hllc.cp-ma
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
HLLC.CP-Man
These viruses were compiled with high level language compilers and in some cases packed with different compression utilities. Often they contain the text strings, according to the compiler:
Turbo C++ - Copyright 1990 Borland Intl. Null pointer assignment
Abnormal program termination
Divide error
Runtime error
The "HLL" viruses are divided into several classes:
HLLC: High Level Language Companion viruses. These viruses are companion ones.
HLLO: High Level Language Overwriting viruses. These viruses search for files and overwrite them.
HLLP: High Level Language Parasitic viruses. These are parasitic viruses that infect the files at their beginning or at their end without overwriting the file.
HLLW: High Level Language Worm viruses. These viruses do not need any host file to spread. They just copy themselves to disk directories with the same or different names.
HLLC.16850
It is a memory resident companion virus. It searches for the .EXE files and creates companion .COM files.
HLLC.17690
It is a nonmemory resident not dangerous file infector. It searches for the .COM and .EXE files of the subdirectory tree of random selected logical drive. It renames the file to the random selected name, stores that name into the own body in encrypted form, and writes itself instead of infected file. The infected file is not changed by the virus, it is only renamed.
This virus checks the contents of the files for the "Microsoft Windows" string and do not infect these files. On error this virus displays: "Bad command or file name". It was written in C language and contains several C-compiler strings.
HLLC.Cornucopia
That virus is encrypted and packed with PkLite. It drops itself in two different variants. It contains the text string:
detected the "Cornucopia Virus"
HLLC.CP-Man
This virus contains the text strings:
Very fast interrupt handler (C) PC Ace Technologies.
Let me present: CP-VIRUS!
Copyright (c) 1994-1995 CP-MaN of CP-DeZiGN
Written in Vasteras of Sweden!
Ya knowall Your mom can't save ya know!
________ _________
Greets: _ _ _ Oh, dear! I've trashed some sectors, but
_ _ _ still have them in memory (encrypted) and
Phalcon _ _________ will write them back to your disk if you
Skism, _ _ just do as I say. Shit happens!
Immortal _ _
Riot, ________ _
Dark
Avenger
Check this counter. If you reset or turn your computer off now all your
data will be lost forever. However, if you wait until the counter has
reached zero you won't lose any data! It's your choice. Happy waiting!
CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP CP
left, then you will get your data back. Happy waiting!
Finished! I'm impressed. You did really wait didn't you? Well, I just want
you to know that I keep my promises. No data is destroyed.
Oh, just one more thing. This virus does not destroy data at all, it would
have been enough to reset the computer. Hope you enjoyed waiting! Hehehe...
C:\DOS\MEM.DAT
C:\DOS\MEM.EXE
COMSPEC
/C REN C:\DOS\MEM.EXE MEM.DAT
/C COPY
C:\DOS\MEM.EXE >NUL
C:\DOS\SMARTDRV.DAT
C:\DOS\SMARTDRV.EXE
/C REN C:\DOS\SMARTDRV.EXE SMARTDRV.DAT
C:\DOS\SMARTDRV.EXE
*.exe
CHKLIST.MS
/C DEL CHKLIST.MS > NUL
CHKLIST.CP
/C DEL CHKLIST.CP > NUL
/C REN >NUL
HLLC.Cumulus
While infecting this virus appends to its code the file name that is infected, the current date and time. As a result the infected files contain the list of names of all their "parents" and the dates of infection. This virus contains the text strings:
*.exe .com x.y Captain Cumulus travels .COM .EXE
C:\PCTOOLS C:\WP51 C:\ACAD C:\EXCEL C:\WP C:\DOS
(C)CaptainCumulusandSantaClaus-Finland
HLLC.Eagle.7705
It is a harmless nonmemory resident virus. It is packed with Pklite utility, and contains the text string (also packed):
Portions Copyright (c) 1983,91 Borland & Eagle Performance Software
HLLC.Enrico
It drops "March6" boot virus on floppy disks. It contains the text:
(c) Enrico
HLLC.FLV.10217
This virus contains the text string:
Virus [Fired Love 10217] Version 1.0...! By L.S.Y.
HLLC.Globe.6610
It creates the .COM files with the name of .EXE files that are found. This virus compiled with Turbo-C compiler and compressed with DIET utility. The infector contains the text strings:
Turbo-C - Copyright (c) 1988 Borland Intl. Divide error
Abnormal program termination
Globe Virus V3.00
PATH *.EXE .COM .EXE
HLLC.Halley.7856
It is a nonmemory resident companion virus. It searches for .EXE files and creates the .COM files with the same name, then writes itself into these .COM files. This virus contains the text strings:
HALLEY -virus v.1.0
-------------------
Don`t panic, I`m the harmless one.
