Virus Database


Win95.Dodo

Description Win95.Dodo

It is not a dangerous memory resident parasitic virus. It replicates under Win9x systems only. Known virus version does not infect WinME systems because of a bug.
The virus stays in Windows memory as a component of KERNEL32.DLL system library, patches KERNEL32 addressed to install its hook on file opening calls, and then infects PE EXE and DLL files that are opened.
While infecting a file the virus writes itself to "caves" in file body, if there are such ones. The infection method looks similar to the "Win95.CIH" virus: the virus body is split to blocks that are stored at the end of PE sections, if there are "caves" of enough size.
Starting from 2001 on 1st day of each month the virus sets the system date to 1981.
The virus contains the text strings:
Dodo 1.2

Check other viruses! Be aware! Use Antiviral Software

Promis

Description Promis

This is a dangerous memory resident polymorphic virus. It writes itself to the end of COM and EXE files. It hooks INT 21h and infects the files that are executed or opened. The virus does not infect files: SC*, TB*, WI*, PE*, TH*, VI*, CH*, PR*
The virus deletes anti-virus CRC database files and other programs with names: ANTI-VIR.DAT, CHKLIST .MS, CHKLIST.MS, THIMAGEN.ARC, ACUARIO.SEX, TH.RPT.
The virus contains never used text:
pRoMiScUo ViRuS DeDiCaDo A ToDaS MiS MuJeReS!!

Protect Family

Description Protect Family

These are dangerous memory resident parasitic viruses. They hook INT 21h and 1Ch or 33h depending on their versions, and then write themselves to the end of COM and EXE files that are executed.
"Protect.1157,1196" clear the file attributes and corrupt the mouse driver
(in the memory). "Protect.1355" manifests itself by a small and very
disgusting screen trembling.

The viruses contain the text:
File protection

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com