CIH (computer virus)

CIH
Antivirus intercept message on a Windows 95 system

CIH, also known as Chernobyl or Spacefiller, is a Microsoft Windows 9x computer virus that first emerged in 1998. Its payload is highly destructive to vulnerable systems, overwriting critical information on infected system drives and, in some cases, destroying the system BIOS. The virus was created by Chen Ing-hau (陳盈豪, pinyin: Chén Yíngháo), a student at Tatung University in Taiwan.[1] It was believed to have infected sixty million computers internationally, resulting in an estimated NT$1 billion (US$35,801,231.56) in commercial damages.[1]

Chen claimed to have written the virus as a challenge against bold claims of antiviral efficiency by antivirus software developers.[2] Chen stated that after classmates at Tatung University spread the virus, he apologized to the school and made an antivirus program available for public download. Weng Shi-hao (翁世豪), a student at Tamkang University, co-authored with the antivirus program.[2] Prosecutors in Taiwan could not charge Chen at the time because no victims came forward with a lawsuit.[3] Nevertheless, these events led to new computer crime legislation in Taiwan.[2]

The name "Chernobyl Virus" was coined sometime after the virus was already well known as CIH and refers to the complete coincidence of the payload trigger date in some variants of the virus (actually the virus creation date in 1998, to trigger exactly a year later) and the Chernobyl disaster, which happened in the Soviet Union on April 26, 1986.[4]

The name "Spacefiller" was introduced because most viruses write their code to the end of the infected file, with infected files being detectable because their file size increases. In contrast, CIH looks for gaps in the existing program code, where it then writes its code, preventing an increase in file size; in that way, the virus avoids detection.[4]

History

The virus first emerged in 1998. In March 1999, several thousand IBM Aptivas shipped with the CIH virus,[5] just one month before the virus would trigger. In July 1999, copies of remote administration tool Back Orifice 2000 given out to DEF CON 7 attendees were discovered by the organizers to have been infected with CIH.[6] On December 31, 1999, Yamaha shipped a software update to their CD-R400 drives that was infected with the virus. In July 1998, a demo version of the first-person shooter game Sin was infected by one of its mirror sites.[7]

CIH's dual payload was delivered for the first time on April 26, 1999, with most of the damage occurring in Asia.[8] CIH filled the first 1024 KB of the host's boot drive with zeros and then attacked certain types of BIOS. Both of these payloads served to render the host computer inoperable, and for most ordinary users, the virus essentially destroyed the PC. Technically, however, it was possible to replace the BIOS chip,[citation needed] and methods for recovering hard disk data emerged later.[citation needed]

Today, CIH is not as widespread as it once was, due to awareness of the threat and the fact that it only affects older Windows 9x (95, 98, ME) operating systems.

The virus made another comeback in 2001 when a variant of the LoveLetter Worm in a VBS file that contained a dropper routine for the CIH virus was circulated around the internet under the guise of a nude picture of Jennifer Lopez.

A modified version of the virus called CIH.1106 was discovered in December 2002, but it is not widespread and only affects Windows 9x-based systems.[9]

Virus specifics

CIH spreads under the Portable Executable file format under the Windows 9x-based operating systems, Windows 95, 98, and ME. CIH does not spread under Windows NT-based operating systems nor Win16-based operating systems such as Windows 3.x or below.[10]

CIH infects Portable Executable files by splitting the bulk of its code into small slivers inserted into the inter-section gaps commonly seen in PE files and writing a small re-assembly routine and table of its own code segments' locations into unused space in the tail of the PE header. This earned CIH another name, "Spacefiller". The size of the virus is around 1 kilobyte, but due to its novel multiple-cavity infection method, infected files do not grow at all. It uses methods of jumping from processor ring 3 to 0 to hook system calls.

The payload, which is considered extremely dangerous, first involves the virus overwriting the first megabyte (1024KB) of the hard drive with zeroes, beginning at sector 0. This deletes the contents of the partition table, and may cause the machine to hang or cue the blue screen of death.

The second payload tries to write to the Flash BIOS. BIOSes that can be successfully written to by the virus have critical boot-time codes replaced with junk. This routine only works on some machines. Much emphasis has been put on machines with motherboards based on the Intel 430TX chipset, but by far the most important variable in CIH's success in writing to a machine's BIOS is the type of Flash ROM chip in the machine. Different Flash ROM chips (or chip families) have different write-enable routines specific to those chips. CIH makes no attempt to test for the Flash ROM type in its victim machines and has only one write-enable sequence.