I just want to travel...
Have a nice day!
This virus was written in Turbo Pascal, the Pascal copyright message is erased with the strings:
Shit happens... at
WANT TO TRAVEL!! I WANT TO TRAVELL!!
HLLC.Happy
These are not dangerous nonmemory resident companion viruses. They search for .EXE files of the current directory, and create the .COM files with the same names but the .COM extensions. They stay memory resident but do not hook virus-like interrupts - so they are set as nonmemory resident. There are two such viruses, both variants are the same virus, but compressed with different utilities: LZEXE and PKLITE. In October on Mondays these viruses display the message:
HAVE A "HAPPY MONDAY" LANCSPOLY SUCKERS. POP WILL EAT ITSELF
and display the 'face' character (ASCII 1).
HLLC.IdoMoshe
This virus creates the VIRDEMO.EXE files in root directories of all available disks and writes its body into these files. Then it modifies AUTOEXEC.BAT file in root directories of all drives, and then insert into beginning of this file the strings:
Echo off
virdemo
If there is no AUTOEXEC.BAT file, the virus creates it. This virus displays the message:
YOU HAVE A IDO & MOSHE NON HAZARD DEMO VIRUS
FOR CLEANING THIS VIRUS YOH MUST DELETE ALL VIRDEMO.EXE FILES
IN ALL ROOT DIRECTORIES IN ALL YOUR DISK
It also contains the strings:
:\Virdemo.exe :\virdemo.exe :\autoexec.bat virdemo Echo off
HLLC.Lanc
It is a memory resident companion virus. This virus was compiled with Turbo-Pascal compiler. This virus contains the text strings:
*.EXE .COM COMSPEC
>HAVE A "HAPPY MONDAY" LANCSPOLY SUCKERS. POP WILL EAT ITSELF
HLLC.Tpworm
It is a harmless nonmemory resident virus. It searches for .EXE files and creates the companion .COM files with the same names. This virus was compiled by Microsoft C compiler and contains all Microsoft C compiler strings. Sometimes this virus deletes the infected file and displays:
Find me!
HLLC.Ultimation
It is not a dangerous nonmemory resident virus. It searches for *.EXE file, renames it to "_*.EXE", and writes itself instead of this file.Being executed this virus searches and infects the first not infected EXE file, then executes the host file. The virus is compiled by Turbo C compiler and contains the text strings:
Turbo C++ - Copyright 1990 Borland Intl.
Null pointer assignment
Divide error
Abnormal program termination
PATH *.EXE copy NUL
It also contains the debug information. After execution this virus displays one of the messages:
I'm bored.
Screw you.
Life is a drag.
kufc fof.
Ouch! Don't hit me so hard.
Floppy drive A: is flooded. Please insert J cloth.
Murderer.
You have been infected by ULTIMATION corp.
Go directly to jail. Do not pass go. Do not collect $200.
.Ah ha! Caught you.
Copy protection error 23. Please re-install from master.
HLLC.Aids.8064
This is a harmless (?) nonmemory resident companion virus. If a companion file which has no original .EXE file (i.e. host file) is started, the virus displays the text:
Your computer is infected with ...
Aids Virus II
- Signed WOP & PGT of DutchCrack -
Getting used to me ?
Next time, Use a Condom .....
HLLO.Aids
These viruses are written in Pascal, and contain the text:
This File Has Been Infected By AIDS! HaHa!
*********************************************************************
* ATTENTION: *
* I have been elected to inform you that throughout your process of *
* collecting and executing files, you have accidentally ...... *
* yourself over; again, that's PHUCKED yourself over. No, it cannot *
* be; YES, it CAN be, a ..... has infected your system. Now what do *
* you have to say about that? HAHAHAHA. Have .... with this one and *
* remember, there is NO cure for *
* *
* __________ ____________ ___________ __________ *
* ____________ ____________ ____________ ____________ *
* ____ ___ ___ ___ ___ ____ __ *
* ___ ___ ___ ___ ___ ___ *
* _____________ ___ ___ ___ ____________ *
* _____________ ___ ___ ___ ____________ *
* ___ ___ ___ ___ ___ ___ *
* ___ ___ ___ ___ ____ __ ____ *
* ___ ___ ____________ _____________ ____________ *
* __ __ ____________ ___________ __________ *
* *
*********************************************************************
HLLO.Harakiri.5488
It is a very dangerous nonmemory resident virus. It searches for .COM and .EXE files, and overwrites them. The infected files are not recoverable, they should be deleted. This virus displays several messages while processing the files:
Ej Infekterad....!
