Virus.Win9x.CIH - removal process

  Рет қаралды 278,346

danooct1

danooct1

Күн бұрын

Пікірлер
@deterdettol
@deterdettol 8 жыл бұрын
Very interesting. Back in 1999, when CIH infected our family computer, now I understand why our anti-virus kept finding so many infected files, and multiple scans didn't work. My dad had no choice but to boot into DOS and executed all the tools on command line to eradicate the infection. Just want to confirm if it is possible instead to boot to DOS to run the tools instead of running it on Windows. Thanks Danooct1, you have outdone yourself once again with an extremely informative and entertaining video.
@ZRZK2127
@ZRZK2127 8 жыл бұрын
+James Chan i loved how you let us know it was your dad that did it. it's like i'm back in the 90s and the family computer got infected and dad has to fix it
@deterdettol
@deterdettol 8 жыл бұрын
+Zero Ziat Actually, we don't know who did it. A couple of people were using it and were downloading stuff from people's emails and the Internet. My dad was quite good with the computer, so he cleaned up the mess.
@ZRZK2127
@ZRZK2127 8 жыл бұрын
+James Chan the same happened in my house! hahaha
@OctoomyYTOfficial
@OctoomyYTOfficial 2 жыл бұрын
That family computer got lucky
@Bisqwit
@Bisqwit 8 жыл бұрын
Very nice video. Your style of narration is also easy and pleasant to listen to. Good job!
@StevePro121
@StevePro121 8 жыл бұрын
+Bisqwit wait... you are the same guy who created a recreation of doom in C?
@Bisqwit
@Bisqwit 8 жыл бұрын
+Elmo64 Yup.
@cldgonz
@cldgonz 8 жыл бұрын
+Bisqwit didnt expect to see you in this vid lol
@Lunascaped
@Lunascaped 8 жыл бұрын
Bisqwit dannoct1 is bob ross confirmed?!
@Microsoft-Windows
@Microsoft-Windows 6 жыл бұрын
+Bisqwit Found you again in a comment haha :)
@Shortninja66
@Shortninja66 8 жыл бұрын
3:38 *says you need to change the date far away from 26 april* *changes date to 20 april* lmao
@trance_vortex
@trance_vortex 8 жыл бұрын
Blaze it!
@sixfr0nt
@sixfr0nt 7 жыл бұрын
a veeerrry special day, lmao
@add3685
@add3685 5 жыл бұрын
Best date to avoid CIH: April 27
@DJRY360
@DJRY360 4 жыл бұрын
But my birthday is April 26
@xxEzraBxxx
@xxEzraBxxx 4 жыл бұрын
4-20
@awesomegamer31
@awesomegamer31 8 жыл бұрын
I love this high production value post commentary you've sort of done. Great work Dan! Hope to see more of this genre in the future.
@GDNachoo
@GDNachoo 7 жыл бұрын
verbose convertor?
@NetRolller3D
@NetRolller3D 6 жыл бұрын
Interesting sidenote: HDDs formatted with newer utilities (those supporting Advanced Format) are mostly impervious to CIH. These new utilities put the 1st partition at sector 2048 instead of 63 to ensure alignment, so all that needs to be done after a CIH attack is a simple MBR rebuild (since the first 1MB is left clear, except for the MBR).
@JMC_90
@JMC_90 8 жыл бұрын
No fucking way, I had this when I was younger, My BIOS wasn't deleted and the machine continued to boot into windows, but that green bar at the top would appear when I visited certain websites, tried to watch video, listen to music, files would stop working etc.. The computer would then hang until I pressed the reset button and start again. I tested the hardware thinking it might have been a graphics error but no such luck, It would still happen in safe mode etc, eventually got a hold of my 98 disc and reinstalled completely and the problem was fixed, so couldn't have been hardware.. Is it possible there where variations of this virus or does it just affect different systems in different ways? EDIT: At 2:35 the screen has a green a bar at the top with distorted purple pixels, this is exactly the way my screen would go the second I ran pretty much anything.
@xxxprogamerxxx5909
@xxxprogamerxxx5909 5 жыл бұрын
Jamie McG you didnt even edited your fucking comment
@tristan6509
@tristan6509 5 жыл бұрын
@@xxxprogamerxxx5909 KZbin didn't record if a comment is edited until 1-2 years ago...
