Frodo Soft Virus
Virus Name: Frodo Soft
Aliases: F-soft
V Status: Rare
Discovered: October, 1992
Symptoms: .COM file growth
Origin: Warsaw, Poland
Eff Length: 563 Bytes
Type Code: PNCK - Parasitic Non-Resident .COM Infector
Detection Method: ViruScan, Sweep, F-Prot, AVTK, IBMAV, NAV,
NAVDX, VAlert, PCScan, ChAV,
Sweep/N, Innoc, NProt, AVTK/N, NAV/N, IBMAV/N, NShld
Removal Instructions: Delete infected files
General Comments:
The Frodo Soft virus was received in October, 1992. It is originally
from Warsaw, Poland. Frodo Soft is a non-resident, direct action
infector of .COM programs, including COMMAND.COM. It should not be
confused with the 4096 or Frodo virus as they are not related.
When a program infected with the Frodo Soft virus is executed, this
virus will infect one .COM program located in the current directory.
If COMMAND.COM is located in this directory, it may become infected.
Programs infected with the Frodo Soft virus will have a file length
increase of 563 bytes with the virus being located at the end of
the file. The program's date and time in the DOS disk directory
listing will not be altered. The following text strings are
encrypted within the viral code, and hence not visible in infected
programs:
"*.com"
"Gmks*.exe"
"(c) Frodo Soft"
It is unknown what Frodo Soft does besides replicate.
Known variant(s) of Frodo Soft are:
Frodo Soft-458: An earlier version of the Frodo Soft virus
described above, this variant infects one .COM program
each time an infected program is executed. Infected
programs have a file length increase of 458 bytes with
the virus being located at the end of the file. The
following text strings are encrypted within the viral
code:
"????????com"
"mks?????.exe"
"(c) Frodo Soft"
Origin: Warsaw, Poland October, 1992.
Frodo Soft.633: Received in January, 1995, Frodo Soft.633 is
a 633 byte variant of the Frodo Soft virus described above.
It infects one .COM program in the current directory when
an infected program is executed. Infected programs
increase in size by 633 bytes with the virus being located
at the end of the file. The program's date and time in the
DOS disk directory listing will not be altered. The
following text strings are encrypted within the viral code:
"*.com"
"mks*.exe"
"(c) Frodo Soft"
Origin: Unknown January, 1995.
Frodo Soft.656: Received in January, 1995, Frodo Soft.656 is
a 656 byte variant of the Frodo Soft virus described above.
It infects one .COM program in the current directory when
an infected program is executed. Infected programs
increase in size by 656 bytes with the virus being located
at the end of the file. The program's date and time in the
DOS disk directory listing will not be altered. The
following text strings are encrypted within the viral code:
"*.com"
"mks*.exe"
"(c) Frodo Soft"
Origin: Unknown January, 1995.