[LINUX:5603] CIH

Umit GULER (guler@yok.gov.tr)
Tue, 27 Apr 1999 08:59:46 +0300 (EET DST)

Name: CIH
Type: Resident EXE-files
Alias: PE_CIH, CIHV, SPACEFILLER
Origin: Taiwan

CIH virus infects Windows 95 and 98 EXE files. After an infected EXE is
executed, the virus will stay in memory and will infect other programs as
they are accessed.

The CIH virus was first located in Taiwan in early June. After that, it has
been confirmed to be in the wild in at least France, Germany, The
Netherlands, Sweden, China, Israel, Chile and Australia. CIH has been
spreading very quickly as it has been distributed through pirated software.

It seems that at least four underground pirate software groups got infected
with the CIH virus, and they inadvertently spread the virus globally in new
pirated softwares they released through their own channels. These releases
include some new games which will spread world-wide very quickly. There's
also a persistent rumor about a 'PWA-cracked copy' of Windows 98 which would
be infected by the CIH virus but Data Fellows has been unable to confirm
this.

What makes the CIH case really serious is that the virus activates
destructively. When it happens the virus overwrites most of the data on the
computers hard drive. This can be recovered with recent backups.

However, the virus has another, unique activation routine: It will try to
overwrite the Flash BIOS chip of the machine. If this succeeds, the machine
will be unable to boot at all unless the chip is reprogammed. The Flash
routine will work on many types of Pentium machines - for example, on
machines based on the Intel 430TX chipset. On most machines, the Flash BIOS
can be protected with a jumper. By default, protection is usually off.

The CIH virus infects Windows executable files (EXE files). It does not
infect Word or Excel documents. CIH works under both Windows 95 and Windows
98, but it does not work under Windows NT.

CIH uses a peculiar way of infecting executables. As a result, the size of
the infected files does not grow at all. The actual size of the virus code
is around 1 kB. The virus also employees advanced tricks in jumping from
processor ring 3 to ring 0 in order to hook file system calls.

There are four known closely-related variants:

CIH v1.2 (CIH.1003): Activates on April 26th. This is the most common
variant. It contains this text:

CIH v1.2 TTIT

CIH v1.3 (CIH.1010.A and CIH.1010.B): Activates on June 26th. Contains this
text:

CIH v1.3 TTIT

CIH v1.4 (CIH.1019): Activates on 26th of every month. It is in the wild,
but not particularily common. It contains this text:

CIH v1.4 TATUNG

[Mikko Hypponen/Data Fellows]


Listeden cikmak icin:
unsub linux
mesajini listeci@bilkent.edu.tr'a gonderiniz.
Lutfen Listeci icin MIME / HTML / Turkce Aksan kullanmayin.
Liste arsivinin adresi: http://listweb.bilkent.edu.tr/