@ibapreppie
@ibapreppie 4 жыл бұрын
@@xxxprogamerxxx5909 Neither did you
@ChanceOfOne344254
@ChanceOfOne344254 Жыл бұрын
As far as I know, the other CIH variants primarily affected payload dates, and not the payload itself. It's possible you were infected with a different virus, it may have been something like the virus CAW, because that virus would cause the distorted line lock up when you run programs. However it is possible you had a variant that hasn't been documented and which didn't perform payloads correctly and/or altered them.
@mxl12
@mxl12 8 жыл бұрын
Allthough no one will be struck by CIH unintentionally these days it is still a great prove of concept, knowing how destructive it was back then.This reminds me of picking up an old video game from your childhood and finally beat the endboss which you never managed to when you were young. Even though none of your friends will take about the game anymore and value your success it is still an important achievement for your ego.If you can beat CIH Dan you will probably do so with many viruses to come. That is why I am subscribed to your channel :)
@dragonsky2884
@dragonsky2884 8 жыл бұрын
Why did your videos suddenly become more professional? Your voice is clearer, you talk more fluently,calmly and in a warm tone, and the footage is more high-quality than usual... Me likes it.
@UltimateTMGModder
@UltimateTMGModder 8 жыл бұрын
No dislikes, well deserved. You're awesome Dan I love watching these videos and it's shown me a lot about viruses. Keep it up
@Ryanlf999
@Ryanlf999 8 жыл бұрын
Agreed 100 %!
@sciencemkid
@sciencemkid 8 жыл бұрын
Oh shit 5! :(
@sciencemkid
@sciencemkid 8 жыл бұрын
Still good video :)
@darofleciarz
@darofleciarz 2 жыл бұрын
No dislikes, true!...
@SmeddyTooBestChannel
@SmeddyTooBestChannel 8 жыл бұрын
Now do the process of reflashing the BIOS with only the technology at the time. ;)
@sevencinderblocks
@sevencinderblocks 8 жыл бұрын
rip danoct1
@xanlord2k
@xanlord2k 8 жыл бұрын
unsolder the bios chip, put another one and force an update via ms-dos and hotswap the old chip. simple.
@SireSquish
@SireSquish 8 жыл бұрын
+OH MY GOD!!! So try to find a similar board with a similar chip. They don't necessarily have to be identical.
@8bits59
@8bits59 6 жыл бұрын
...so order a new BIOS chip from the manufacturer? They were almost all socketed at this point in time
@AwesumIndustrys
@AwesumIndustrys 4 жыл бұрын
So spend hundreds of dollars on an EEPROM writer and somehow find a clean copy of the BIOS to flash it with?
@kitanaisunshine1057
@kitanaisunshine1057 8 жыл бұрын
Great work! I love how you sound so happy throughout the video. That just makes it even more fun to watch :D
@Exachad
@Exachad 8 жыл бұрын
You finally made the vid. I have been waiting for 4 years now.
@NickRosaci
@NickRosaci 8 жыл бұрын
I just came across your videos yesterday. This is really interesting stuff! I've always wanted to see a virus in action, but not on my own computer, of course. I've always wondered about the viruses that cause physical damage to the computers, so I'll be looking for those. It's also really interesting that these viruses still break out of the virtual operating systems to cause real damage. Old, obsolete viruses still able to infect new computers--really cool.
@davyvangeerke5826
@davyvangeerke5826 8 жыл бұрын
Hey! I only just found your channel a few days ago and you make some really interesting videos that are super fun to watch! I was just wondering what field you specialised in? or what course you studied in order to have such a good understanding of all this. Love the channel dude!!
@aaronlindros6048
@aaronlindros6048 8 жыл бұрын
Did you change the date to 4/20 on purpose?
@AbRaSkZo
@AbRaSkZo 8 жыл бұрын
say this to Druaga1
@Brorrowind
@Brorrowind 8 жыл бұрын
+SkelettZockt Goddamn and I thought I was the only one that thought about Druaga when they saw that date.
@AbRaSkZo
@AbRaSkZo 8 жыл бұрын
Brorrowind yea smoke w33d everyday
@henrikhyrup3995
@henrikhyrup3995 5 жыл бұрын
Should have changed it to 6/9 :P
@nokti...
@nokti... 5 жыл бұрын
*_n i c e_*
@chamseddinehammouda6965
@chamseddinehammouda6965 8 жыл бұрын
Cool video! By the way, did you know that you were featured in a Quebec documentary about zero day flaws that was broadcasted a week ago?