For the first payload, any information that the virus has overwritten with zeros is lost. If the first partition is FAT32, and over about one gigabyte, all that will get overwritten is the MBR, the partition table, the boot sector of the first partition and the first copy of the FAT of the first partition. The MBR and boot sectors can simply be replaced with copies of the standard versions; the partition table can be rebuilt by scanning over the entire drive and the first copy of the FAT can be restored from the second copy. This means a complete recovery with no loss of user data can be performed automatically by a tool like Fix CIH.

If the first partition is not FAT32 or is smaller than 1 GB, the bulk of user data on that partition will still be intact, but without the root directory and FAT it will be difficult to find it, especially if there is significant fragmentation.

If the second payload executes successfully, the computer will not start at all. Reprogramming or replacement of the Flash BIOS chip is then required, as most systems that CIH can affect predate BIOS restoration features.

Variants

Moniker Description
CIH v1.2/CIH.1003 This variant is the most common one and activates on April 26. It contains the string: CIH v1.2 TTIT
CIH v1.3/CIH.1010.A and CIH1010.B This variant also activates on April 26. It contains the string: CIH v1.3 TTIT
CIH v1.4/CIH.1019 This variant activates on the 26th of any month. It contains the string CIH v1.4 TATUNG.
CIH.1049 This variant activates on August 2 instead of April 26.

See also

References

  1. ^ a b "從CIH「重裝駭客」變身「除錯超人」". iThome online (in Chinese). 2006-08-25. Archived from the original on 2013-04-17.
  2. ^ a b c "從駭電腦到愛旅行─昔日網路小子陳盈豪 - 親子天下雜誌8期 - 陳盈豪,網路世界,宅男,網路沉迷". parenting.com.tw (in Chinese). 2013-06-07. Archived from the original on 2013-06-07.
  3. ^ "打擊駭客,不再無法可施 - 安全常識 - 法務部行政執行署嘉義分署" (in Chinese). 行政執行署嘉義行政執行處. 2005-12-10. Archived from the original on 2013-10-29.
  4. ^ a b "What is the Chernobyl Virus? (with pictures)". Easy Tech Junkie. Retrieved 2023-02-16.
  5. ^ Weil, Nancy (1999-04-07). "Some Aptivas shipped with CIH virus". CNN. Archived from the original on 2007-01-04.
  6. ^ "Back Orifice CDs infected with CIH virus - Tech News on ZDNet". ZDNet. July 14, 1999. Archived from the original on 2007-03-11.
  7. ^ "US Report: Gamers believe Activision's 'SiN' carries CIH virus". ZDNet.co.uk. 28 Jul 1998. Archived from the original on 2009-04-17.
  8. ^ Lemos, Robert (May 25, 1999). "Is the CIH virus on the endangered list?".
  9. ^ "Virus:DOS/CIH". F-Secure Labs. Archived from the original on 2001-01-28. Retrieved 2021-12-07.
  10. ^ "Virus:DOS/CIH | F-Secure Labs". www.f-secure.com. Retrieved 2023-11-05.

Read other articles:

Questa voce sull'argomento contee del Wisconsin è solo un abbozzo. Contribuisci a migliorarla secondo le convenzioni di Wikipedia. Contea di MarathonconteaLocalizzazioneStato Stati Uniti Stato federato Wisconsin AmministrazioneCapoluogoWausau Data di istituzione1850 TerritorioCoordinatedel capoluogo44°57′33″N 89°37′48″W / 44.959167°N 89.63°W44.959167; -89.63 (Contea di Marathon)Coordinate: 44°57′33″N 89°37′48″W / 44.9591...

 

Cinema ofBrazil List of Brazilian films Brazilian Animation Pre 1920 1920s 1930s 1930 1931 1932 1933 19341935 1936 1937 1938 1939 1940s 1940 1941 1942 1943 19441945 1946 1947 1948 1949 1950s 1950 1951 1952 1953 19541955 1956 1957 1958 1959 1960s 1960 1961 1962 1963 19641965 1966 1967 1968 1969 1970s 1970 1971 1972 1973 19741975 1976 1977 1978 1979 1980s 1980 1981 1982 1983 19841985 1986 1987 1988 1989 1990s 1990 1991 1992 1993 19941995 1996 1997 1998 1999 2000s 2000 2001 2002 2003 20042005 2...

