Symptoms of the Chernobyl virus

Symptoms of the Chernobyl virus

I have a problem with a virus. It struck at just past midnight on April 26. In that respect it resembles the CIH virus. The problem is that when it disabled my system, it identified itself with a Windows protection fault-type screen but it had text on it that read, "chernobyle 2, something RUSSIA , Made by Prism and I think W32." That's only part of it that I can remember, because I did not write it down, and now Windows only gets a blue screen. "cdromdrive" also refused to stay closed earlier in the day. All attempts to load or run virus software are cut short by blue screens, as well.

The Symantec site has a CIH remedy, but their description of the messages that one would be getting are diferent than what I am getting. (Non-System Disk when boot from hard drive and invalid media when trying to boot from floppy) I get a Windows blue screen. Can you help?


    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Sorry to say, but I think your Chernobyl has melted down and done irreparable harm to your drive. If you have floppy booted and you are still BSoD (blue screen or scream of death) your system may be long gone. You have a variant of the CIH virus that did it's job well and may have removed every piece of valid code on your computer.

Depending on the version of the OS, hardware and other variables, you may be able to reload the OS or at least the boot portion. That doesn't mean the MTA, FAT or other method to map the drive is still valid or the boot sector is even on the system. Furthermore, ensure you are totally disconnected from any valid system while attempting to recover. You do not want to damage other systems on your network.

I know this is not much help, but I feel what you have explained may be unredeemable at this point.


For more information on this topic, visit these other SearchSecurity resources:
News & Analysis: Chernobyl virus set to wake up
Definition: Chernobyl virus
Best Web Links: Malware


This was first published in May 2002