Home Malware Programs Viruses W95/CIH

W95/CIH

Posted: August 31, 2007

Threat Metric

Threat Level: 7/10
Infected PCs: 11
First Seen: July 24, 2009
OS(es) Affected: Windows

W95/CIH, also known as Chernobyl, is a parasitic family of viruses. W95/CIH was first detected in June 1998 in Taiwan. W95/CIH contains a very dangerous payload, whose trigger date depends on the variant. On this date, the viruses attempt to overwrite the flash-BIOS. If the flash-BIOS is write-enabled (and this is the case in most modern computers with a flash-BIOS) this renders the machine unusable because it will no longer boot. The only way to infect a computer with W95/CIH is to execute an infected file on the computer. The infected file may come from a multitude of sources including floppy diskettes, downloads through an online service, network, etc. Once the infected file is executed, W95/CIH may activate.

W95/CIH

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



malware.exe File name: malware.exe
Size: 110.59 KB (110592 bytes)
MD5: adffb5f04120930b865bcd5c7e185315
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Loading...