Sdir =
Infecting file
File Already Infected
Program too big to fit in memory
Your PC is alive and infected with the HARAKIRI virus!
It also contains the text strings:
*.*
*.exe
*.com
This virus compiled by Turbo-Pascal compiler and there are the compiler messages in the virus body.
HLLO.House.11636
It is a very dangerous nonmemory resident virus. It searches for .EXE files of the current directory and overwrites them. It is written in C language. It contains the text string:
*.exe *HOUSEVIRUS* *.exe rb rb rb+
HLLO.Joker
When an infected file is executed, the virus scans the directories of A: and C: disks and infects there not more than 10 .EXE files. After infecting the virus searches for .DBF files, and writes some data to them (makes them shorter?). The virus contains the strings: "C:\*.", "C:\", "C:\*.EXE", "\*.EXE", "C:\*.DBF", "\*.DBF", "A:\*.EXE", "A:\", "Runtime error at". Instead of running the host file, the virus displays one of the strings:
Error in EXE file
File cannot be copied onto itself
Compare OK
Invalid Volume ID Format failure
Incorrect DOS version
Please put a new disk into drive A:
End of input file
END OF WORKTIME. TURN SYSTEM OFF!
Divide Overflow
Water detect in Co-processor
I am hungry! Insert HAMBURGER into drive A:
NO SMOKING, PLEASE! Thanks.
Don't beat me !!
Don't drink and drive.
Another cup of cofee ? OH, YES!
Can you .... me ? Maybe ...
Coca-Cola is it !
What about ? Oh, yes. O.K. TODAY
Missing VGA! Call (209) 683-6858 !
Attention! Hard Disk is RADIOACTIVE!
I'm so much dirty! CLEAN ME!
Kiss my ... keyboard!
Hard Disk's head has been destroyed. Can you borow me your one?
Missing light magenta ribbon in printer!
In case mistake, call GHOST BUSTERS
Insert tractor toilet paper into printer.
Are you funny?
Keep smiling!
Warning! In drive A: are two diskettes.
Warning! Your mouse has some virus!
Disconnect your mouse, there are some cats!
I don't understand you. Can you repeat it?
West Lake Software and Data Research, WA 0108077, New Orleans, (c) 1986
HLLO.Kamikaze
It owerwrites .EXE files of the current directory. It contains encrypted text:
kamikaze
HLLO.Nova
It is a dangerous nonmemory resident virus. It searches for .EXE files and overwrites them. It displays/contains the messages:
Finish demogroup NOVA 1994!
This program needs installation.
This is Dangerous Messanger, and here is my message to the world
Bad command or file name
Computer protected, no action.
Dangerous Messanger was here!
Can't initalize hardware... Try on another computer...
*.exe *.*
HLLO.NumOne
There are nonmemory resident dangerous viruses. They search for .COM files and overwrite them. They display while infecting a file:
This file has been infected by Number One!
infected.
They compiled with Turbo-Pascal compiler and contain all the compiler messages:
Copyright (C) 1985 BORLAND Inc
Color display 80x25
Not enough memory$Incorrect DOS version$
Program aborted
User Break I/O Run-time error
"HLLO.NumOne.b" contains the text:
Monochrome display
HLLO.Oscar
It is a nonmemory resident virus. It searches for *.COM and *.EXE files on drives C:, D:, ... and overwrites them. It contains the text string:
(C) by OSCAR
This virus is compressed, after decompression several other strings appear:
General error reading drive
Abort, Retry, File?
(C) OSCAR. To dopiero pierwsze pozdrowienia dla S.Fischera i M.Sella.
Runtime error at .
Portions Copyright (c) 1983,90 Borland
HLLO.Picked.4505
It displays the messages:
Hey, horney, you shoulda used a CONDOM!!!
There are no EXE files in
You Have picked the file:
HLLO.Pu
It contains the texts:
Infected with radioactive Pu !
Beware for radiation
HLLO.Ruf
It contains the internal texts:
The 1993 RUW-virus has infected your system.
The damage has taken place . . . .
Directory has been removed from the system.
Bad command or file name
HLLO.Ruf
It contains/displays the strings:
Packed file is corrupt(ed)
TU, 1994 product in TP v7.0
HLLO.Shadowgard
It is a very dangerous nonmemory resident overwriting virus. It searches for .COM and .EXE files and overwrites them. Then it decrypts and displays one of the messages:
Illegal copy
Insufficient memory
Network busy
Drive not ready
This virus is compiled by Pascal compiler. The Pascal error message "Runtime error" is replaced with the string:
[Shadow-Gard] in
This is only DEMO version ! Prepare...