 

Siwaluh Jabu, rumah tradisional masyarakat Karo dengan beberapa geriten di Kabanjahe, Sumatera Utara. Artikel ini adalah bagian dari seriAgama asli Nusantara Sumatra Ugamo Malim • Pemena • Arat Sabulungan • Fanömba adu • Melayu Jawa Sunda Wiwitan (Madraisme & Buhun) • Kapitayan • Kejawen • Hindu Jawa • Saminisme Nusa Tenggara Hindu Bali • Halaika • Wetu Telu • Marapu • Jingi Tiu • Koda Kirin �...

У этого термина существуют и другие значения, см. Маша и медведь (значения). Маша и Медведь Почтовая марка России, 2019 год Жанр мультсериал Техника анимации компьютерная Создатель Олег Кузовков На основе Маша и Медведь[d] Режиссёры Олег КузовковОлег УжиновОльга БаулинаВ...

 

Election in Vermont Main article: 1828 United States presidential election 1828 United States presidential election in Vermont ← 1824 October 31 – December 2, 1828 1832 →   Nominee John Quincy Adams Andrew Jackson Party National Republican Democratic Home state Massachusetts Tennessee Running mate Richard Rush John C. Calhoun Electoral vote 7 0 Popular vote 25,363 8,350 Percentage 75.23% 24.77% County Results Adams  50-60%  ...

 

追晉陸軍二級上將趙家驤將軍个人资料出生1910年 大清河南省衛輝府汲縣逝世1958年8月23日(1958歲—08—23)(47—48歲) † 中華民國福建省金門縣国籍 中華民國政党 中國國民黨获奖 青天白日勳章(追贈)军事背景效忠 中華民國服役 國民革命軍 中華民國陸軍服役时间1924年-1958年军衔 二級上將 (追晉)部队四十七師指挥東北剿匪總司令部參謀長陸軍�...

2002 UCI Road World ChampionshipsLimburgShow map of BelgiumLimburgShow map of EuropeVenueLimburg, BelgiumDate(s) (2002-10-08 - 2002-10-13)8–13 October 2002Coordinates50°58′38.6″N 5°16′43.8″E / 50.977389°N 5.278833°E / 50.977389; 5.278833Events10← 20012003 → The 2002 UCI Road World Championships took place in the region of Limburg, Belgium, between 8 and 13 October 2002. The event consisted of a road race and a time trial for...

 

French director and screenwriter You can help expand this article with text translated from the corresponding article in French. (April 2012) Click [show] for important translation instructions. View a machine-translated version of the French article. Machine translation, like DeepL or Google Translate, is a useful starting point for translations, but translators must revise errors as necessary and confirm that the translation is accurate, rather than simply copy-pasting machine-translat...

 

Qualifying competition to the German Cup Football tournamentBavarian CupFounded1998; 26 years ago (1998)RegionBavariaNumber of teams64Current championsFV Illertissen (2022–23)Most successful club(s)Jahn Regensburg (7 titles) The Bavarian Cup (German: Bayerischer Toto-Pokal), was created in 1998 and functions as a qualifying competition to the German Cup. It is one of the 21 regional cups in Germany. It is one of three regional associations who are permitted to send two ama...

本條目存在以下問題,請協助改善本條目或在討論頁針對議題發表看法。 此條目需要編修,以確保文法、用詞、语气、格式、標點等使用恰当。 (2013年8月6日)請按照校對指引,幫助编辑這個條目。(幫助、討論) 此條目剧情、虛構用語或人物介紹过长过细,需清理无关故事主轴的细节、用語和角色介紹。 (2020年10月6日)劇情、用語和人物介紹都只是用於了解故事主軸,輔助�...

 

American department store chain This article is about the department store chain. For its founder, see James Cash Penney. For the Irish retail chain branded Penneys, see Primark. Penney OpCo LLCJCPenney store at Aventura Mall in 2006Trade nameJCPenneyFormerlyJ. C. Penney Company, Inc.Company typeJoint ventureTraded asNYSE: JCP (1927–2020)OTC Pink: JCPNQ (May 2020–January 2021)OTC Pink: CPPRQ (as Old COPPER Company, Inc, January–February 2021)IndustryRetailFoundedApril 14, 1902...

 

.pm

Internet country code top-level domain for Saint Pierre and MiquelonThis article is about the top level domain. For the file extension, see Perl module..pmIntroduced20 August 1997TLD typeCountry code top-level domainStatusActiveRegistryAFNICSponsorAFNICIntended useEntities connected with  Saint Pierre and MiquelonActual useSees rare use, most of which is not related to Saint Pierre and MiquelonRegistration restrictionsRegistrant must reside in the European Economic Area or in Switzerland...

