Author Topic: Win95:CIH-ASP virus  (Read 4327 times)

0 Members and 1 Guest are viewing this topic.

centrum

  • Guest
Win95:CIH-ASP virus
« on: August 04, 2006, 12:00:56 PM »
Hello,

I have downloaded and installed  avast!Home Edition , registered it, download virusbase update. Then clicked desktop shortcut to avast!, and starts memory scanner.
It show, almost at once, that I infected with Win95:CIH-ASP virus, in c:\windows\notepad.exe.
I can no open notepad, since avast! block it. I've noticed no any oddities in PC behaviour before, include notepad.

What is actions I need to do and where is description of this virus? (if virus have name, it was investigated, however, description must be also)
What files it damaged, etc?

thanks.
« Last Edit: August 04, 2006, 12:02:42 PM by centrum »

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Win95:CIH-ASP virus
« Reply #1 on: August 04, 2006, 01:08:18 PM »
It's most likely really infected. Location is right and it's most certanly not a false positive on something as common as notepad.
Visit my webpage Angry Sheep Blog

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Win95:CIH-ASP virus
« Reply #2 on: August 04, 2006, 01:34:15 PM »
Hi centrum,

If it was Chernobyl variant = Virusinfo: CIH of PE_CIH virus

These seems to be a very nasty virus. It overwrites the flash BIOS of your computer, after which the supplier has to set it anew. Or it reformats your hard disk. Give in after a  DOS-prompt:

        CURE C:


an your C: disk is checked for this virus.

In your case the Win95: CIH-ASP is a "dropper", and can be removed by deleting this file: cih_13.exe

polonus
« Last Edit: August 04, 2006, 01:41:32 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

centrum

  • Guest
Re: Win95:CIH-ASP virus
« Reply #3 on: August 04, 2006, 03:29:41 PM »
Hi polonus,

I've installed avast! only yesterday night, just haven't time enough to learn all scanning features.
Should I do full scanning? How get rid of this specific virus? To check C drive for virus, I need from DOS?
(boot in DOS mode?)

centrum

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Win95:CIH-ASP virus
« Reply #4 on: August 04, 2006, 03:33:33 PM »
You could also check the offending/suspect file to confirm the detection is good at: VirusTotal - Multi engine on-line virus scanner
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. You can't do this with the file in the chest, you will need to move it out.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

centrum

  • Guest
Re: Win95:CIH-ASP virus
« Reply #5 on: August 05, 2006, 12:28:15 AM »
Got the following scanning results(online scanner):

Antivirus   Version   Update   Result
AntiVir   6.35.1.0   08.04.2006   TR/FlashKiller.C
Authentium   4.93.8   08.04.2006    no virus found
Avast   4.7.844.0   08.04.2006   Win95:CIH-ASP
AVG   386   08.04.2006    no virus found
BitDefender   7.2   08.04.2006    no virus found
CAT-QuickHeal   8.00   08.04.2006    no virus found
ClamAV   devel-20060426   08.04.2006   W32.CIH.1003
DrWeb   4.33   08.04.2006    no virus found
eTrust-InoculateIT   23.72.86   08.03.2006    no virus found
eTrust-Vet   12.6.2324   08.04.2006   Win32/CIH!remnants
Ewido   4.0   08.04.2006    no virus found
Fortinet   2.77.0.0   08.04.2006   suspicious
F-Prot   3.16f   08.04.2006    no virus found
F-Prot4   4.2.1.29   08.04.2006    no virus found
Ikarus   0.2.65.0   08.04.2006   W95.Cih.1003
Kaspersky   4.0.2.24   08.04.2006    no virus found
McAfee   4822   08.04.2006    no virus found
Microsoft   1.1508   08.04.2006    no virus found
NOD32v2   1.1692   08.04.2006    no virus found
Norman   5.90.23   08.04.2006    no virus found
Panda   9.0.0.4   08.04.2006    no virus found
Sophos   4.08.0   08.04.2006   W95/CIH-10xx
Symantec   8.0   08.04.2006   W95.CIH.damaged
TheHacker   5.9.8.186   08.04.2006 no virus found
UNA         

Aditional Information:

File size: 34304 bytes
MD5: 90a0732a7ed62ea44e19e848b5c288b6
SHA1: 33f0fd5e5fc1fcc8a7cc603e55453750246e7490

8 antivirus show virus.  What is the way to remove virus?
« Last Edit: August 05, 2006, 12:32:00 AM by centrum »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Win95:CIH-ASP virus
« Reply #6 on: August 05, 2006, 01:25:02 AM »
I'm not sure that you can repair it, moving it to the chest and trying to get a replacement notepad.exe may be the easiest option.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security