HLLP.7408
It copies into the memory a TSR-program which delays on INT 1Ch (timer) and INT 27h (KEEP).
HLLP.5792
It infects .EXE files only, and displays the messages:
Error in *.EXE file
Pa,pa slodki bobasku ...
HLLP.6144
It contains the texts and displays some of them:
<*>-==> DisDev -Copyright (c) 1066 ScumSoft- <==-<*>
disdev
DisDev
Portions Copyright (c) 1066 ScumSoft!!
HLLP.7529
It contains the texts:
Insufficient DOS Version ... must be 3.2x or greater
Write Protect Error \ Disk Full ...
Error in file .EXE Abort.
PATH
Portions Copyright (c) 1983,90 Borland
IO sono STANCO ! va a dormire anche tu
HLLP.10460
It is not a dangerous nonmemory resident parasitic virus. It searches for .COM files of the current directory and writes itself to the beginning of the file. While infecting it displays the messages in Russian. It is compiled with Turbo C++ compiler and contains copyright strings of this compiler.
HLLP.15392
It displays the message:
M.S. Jurusalem Virus
This is a HARMLESS virus
Do not panick this is a Harmless Virus
<<< Press any key to continue >>
Do not worry this virus is designed to avoide making any damage to your
files. A free Virus remover will be send to computer Magazines:by then 30th
of oct 1992 So they can supply to coustomers. This is a demonstration of what
a Palestinian Boy can do. It is made by one of these Palestinians who are
suffering every day in their own homes because they don`t want to leave these
homes. It is the most unfair situation in the world, it is a crime which the
West has committed long time ago and still committing it until now under the
name of PEACE. Look at the Israelis, Western and Arabic governments. They are
criminals who talks about peace and freedom but they never allow them and
here are the Palestinians nation in Israel standing in their land fighting
for their own rights no matter what happens while U.S.A., Europe and some of
the Arabic nations supporting the Israelis to fight and finish this small
nation whom Jesus was one of them and after all this they call them selfs
Christians. It is Very easy to see this truth just wake up and remember that
one day you and your nationIare going to stand in front of the Creator of
this world to be judged on what you and your country did to the innocent
people. There is a lot a person can do to help a nation at least by
supporting this nation. It is very easy to such a virus to destroy your data
but this is not the manners of a good Palestinian. Our soul is light our
heart is white our mind is bright and we will always be the same no matter
what we go through. Signature: A Palestinian teenager. Sorry for interrupting
your work
HLLP.Animus
These viruses contain the text strings:
COMMAND.COM
Animus.id
Animus.exe
Portions Copyright (c) 1983,90 Borland
"HLLP.Animus.b" displays:
Give me CooKie? (use all Lower Case)
vanilla wafer
chocolate chip oreo hydrox
HLLP.Bdaagwa
It is packed with not standard compression utility. The decompressed virus contains the text strings:
Your PC is now BDGWA! (v1.2)
This program can not be executed because it is infected with a virus!
HLLP.Bishkek
"HLLP.Bishkek.4160" is not a dangerous virus. It displays the message:
Smokie4 virus (c) BISHKEK 1996
"HLLP.Bishkek.4240" is a very dangerous virus. It erases the disk boot sectors and displays the message:
2Smokie3 virus,i zater tvoi sector,Ti ponal? Y/N
The virus also contains the text strings:
Smokie3 (c) by Bishkek 1996
Pentium
HLLP.Dupalec
It is not a dangerous nonmemory resident parasitic virus. It searches for .COM and .EXE files and writes itself to the beginning of the file. While infecting it uses the DOS prompt commands RENAME and DEL that are called as sub-processes. This infector contains the text strings:
/C rename dupalec.exe
comspec
/C del dupalec.exe
dupacel.exe
/C rename dupa.exe
comspec
/C rename dupacel.exe
/C del
/C rename dupa.exe
protekt Cannot write .INI *.exe COMMAND.COM *.com NIEDZIALAJ
Runtime error at .
Portions Copyright (c) 1983,90 Borland
Pozdrowienia dla SZEFA!
Jak tam may Szmitek?
A teraz na powanie ( mam polskie znaki w standardzie Mazowii )
PROSZ NIE STRASZY DZIECI IN
Sometimes this virus displays one of the messages:
Przerwa obiadowa do 13:15
Wyszam za m.Zaraz wracam.
Ju dawno po bajce!
Zgodniaem
Uwaaj.W kuchni jest duch.