@danooct1
@danooct1 8 жыл бұрын
+Chockeyproh Wii U 3DS really? do you have a link/more information?
@chamseddinehammouda6965
@chamseddinehammouda6965 8 жыл бұрын
+danooct1 Sure! One second please, just to upload a screenshot of it online.
@chamseddinehammouda6965
@chamseddinehammouda6965 8 жыл бұрын
+danooct1 drive.google.com/file/d/0B_DKmOADWDWiY2pjeWlIY3BXa0k/view?usp=docslist_api drive.google.com/file/d/0B_DKmOADWDWiSGg2a1Y4VmpDUjg/view?usp=docslist_api These are two (awful quality) pictures I took. I can also give you the video (about 7 seconds) of where you are involved, but it is in french. It is a part explaining that first malware that took control of your OS were not dangerous and were having a diverting payload.
@sorsu
@sorsu 8 жыл бұрын
+OH MY GOD!!! i even saw the source and its right. that is step up. a HUGE STEP UP.
@DVDfeverGames
@DVDfeverGames 4 жыл бұрын
These days, we have Windows 10 to download updates that don't work, and cause it to reboot 3 times before it gives up, uninstalls its own update, and takes you back to where you were originally. It's equally irritating.
@melihcelik9797
@melihcelik9797 5 жыл бұрын
Fascinating tool. Since I don't want to run a DOS simulator on this program, I read the instructions from your video (thx for including all of them by the way) and this is just pure clever. I don't know how it would be possible to reconstruct the whole MRB with FAT16 systems, but if Steve Gibson says its possible, then its possible somehow. However, using the copy to reconstruct whole disk is just amazing. Just people in this bussines knows how a file system works and he delivered a solution to this problem. Also it shows you how slow computer storage was back in the day. This isn't even really old but 7 minutes for a GB is massive considering this tool runs on machine code, standalone on the CPU.
@Wrydryn
@Wrydryn 8 жыл бұрын
these videos are so entertaining. having heard about many of them but now I can see them in action.
@CYXXYC
@CYXXYC 8 жыл бұрын
When saw the title in my sub box got so excited :D
@Wolfblood2004
@Wolfblood2004 8 жыл бұрын
+BurnyCreative Lol I know right :D
@BeavisOfArabia
@BeavisOfArabia 8 жыл бұрын
I've suggested this before, but I'd like to see the effects of a virus and how to remove it in a single video. I don't mind having it split into two videos, but the fact that you sometimes don't do removals for some viruses (don't think you've said in the video that you can't remove it after it's infected the system) and I really wonder how some of those viruses can actually be removed.
@danooct1
@danooct1 8 жыл бұрын
+TheEngineer TCR (TheEngineerTCR) most viruses don't have specific removal tools and i just format the drive to get rid of them.
@maddiwulfe
@maddiwulfe 8 жыл бұрын
I use the command prompt
@GabeofPlayStationLand
@GabeofPlayStationLand 8 жыл бұрын
Great video, Dan! I don't think I've ever been more enticed during one of your vids!
@notlun
@notlun 8 жыл бұрын
At first I was sceptic but the way you did this video and explained everything was brilliant. very nice content, hope to see more of this
@Sketch1994
@Sketch1994 8 жыл бұрын
OMG...My first computer in 2004 came with Windows ME and I only now I realize how lucky I was to have it until 2012!
@usslibertyincident
@usslibertyincident 8 жыл бұрын
damn, this is probably your most well made video yet.
@FF-Pineberry
@FF-Pineberry 4 жыл бұрын
CIH needs to change date to 26 April 1986. This date of Explosion the Chernobyl NPP.
@suzunakuraki3747
@suzunakuraki3747 2 жыл бұрын
I do wanna know what happens to the machines that have been wrecked by CIH -- As in black-screened, no access to the BIOS? Most Virus wrecked machines do let you get to the BIOS screen before moving to the BSOD -- OS's failing to boot because the virus wrecked a system file.
@Hataro-xu1pl
@Hataro-xu1pl Жыл бұрын
Buy new main?
@Tyler-on5se
@Tyler-on5se 8 жыл бұрын
Dan ive been waiting for another cih vid for a while. Thank you!!!!
@ThePreviousLevel
@ThePreviousLevel 8 жыл бұрын
Seeing all these videos, it would appear best defense for a lot of those malwares was to simply disable/freeze your system time. Awesome channel though. It brings me back some cool memories.
