turn off System Restore on all drives



Note: this information was found on the avg website: http://www.grisoft.com/html/us_faq.p...aa2cf27d9e60ed


oh yeah one more thing: I hope that those whom coded viruses can get a life and burn their asses in hell.
Reply With Quote

  #7  
Old 12-29-2002, 06:03 PM
Madcapper's Avatar
Madcapper Offline
Junior Member
 
Join Date: Dec 2002
Posts: 2
Question for ESALADUANE:

Just curious about the comment you made about file sharing programs being hugely unpopular in many circles.
What circles do you refer to? I could see why the file sharing programs like Kazaa would be unpopular with software vendors but I don't understand why normal Joes would object to them. No skin off their backs.

As for the Win32 Hantaner virus, I also got hit with it and was successful in cleaning it. I don't know if it takes up residence in the same places and in the same ways every time but in my case it took up residence in the C:\_RESTORE directory. Microsoft deliberately made it difficult to modify this folder and the only way to do it is to disable system restore. It'll wipe out your restore points, which is the tradeoff for getting rid of the virus. If this applies here and you have to take this route, don't forget to re-enable system restore once you clean your system.
Reply With Quote

  #8  
Old 12-29-2002, 06:12 PM
ESALADUANE's Avatar
ESALADUANE Offline
Senior Member
 
Join Date: Nov 2002
Location: Minneapolis, Minnesota, USA
Posts: 2,003
What distinction are you making between software vendors and normal Joes?
Reply With Quote

  #9  
Old 12-30-2002, 03:21 AM
Madcapper's Avatar
Madcapper Offline
Junior Member
 
Join Date: Dec 2002
Posts: 2
Maybe 'vendors' isn't the word I was looking for. Maybe 'conglomerates' would be more appropriate. Nintendo, or even the RIAA are examples.
I personally am not into the file-swapping thing but it doesn't have much to do with ethics. People who do it don't bother me none. Just through my own experience I seldom encounter people who are bothered by it, so I was honestly curious about your comment.
Reply With Quote

  #10  
Old 12-30-2002, 04:12 PM
eatty's Avatar
eatty Offline
Junior Member
 
Join Date: Dec 2002
Posts: 1
I got the same virus on my computer through kazaa and every time i start the computer the avg sheild comes up then freezes when i try to do somthing and i can't get to the place to delete it. how would i fix this problem?

EATTY

(ps. i have windows ME)
Reply With Quote

  #11  
Old 12-31-2002, 02:58 AM
The Tool's Avatar
The Tool Offline
Mod
 
Join Date: Feb 2002
Location: LaLa Land
Posts: 918
Current engine and DAT files of McAfee can remove it.
Reply With Quote

  #12  
Old 12-31-2002, 08:40 AM
Quokka Offline
Junior Member
 
Join Date: Nov 2002
Location: kent uk
Posts: 18
I use AVG, I also have Zone Alarm .
Even if you go to Kazza and share files ?????????????? the firewall will only let you share others, it wont allow others to share yours !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! not allowing others to share your files, selfish yes, but much safer, not that I speak from personal experience you understand
Quokka

just read all that stuff from Esduane, if I had had kazza light I may have just deleted it.
__________________
help I'm a ludite !!!

Last edited by Quokka : 12-31-2002 at 08:50 AM.
Reply With Quote

  #13  
Old 01-04-2003, 09:59 PM
Marky1928 Offline
Junior Member
 
Join Date: Jan 2003
Posts: 5
Zone alarm

Hey Quokka with Zonealarm do u know how to make websites open faster or what is making them slower

Last edited by Marky1928 : 01-04-2003 at 10:37 PM.
Reply With Quote

  #14  
Old 01-04-2003, 10:36 PM
Marky1928 Offline
Junior Member
 
Join Date: Jan 2003
Posts: 5
Scan

U can try scaning your computer with stinger from Mcafee and will find viruses and fix the files ( http://vil.nai.com/vil/stinger/ )
Reply With Quote

  #15  
Old 01-04-2003, 11:09 PM
Quokka Offline
Junior Member
 
Join Date: Nov 2002
Location: kent uk
Posts: 18
As my signiture suggests, and the other few posts I have made here, I know nothing mate, sorry.
I also have adsl broadband so speed aint no problem to me,( smug sod )
Trouble is, being a pillock with the fastest computer I could get and with the fastest connections, it just means I COCK UP TWICE AS QUICK AS EVERYONE ELSE.
Sorry I cant be of assistance marky
Quokka
__________________
help I'm a ludite !!!
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Blaster virus help request - thanks! owenhbrown Windows XP 8 04-30-2005 10:08 PM
virus from hell HELP! Felman Windows XP 3 02-12-2005 05:02 PM
how to get rid of a file w/ a certain virus SHk012 Windows XP 2 06-23-2003 11:38 AM
Virus Help- NAV Isnt Helping antivirus99 Windows XP 3 03-10-2003 06:20 PM
Trillian Pro Virus high6ix Internet 14 02-18-2003 01:32 PM



All times are GMT -5. The time now is 11:53 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.