hllc.dope.487
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
HLLC.Dope.4870
These are companion viruses written in the C language and compiled with Borland C++ ver 3.0. The viruses were also packed by virus author with PKLite executable file compressor to decrease the virus size.
When an infected file is executed, the virus gets PATH environment variable, randomly selects one of directories listed there, and infects one EXE file in selected directory. While infecting the virus creates the companion .COM file with archive and hidden attributes set, and writes its code to there. The virus then runs the host .EXE file to return control to the host program.
The "Dope.4879" virus is harmless one and does not manifest itself in any way.
The "Dope.5219" is a dangerous virus. Depending on the random counter it overwrites the EXE files with a program that displays the message, when overwritten file is executed:
General failure reading drive
Abort, Retry, Fail?
This virus also contains the text "DOPE By KiLLeRbYtE". The virus checks this string, and in case it is modified (replaced with another text string), it displays the word "Fuk" and immediately exits (with no infection and no host file execution).
Copyright @2006 hllc.dope.487