@LiEnby
@LiEnby 6 жыл бұрын
siwoti remove the CMOS Battery lol
@FroggyCrimes
@FroggyCrimes 8 жыл бұрын
Good ol' Steve Gibson. I instantly recognized the name lol. He's got some pretty good podcasts
@antthegord9411
@antthegord9411 6 жыл бұрын
Having been in network security for 4 years and understanding quite a lot about not just the skill but the psychology of hackers, I can already assure you many hackers hate you severely for exposing how a vast majority of these older hacks (and the newer ones too) were used, clearing up a lot of the panic/fear the used to exist around malware. It's glorious to finally be able to be so publicly smug towards those jobless, lazy bastards who won't get a real job. Then again, keeps guys like me in business so I guess I should be thanking them
@KenSharp
@KenSharp 6 жыл бұрын
Honestly they couldn't care less. A child could fix this.
@Pachoom
@Pachoom 8 жыл бұрын
Im waiting for this soooo many months,i knew its fixable!Great vid Dan
@FragsJr
@FragsJr 8 жыл бұрын
Great video Dan! Loved the editing/voiceover style.
@rdxdt
@rdxdt 8 жыл бұрын
To repair the BIOS corruption you could hotswap the bios on a good motherboard and flash it again or get one external programmer to flash the bios again.
@eduardoluann
@eduardoluann 8 жыл бұрын
That was a very interesting video! As far as I knew, the only way to repair a computer destroyed by CIH was to find another clean PC with the same chipset and hot-swap BIOS chips. I didn't knew there were "immune" chipsets, that are repairable. Can you do a BIOS-swap video too? It would be a very interesting thing to watch!
@LiEnby
@LiEnby 6 жыл бұрын
Eduardo W. I'm guessing boot with working bios then hotswap to the non working one and use the same exploit to write the original bios onto it?
@GRBtutorials
@GRBtutorials 2 жыл бұрын
Well, it could also be externally reprogrammed. From what I read, even back then it was possible to buy a flash programmer and successfully reflash the BIOS. Not common knowledge, though, especially back then, and you needed another computer anyways.
@PavlentijIvani4
@PavlentijIvani4 5 жыл бұрын
My computer was corrupted by cih, bios and hdd both. It was a real pain!
@PavlentijIvani4
@PavlentijIvani4 5 жыл бұрын
@@malwaretestingfan hm, smtng about 2000-ies. It was pentium 133 or something like that 😁 and windows98 to my mind.
@PavlentijIvani4
@PavlentijIvani4 5 жыл бұрын
@@malwaretestingfan it was popular in 00s
@matthew65536
@matthew65536 8 жыл бұрын
have you thought of trying this in Qemu? I think it would successful in Qemu, because its closer to acting like a real Pc.
@luksamuk
@luksamuk 8 жыл бұрын
Despite the obvious fact that ClamAV doesn't have live scan (although I've already seen extensions that can help ClamAV perform live scans), do you think it's efficient enough? I currently use no antivirus on my Windows system, and I don't feel like any of them are any more effective nowadays than minding what you access.
@FreddyXYZ
@FreddyXYZ 8 жыл бұрын
Hey dancot I love your vids they are the best I was always into technology and how viruses work. thank you and keep making great videos
@SireSquish
@SireSquish 8 жыл бұрын
Dan - I know you get a million messages, and I've asked before - but have you actualy done a hotswap BIOS?
@danooct1
@danooct1 8 жыл бұрын
+SireSquish I'd like to try one but I don't have a similar enough mobo. Maybe someday I'll pick one up and make a video on it.
@fazbearentertainment5720
@fazbearentertainment5720 8 жыл бұрын
danooct1 I'd love to get a pc I'm watching on Samsung galaxy tab e lite
@MidnightMechanic
@MidnightMechanic 8 жыл бұрын
So what if you're unlucky and have a BIOS that gets overwrote by CIH? Since all the boot drives are rendered unbootable, there's no way of using DOS as a saving grace, huh?
@LiEnby
@LiEnby 6 жыл бұрын
Midnight Mechanic you have to desolder the bios and hotswap with one from a working board then use the same exploit? to re-write the firmware to it
@prifes7364
@prifes7364 4 жыл бұрын
Okay, but is there a kill_covid-19 command that I can just write into the console of life?
