Kampana Virus (20-FEB-1993) Entry...............: Kampana Virus Alias(es)...........: Telefonica = Spanish Telecom Virus Virus Strain........: Kampana Virus Strain Virus detected when.: December 1990 where.: Spain Classification......: Program Virus: memory-resident, self-encrypting appending COM infector, stealth Length of virus.....: 1) Length on media: 3700 bytes 2) Length in RAM: 3700 bytes Variants............: --------------------- Preconditions ------------------------------------ Operating system(s).: MS-DOS Version/release.....: 2.0 and higher Computer model(s)...: All MS-DOS machines --------------------- Attributes --------------------------------------- Easy identification.: The following text can be found in memory: "Virus Anti - C.T.N.E. (c)1990 Grupo Holokausto.",0h, "Kampanya Anti-Telefonica. Menos tarifas y mas servicio.",0h, "Programmed in Barcelona (Spain). 23-8-90. - 666 -",0h Type of infection...: Self-Identification: The time stamp of an infected file is changedby adding 200 to actual year (19xx ==> 21xx); this will not be visible when virus is resident. When executing an infected file, virus will decrypt and install itself resident in memory. Subsequently, Kampana Boot Virus is installed on hard disk (see Kampana Boot). A previously non-infected .COM file is infected when virus is memory-resident by appending the viral code to it; small COM files (size<128) and large COM files (size>=61000 bytes) are not infected. Infection trigger...: Execution of a .COM-file (but not IBM*.COM or ??MAND*.COM), this is Storage media affected: Files on all media. (See boot-virus, too.) Interrupts hooked...: INT21h only. Damage..............: Permanent Damage: Kampana Virus overwrites HD boot sector with Kampana Boot. Damage trigger......: Permanent Damage: accessing a file on disk. Particularities.....: The virus ignores all attributes of a file. It encryptes itself in a file using two different techniques, including many changes of dummy bytes to reduce the length of scan strings; it looks for interrupts 13h, 21h, 40h to access BIOS and DOS directly; if file- length is looked for, virus displays original length of an infected file. --------------------- Agents ------------------------------------------- Countermeasures.....: Very difficult because of encryption and stealth! Countermeasures successful: --- Standard means......: FindViru, F-Prot and Scan (etc) --------------------- Acknowledgement ---------------------------------- Location............: Virus Test Center, University Hamburg, FRG Classification by...: Daniel Loeffler Documentation by....: Daniel Loeffler Date................: January 25, 1993 Information Source..: Reverse-Engineering of virus code .