Skip to main content

Win95_Caw

Classification

Category:

Malware

Aliases:

  • Win95.Caw

Summary

Caw is a dangerous memory resident Win95/98 virus. When an infected program is run the virus gets control, switches itself from application level (Ring3) to Windows kernel (Ring0), allocates a block of Windows memory, hooks file access functions (IFS API) and stays memory resident as a system VxD driver. The virus then intercepts file opening function and writes itself to the end of PE EXE files that are opened. While infecting a file the virus increases last file section and writes itself to there.

Removal

Technical Details

The virus has a bug and in some cases corrupts files while infecting them. When such files are run they cause a standard Windows message about error in application to appear.

The virus has two dangerous payloads. 1s: on 7th of July on each file opening the virus erases 16 sectors at random position on the drive C:.

If current minutes are equal to 0 the virus deletes the files that are being opened: WINWORD.EXE, and files with extensions:

BMP JPG DOC WRI BAS SAV PDF RTF TXT

The second payload can be 'customized': if there is the file called 'C:\AW' the virus gets file names and extensions from this file, and deletes them.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.