@thatonemelody
@thatonemelody 2 жыл бұрын
"Rendering the computer unbootable. SOME OF YOU-" that threw me into wednesday
@disastra_tds
@disastra_tds 8 жыл бұрын
7 people has destroyed BIOS...
@kaz_iaa
@kaz_iaa 8 жыл бұрын
Danooct1, thank you for your great content. By the way, do you have access to the database virusshare?
@carsonp.7009
@carsonp.7009 7 жыл бұрын
hey, at 1:59 why isnt the virus called CIH.exe like on the other vid, same OS right?
@Hexaotl
@Hexaotl 8 жыл бұрын
Hey Dan! Your videos have really inspired me to try to mess around with some programming and try to make some simple malware programs. So i am just wondering what programming language you would recommend for someone starting up writing malware?
@Hexaotl
@Hexaotl 8 жыл бұрын
***** I dont really know if Assembly is the correct choice nowadays. And isnt C really difficult/time consuming to learn?
@ZRZK2127
@ZRZK2127 8 жыл бұрын
Nice video man, love these. It's like a trip to the 90s. You ever gonna do some old linux malware videos or something?
@pixelbucket8884
@pixelbucket8884 8 жыл бұрын
I didn't even know Linux malware existed (0_0)
@ZRZK2127
@ZRZK2127 8 жыл бұрын
+PixelBucket The Herobrine Hunter there obviously are some exploits and such. frankly it'd be interesting to see, specially on older systems
@Industryman
@Industryman 8 жыл бұрын
Question: I'm a computer geek, but want to know what it means when a virus "Writes its code to the end"?
@danooct1
@danooct1 8 жыл бұрын
+Dodge it all | One Hour Specialty when a virus infects a file it will patch in code at the beginning of a file telling it to jump to a location at the end of the program. the virus writes its code there so when the program is run, it will jump to the virus, run the virus, then jump back to the host program and run the original program the user was trying to run. so trying to run any infected file will always load the virus. different viruses have different methods of infecting files, like CIH (nicknamed Spacefiller) will seek out empty pockets of space in a file when infecting it, rather than writing to the end of it, so that there's not an increase in the original file's size (which would alert the user that it had been altered in some way)
@Industryman
@Industryman 8 жыл бұрын
+danooct1 Alright! Thank you for clearing the air!
@timothysimmons9359
@timothysimmons9359 8 жыл бұрын
I heard about CIH. I wish to see the most destructive worm/trojan/ or virus ever known!
@windowsthebattler5806
@windowsthebattler5806 5 жыл бұрын
4:12 thank you for choosing the norton antivirus virus scanner to check your computer system for viruses
@danem2215
@danem2215 5 жыл бұрын
Thank you for dialing 911 for all your emergency services needs
@windowsthebattler5806
@windowsthebattler5806 5 жыл бұрын
@@danem2215 i never use 911, i use the 112!
@GingerChristmas
@GingerChristmas 8 жыл бұрын
Makes me wonder what the most recent chipset/CPU that the bios overwrite payload will work on.
@delta_cosmic
@delta_cosmic 8 жыл бұрын
you also need to empty the recycle bin just to be safe
@20EsOfficial
@20EsOfficial 8 жыл бұрын
I know most people wouldn't like to try this, but what would happen if you ran CIH on bootcamp on a Mac w/ dualboot. Will it still boot to OSX?
@Yrouel86
@Yrouel86 8 жыл бұрын
Nice, so did you repair that old pc that was nuked in the original video? With a programmer the BIOS can easily be reflashed
@Notevenmad955
@Notevenmad955 8 жыл бұрын
if you can find a bios that old than its easy
@Notevenmad955
@Notevenmad955 8 жыл бұрын
+I am not even mad then*
@dragonsky2884
@dragonsky2884 8 жыл бұрын
+I am not even mad It's not like you can flash another BIOS that is compatible. It doesn't have to be the exact same one.
@triplebog
@triplebog 8 жыл бұрын
Have you ever thought about playing Lose/Lose? That game is kind of like a virus in itself. I would love to see a video on it.
@themightypikachu2829
@themightypikachu2829 8 жыл бұрын
Tar Alacrin I've never seen a Mac video on this channel.
@phrench64
@phrench64 7 жыл бұрын
+TheMighty Pikachu Mac's dont really get viruses because of the way they are.
@sixfr0nt
@sixfr0nt 6 жыл бұрын
I apologize for the extremely late reply, but Tom.K did a great video on Lose/Lose that you should check out.
