Win95.CIH Spotted In 83PlusAsm v1.01
Posted by Nick on 23 March 2000, 23:37 GMT
Well.. this is a piece of sour news. From bombing the chem test to getting waitlisted at Washington University to this. Last night, a file was added that contained the Win95.CIH virus. THIS FILE WILL CAUSE YOUR SYSTEM TO CEASE FUNCTIONING ON THE 26TH OF ANY MONTH! For those of you who can't tell the emboldened red text apart from everything else, this is a very bad thing. The program was called 83PlusAsm v1.01; it had 255 downloads before we removed it from our archives. If you downloaded this file, do a virus scan of your machine IMMEDIATELY or head to this page to get an online scan of your system. If you have any problems with disinfecting your system, head over to this page or email me. DO THIS PROMPTLY - Win95.CIH WILL RENDER YOUR MACHINE INOPERABLE AFTER MARCH 26TH! We apologize for any problems this may cause anyone. Any other TI sites - scan your systems if you added this file. Once again, if you have ANY problems with getting this virus off your computer, email me and I'll try to make my response as prompt as possible. Update (Nick): An esteemed colleague, David Hall, has informed me of a free virus scanner with free updates. You can find a copy of it here. Update (Nick): Another kind-hearted person, Matt, has given me the linkage to a disk recovery tool called SpinRite. This can even be used after the virus goes off. I don't know how much it can help people, but it's there. (Updated with correct link)
|
|
|
The comments below are written by ticalc.org visitors. Their views are not necessarily those of ticalc.org, and ticalc.org takes no responsibility for their content.
|
|
Information about Win95.CIH
|
David Hall
(Web Page)
|
Copied and pasted...
CIH (Also known as Win95.CIH, Spacefiller or Chernobyl)
There are 3 known variants of the CIH virus - all have the same payload but each is triggered on a different date/set of dates:
* Win95.CIH.1003 - Triggers on the 26th of April
* Win95.CIH.1010 - Triggers on the 26th of June
* Win95.CIH.1019 - Triggers on the 26th of every month
The CIH virus infects PE files only under Windows 95/98 i.e. it infects Windows 95/98-only executable files of the PE format, usually 32 bit executables with the .exe extension. (i.e. notepad.exe, explorer.exe, winword.exe etc).
The virus shows very few symptoms as it is clever in its ability to infect files without increasing their length. It may also cause system crashes, although since it is relatively bug free, the virus can spread and remain unnoticed for some time.
The virus has a nasty payload, consisting of 2 parts:
1) The virus tries to destroy the flash BIOS ROM by reprogramming it with garbage. This does not always work.
2) The virus overwrites the contents of the hard disk with garbage, working through a number of sectors of each cylinder of the hard disk.
If the virus succeeds in reprogramming the flash BIOS ROM, there is no software remedy for it: your PC will no longer be bootable and the flash BIOS will need to be replaced or reprogrammed in a special EPROM programming device. Where the flash BIOS ROM is permanently attached to the motherboard, the entire motherboard will need replacing. The damage caused to the information on the hard disk is possibly recoverable by using data recovery services, and the success depends on the disk size, format, fragmentation etc.
|
|
25 March 2000, 11:48 GMT
|
|
Slight revision
|
Matt Hockenheimer
(Web Page)
|
Spinright isn't the CIH recovery utility, spinrite is actually a disk maintnance utility found at the same site. For the address to the CIH part of the site, click the URL above
|
|
26 March 2000, 18:08 GMT
|
|
Re: Win95.CIH Spotted In 83PlusAsm v1.01
|
Jmstuckm
|
Here is what you need to do: If you still have the virus, the mcafee boot disk you make may not work(unless you made it before you got the virus.) I would go to a friend's computer and install virusscan and make a boot disk from there. Then write-protect the diskette and use that to disinfect. If that doesn't work or mcaffee won't remove the virus, download f-prot from ftp.complex.is(f-prot is a good freeware virus scanner). Then download nomacro.def from that site. Delete the macro.def file and all of the documention files (read the documention first though), and rename nomacro.def to macro.def and put it in with f-prot (macro.def is only for removing msword viruses and nomacro.def is much much smaller). This will make f-prot small enough to fit on a diskette. Then make a boot disk(format a disk with the 'copy system files' checked). Then you can boot your computer with the boot disk, then switch to the f-prot disk and run f-prot with no danger of the virus coming into the program. Remeber, EVERY step of creating these diskettes(even downloading f-prot) must be done on a totally clean computer! Otherwise the virus could interfere and infect the virus scanner.
|
|
27 March 2000, 19:05 GMT
|
|
1 2 3 4 5 6
You can change the number of comments per page in Account Preferences.
|