"Master of puppets" to stara dobra poezja Ppiewana
Czarny blues o 4-tej nad ranem?
Prosz nie straszy dzieci informatyk
HLLP.Globe.5150
It is a harmless nonmemory resident virus. It searches for the .COM and .EXE files and writes itself to the beginning of the file. This virus is compiled with Turbo-Pascal, and then compressed with LZEXE utility. The virus contains the text strings:
HELLO!!!!! - GlobeVirus V3.00
HLLP.Halloween
This is a harmless nonmemory resident virus. It searches for .COM and .EXE files and writes itself to the beginning of the file. It is compiled with TurboPascal compiler. The virus contains the text strings:
*.*
ALL GONE Happy Halloween
.COM .EXE
instal.exe /C instal.exe COMSPEC
*.COM *.EXE
savefrom.667
Runtime error at
HLLP.Legs
It encrypts the files while infecting them. It contans the encrypred text string:
DEATH ON TWO LEGS Was Here
HLLP.Lomza
It is a very dangerous nonmemory resident virus which looks in A:, B:, C:, D: disks directories for .COM and .EXE files and writes itself to the beginning of the file. In some cases it overwrites the files with reboot jump command (JMP F000:FFF0). This virus is written in Turbo-Pascal.
HLLP.Nazi, HLLO.Nazi
"Nazi.4415" is packed. "Nazi.4240" overwrites the file during infection. All "Nazi" viruses contain the text:
ON THE SABBATH.. THE GHOST OF HITLER SPEAKS :
"MY FELLOW NAZI'S.. I WAS WRONG.."
"I NOW COMMAND YOU TO COMMIT SUICIDE.. NOT GENOCIDE.."
"DO IT.. SO THE WORLD WILL BE RID OF THE NAZIPEST..
"AND ALL AUSLANDER CAN TRUELY BE FREE OF NAZIPHOBIA..
NaZiPhobia (c) [VooDoo].. We support the message..
Portions Copyright (c) 1983,90 Borland
HLLP.NotFound
It displays the message:
Borland Virus (C) 1994
Processor Intel PentiumTM not found.
17Gb disk free space not found.
512Mb extended memory not found.
16Mb XGA Video card not found.
Sound Blaster not found.
Sorry, your configuration doesn't match to run this...
HLLP.Rangel.5000
It contains the string:
(C) RANGEL
HLLP.Rsw.5846
It contains (and displays?) the strings:
By Rsw. Version 2.10
COMMAND.COM
VC.COM
CUT-REM.EXE
Copyright (c) 1994 by RSW
Release 17.06.94 , v. 2.10 (BugFix)
nortom.ini
HLLP.Sarka
It contains (and displays?) the strings:
c:\working\zaloha
c:\working\zaloha\1.1
Dobry den pane jsem vr SARKA a ocitl jsem se spatky na vasem pocitaci.
*.exe *.WINDOWS
\work.exe
WARNING: DANGEROUS SUPER"IR S A R K A
Nazdaaaaaaar zdravy vas pocitacovy supervir S A R K A !
Pro zacatek bych mel pro vas nekolik uzitecnych rad: I
1. v pripade resetnuti pocitace nebo vypnuti vas pocitac okamzite
totalne zlikvyduji (neberte to jako vyhrusku)
2. tento vir je opravdu spicka proto zavirovane soubory nahravejte
svym pratelum a znamym at si tento vir taky vychutnaji
3. nahnete se bliz k pocitaci jsem totiz prenosny i na lidi
po precteni stisknete SPACE
! WARNING !
Opravdu sis myslel ze tvuj pocitac neznicim !
Tak to sis myslel spatne !!!!!!!
sacod.exe COMSPEC
HLLP.Sauron.4568
It contains the text strings:
SAURON 4568
Wielkanocne pozdrowienia sklada Sauron
HLLP.Vova
It is encrypted virus. It contains the strings:
(C) Dialogue, Rust. 1993
vir *.com *.exe COMMAND.COM NCMAIN.EXE EMM386.EXE NC.EXE
\VIR comspec /c ren v /c>nul copy/b \vir /c del
vir?
***ProfVovaVir 10.1 (INVECTOR),Give my best regards to LENA !!!
(c) 1992-94 by Vova of Ufa,11/03/94 (max. probability accident=1/128)***
HLLP.VVC.8304
It contains (and displays?) the strings:
I'm sorry You hawe virus.
My name VVC 13 version 1.0 beta.
Special Thank's auhtor viruses Yeanke Doodle , Lozinsky D.N.
Virus by VVC & RSW release 25.02.94
Copyright @2006 hllc.cp-ma