@Etobio
@Etobio 8 жыл бұрын
Excellent work! Glad to see such an awesome nerdy video!
@hazelordwebtv
@hazelordwebtv 3 жыл бұрын
How to use it one last time, 1: make sure ur using 95 or 3.1 if not, Too Bad! 2: when u get any bsod do what it says to reopen windows
@mattr2238
@mattr2238 4 жыл бұрын
Someone on github rewrote CIH to work on the NT kernel. It's still entirely in assembly language, and it's insane.
@partitionhlep
@partitionhlep 3 жыл бұрын
oh no
@mattr2238
@mattr2238 3 жыл бұрын
@@partitionhlep It doesn't really work though because it is still hardware specific, it requires kernel exploits that have been patched since win2k, and it requires borland turbo assembler. I tried assembling it and running it on a 64 bit win7 vm and it did nothing. If you wanted to create a CIH like virus in 2021, you need to start from scratch and use UEFI. Now that's scary, because UEFI is already completely broken.
@partitionhlep
@partitionhlep 3 жыл бұрын
@@mattr2238 my bios mode is legacy
@mattr2238
@mattr2238 3 жыл бұрын
@@partitionhlep That may very well be the case, but the expliot used by CIH is specific to the original IBM PC BIOS, not what we call legacy bios on modern computers. On modern computers, a legacy BIOS is typically a UEFI BIOS that uses a Compatibility Support Module to emulate some of the functionality of the original PC BIOS. Perhaps your computer came with the original Windows NT back in the 90s, in which case it does have a PC BIOS and is vulnerable to the destructive payload.
@partitionhlep
@partitionhlep 3 жыл бұрын
@@mattr2238 ok, i'm running windows 10 on a 2011 pc if you don't know
@szabotihamer
@szabotihamer 8 жыл бұрын
Too bad there's no fix for the dead BIOS. It would have been nice if the bricked machine would have had a removable eprom chip. That way you could get an eprom burner and flash the old BIOS ROM back to the chip and resurrect the machine.
@GRBtutorials
@GRBtutorials 6 жыл бұрын
Tihamér Szabó ? If the virus could overwrite the BIOS, you can reflash the BIOS as well.
@nororlol4life819
@nororlol4life819 5 жыл бұрын
coreboot?
@A3x_x43
@A3x_x43 Ай бұрын
​@@GRBtutorialsnot on the old PCs from 1990s
@jtotheroc
@jtotheroc 7 жыл бұрын
@danoct1 is CIH short for something??
@JTCGiantz56
@JTCGiantz56 8 жыл бұрын
I'm surprised you're able to find all of this old virus cleanup software
@raspberry144mb3
@raspberry144mb3 5 жыл бұрын
CIH was particularly nasty and widespread, so it's not too terribly surprising.
@zumbach242
@zumbach242 8 жыл бұрын
Can you do a video on the whistler virus? I used to have it and it drove me crazy for a month. Took me forever to find out how to fix it.
@DriftHyena
@DriftHyena 7 ай бұрын
I built and ran this virus on my PII build. Only got one BSOD but it gave me a blank screen with a cursor and a solid hard drive light. Next reboot it never posted, but I made sure to backup the BIOS chip before hand and now I can at least get into BIOS. Next step is to restart the deleted hard drive segments and wipe it.
@Lambertv
@Lambertv Жыл бұрын
2:32 that must be the bluest bsod i ever seen
@felixisdev
@felixisdev 8 жыл бұрын
Is it hard to put a simple "BIOS Write Enable" switch on the computer? I think it's stupid, that the BIOS isn't read only
@LiEnby
@LiEnby 6 жыл бұрын
Felix K on modern systems they decided to make EFI writable so it can be updated by the operating system (lol)
@RRW359
@RRW359 8 жыл бұрын
How did this (the virus) work? Wasn't this before NAND storage?
@NothingIsScary
@NothingIsScary 8 ай бұрын
I wish we got to see more of these virus removal videos
@Mario583a
@Mario583a 8 жыл бұрын
Is Danooct1 gonna be the new Rogueamp1/2 now??
@old-superstar64
@old-superstar64 8 жыл бұрын
I have a pc with windows 2000 and an amd athlon 1.1 GHZ proccessor. Would CIH overwrite the bios there?