Leon Conrad (born 15 September 1965) is a British polymath: writer, story structure consultant, educator, and specialist in historic needlework techniques known particularly for historically-styled blackwork embroidery designs. Early life and education Conrad was born in London. He grew up in Putney, attended Willington School for a year before moving to Alexandria, Egypt where he first attended El Nasr Girls' College and then Victoria College, Alexandria. He moved back to the UK in 1983, st...

 

جنديين فرنسيين في المشاة الاستعمارية ينزلون في مدغشقر عام 1895 ملصق تجنيدي للكتائب الاستعمارية لقوات فرنسا الحرة مدفع 75 مم لفرنسا الاستعمارية في الاستخدام قرب سد البحر، جاليبولي 4 يونيو 1915 الكونغو الفرنسية، حوالي 1905: مناوش استعماري يرتدي الزي الأزرق للمهندس كانت الكت�...

 

Chinese educator and statesman (1868–1940) In this Chinese name, the family name is Cai. Cai Yuanpei蔡元培President of the Control YuanIn office1928–1929Preceded byOffice establishedSucceeded byZhao Daiwen [zh]President of the Academia SinicaPreceded byOffice establishedSucceeded byZhu Jiahua Personal detailsBorn11 January 1868 (1868-01-11)Shaoxing, Zhejiang, Qing dynastyDied5 March 1940 (1940-03-06) (aged 72)British Hong KongSpouses Wang Zhao ​ &#...

June 2011 ini tidak memiliki referensi atau sumber tepercaya sehingga isinya tidak bisa dipastikan. Tolong bantu perbaiki artikel ini dengan menambahkan referensi yang layak. June 2011 ini akan dihapus bila tidak tersedia referensi ke sumber tepercaya dalam bentuk catatan kaki atau pranala luar. Wong Fei-hungLahir(1847-07-09)9 Juli 1847 Foshan, GuangdongMeninggal25 Maret 1924(1924-03-25) (umur 76) Guangzhou, GuangdongsakitNama Lain黃飛鴻KebangsaanDinasti Qing, TiongkokGayaHung GarGuru...

 

Species of lily Lilium columbianum Mount Baker-Snoqualmie National Forest Scientific classification Kingdom: Plantae Clade: Tracheophytes Clade: Angiosperms Clade: Monocots Order: Liliales Family: Liliaceae Subfamily: Lilioideae Tribe: Lilieae Genus: Lilium Species: L. columbianum Binomial name Lilium columbianumLeichtlin 1871 not Hanson 1874 Synonyms[1] Synonymy Lilium canadense var. minus Alph.Wood Lilium canadense var. walkeri Alph.Wood Lilium californicum Duch. Lilium sayi Nu...

 

2024 film by Nicole Riegel DandelionTheatrical release posterDirected byNicole RiegelWritten byNicole RiegelProduced by Rian Cahill Adam Cobb Pete McClellan Nicole Riegel Starring KiKi Layne Thomas Doherty Melanie Nicholls-King Brady Stablein Jack Stablein Grace Kaiser CinematographyLauren GuiterasEdited byMilena Z. PetrovicMusic by Bryce Dessner Aaron Dessner Productioncompanies IFC Productions Automatik Entertainment BondIt Media Capital Griffin Drive Productions Room 252 Distributed byIFC ...

Opisthostoma lituusDrawing of the shell of Opisthostoma lituus.Phân loại khoa họcGiới (regnum)AnimaliaNgành (phylum)MolluscaLớp (class)GastropodaHọ (familia)DiplommatinidaeChi (genus)OpisthostomaPhân chi (subgenus)PlectostomaLoài (species)O. lituusDanh pháp hai phầnOpisthostoma lituus Opisthostoma lituus là một loài air-breathing land snail với một nắp, a terrestrial gastropoda mollusca nằm trong họ Diplommatinidae. Phân bố Borneo[1] Chú thích ^ Men...

 

Artikel ini tidak memiliki referensi atau sumber tepercaya sehingga isinya tidak bisa dipastikan. Tolong bantu perbaiki artikel ini dengan menambahkan referensi yang layak. Tulisan tanpa sumber dapat dipertanyakan dan dihapus sewaktu-waktu.Cari sumber: Nomor telepon di Italia – berita · surat kabar · buku · cendekiawan · JSTOR Berikut adalah kode-kode telepon di Italia oleh Telecom Italia: Zona 1 - Liguria, Piedmont, dan Aosta Valley 010 – Kota Genoa...