@wcimlovin9098
@wcimlovin9098 8 жыл бұрын
It shouldn't. I think it "works" only on 95,98 and Me. No worries
@old-superstar64
@old-superstar64 8 жыл бұрын
Michał Jędrzejewski i also quad booted it. it has windows 2000,ME,XP, and 98 SE. only 2000 has internet access though (and probably XP soon)
@old-superstar64
@old-superstar64 8 жыл бұрын
Hello!!! Anything?
@wcimlovin9098
@wcimlovin9098 8 жыл бұрын
superstar64 As I mentioned before it works on Win9x series
@KylesDigitalLab
@KylesDigitalLab 8 жыл бұрын
No, Win2000 is NT. Win9x only had the exploit
@airhead0523
@airhead0523 8 жыл бұрын
I asked this to the internet already, but what happens if you put CIH on a modern PC?
@EvilTurkeySlices
@EvilTurkeySlices 8 жыл бұрын
You would need to be running a 9x version of Windows for it to even run, and it would go the same thing(the PC is too new to have its bios deleted)
@airhead0523
@airhead0523 8 жыл бұрын
+EvilTurkeySlices I guess
@blackblob500
@blackblob500 8 жыл бұрын
I have a SE440-BX-2. Can It be infected with CIH?
@meowskullsgaming
@meowskullsgaming 8 жыл бұрын
3:42 4/20
@ahamdapeynir
@ahamdapeynir 8 жыл бұрын
lol, i noticed that too
@tomnook5177
@tomnook5177 8 жыл бұрын
420 BLAZE IT
@airhead0523
@airhead0523 8 жыл бұрын
On 4/20, I actually overclocked my phone to make it overheat just for 4/20
@bananakiwi8028
@bananakiwi8028 7 жыл бұрын
my birthday is 4/19 noone cares about 4/19 they all care about 4/20 :(
@sixfr0nt
@sixfr0nt 7 жыл бұрын
special day, i actually snuck cake into my school's detention room for 4/20 since i had lunch detention that day. lmao it was fuckin hilarious
@K3NnY_G
@K3NnY_G 8 жыл бұрын
Awesome video man, keep up the great work!
@Synthematix
@Synthematix 6 жыл бұрын
How did you get it to boot again?
@gummel82
@gummel82 8 жыл бұрын
Which anti virus software are you using? Just curious
@Veso266
@Veso266 8 жыл бұрын
can you post CIH Removal files here? PS: Do you think this would work on an emulator that emulates physical BIOS? (something like PCem ( citadel.ringoflightning.net/pcem101_experimental.7z )?
@SzymonParys
@SzymonParys 5 жыл бұрын
why this video is so satisfying?
@vicr123
@vicr123 8 жыл бұрын
Your video editing isn't too bad. It's pretty good! :D
@Fyralism
@Fyralism 7 жыл бұрын
Victor Tran omg I know you from is first timer
@Poebat
@Poebat 8 жыл бұрын
I liked the way you edited this video.
@ELMO7TARAMQ8
@ELMO7TARAMQ8 4 жыл бұрын
if the creator of that virus had made the virus trigger on all of the dates on the calender then it would be even harder to remove this virus
@raymanninja2194
@raymanninja2194 8 жыл бұрын
What computer do you use
@lysandus
@lysandus 8 жыл бұрын
How do you find specific viruses to test?
@ComputersVirtualMachinesAndMor
@ComputersVirtualMachinesAndMor 8 жыл бұрын
What Happened To AmpDan1? Did You Create A Channel Like AmpDan2 DanAmp1
@jacknetarchive
@jacknetarchive 8 жыл бұрын
Dan and Amp have no collab ideas at the moment. But try to stay tuned.
@concepcion_abel
@concepcion_abel 4 жыл бұрын
Porque el título del vídeo está en español si hablas ingles ? Saludos
@shadowzone2588
@shadowzone2588 4 жыл бұрын
antivirus scanner: wait so these files are all infected with CIH? CIH: always has been
@sharki9876
@sharki9876 8 жыл бұрын
do any of these viruses actually work on a modern computer? or is this just mental masturbation
@danooct1
@danooct1 8 жыл бұрын
+sharki9876 win32 stuff has the potential to function on more modern operating systems (like the loveletter VBS worm from 2000 will still work on Windows 10), but in particular windows 9x viruses are limited to 95, 98 and Me, generally. the sort of stuff in this video is just fun to do and I figured it fit the theme of the channel so it was worth recording.
@sharki9876
@sharki9876 8 жыл бұрын
+danooct1 are there any interesting viruses that are possible to analyze/reproduce on a modern system i meant. i see that on your titles you indicate which os theyre built fot
@berthold64
@berthold64 8 жыл бұрын
most win32 and office vba viruses are compatible with windows 10
@AVINIDE
@AVINIDE 8 жыл бұрын
+OH MY GOD!!! How about Linux and sudo rm rf? Does it erase the BIOS?
@OGuiBlindao
@OGuiBlindao 2 жыл бұрын
Does anyone know if there are any download links to these tools?
@OGuiBlindao
@OGuiBlindao 2 жыл бұрын
Nvm i managed to use way back machine on some old download links that are dead and managed to download it
@oneoddturtle
@oneoddturtle 5 жыл бұрын
so i backfired a CIH and Unit94 using Lua 5.5.3 and instead of them hacking my pc, they got sended tons of virus , 47v/s and theyre dead
@daytonsMusicRoom
@daytonsMusicRoom 3 жыл бұрын
Amazing Video As Always
@Keksnek
@Keksnek 8 жыл бұрын
Wow, original video was made in 2012 ? I feel so old :D
@MayDay386
@MayDay386 8 жыл бұрын
maybe is first video about removal of this virus?
@Megadoomable
@Megadoomable 8 жыл бұрын
If you install Windows 98 on an Alienware (which I doubt anyone would do) and run CIH, will the BIOS deletion payload occur?
@cleanycloth
@cleanycloth 8 жыл бұрын
+Megadoomable No, it only affects certain chipsets that were made back in the late 90s.
@Megadoomable
@Megadoomable 8 жыл бұрын
c0d3r3d // cleanycloth ok
@mt441pl
@mt441pl 3 жыл бұрын
that excitement is indeed justified dw
@RaptorZX3
@RaptorZX3 8 жыл бұрын
GRC is awesome to have made that Fix-CIH freeware!
@LilZesty
@LilZesty 8 жыл бұрын
you have no idea how much I would love to help you find viruses and record with you.
@panzerstef
@panzerstef 6 жыл бұрын
MEMZ does the same, but it doesn't overwrite the BIOS, but rather the MBR
@LiEnby
@LiEnby 6 жыл бұрын
Techbird 64 that's super easily fixed lol
@lagriffn
@lagriffn 8 жыл бұрын
Why did the screen glitch out
@GENATARi
@GENATARi 8 жыл бұрын
4-20-95... was that on purpose?
@leperuna2475
@leperuna2475 8 жыл бұрын
Nice, great video. Can you do more email worm showcases or something like that.
Email-Worm.Win32.Magistr (Thanks for 100,000 subscribers!!!)
11:09
Virus.Win16.Apparition
15:12
danooct1
Рет қаралды 339 М.
ВЛОГ ДИАНА В ТУРЦИИ
1:31:22
Lady Diana VLOG
Рет қаралды 1,2 МЛН
Хаги Ваги говорит разными голосами
0:22
Фани Хани
Рет қаралды 2,2 МЛН
«Жат бауыр» телехикаясы І 30 - бөлім | Соңғы бөлім
52:59
Qazaqstan TV / Қазақстан Ұлттық Арнасы
Рет қаралды 340 М.
Virus.DOS.StealthBomber
6:26
danooct1
Рет қаралды 43 М.
Virus.Win9x.Caw
16:43
danooct1
Рет қаралды 213 М.
Email-Worm.Win32.Vote
12:45
danooct1
Рет қаралды 56 М.
Net-Worm.Win32.Sasser On a Physical PC Network
14:54
danooct1
Рет қаралды 486 М.
Virus.DOS.Vanish
4:00
danooct1
Рет қаралды 51 М.
Email-Worm.VBS.Dumb
6:30
danooct1
Рет қаралды 57 М.
Virus.MSWord.Ethan
15:23
danooct1
Рет қаралды 64 М.
Trojan.VBS.Hold
11:07
danooct1
Рет қаралды 92 М.
Virus.Win16.CyberRiot
13:34
danooct1
Рет қаралды 291 М.
Email-Worm.VBS.AnnaKournikova
11:50
danooct1
Рет қаралды 63 М.
ВЛОГ ДИАНА В ТУРЦИИ
1:31:22
Lady Diana VLOG
Рет қаралды 1,2 МЛН