Frodo Soft Virus


 Virus Name:  Frodo Soft 
 Aliases:     F-soft 
 V Status:    Rare 
 Discovered:  October, 1992 
 Symptoms:    .COM file growth 
 Origin:      Warsaw, Poland 
 Eff Length:  563 Bytes 
 Type Code:   PNCK - Parasitic Non-Resident .COM Infector 
 Detection Method:  ViruScan, Sweep, F-Prot, AVTK, IBMAV, NAV, 
                    NAVDX, VAlert, PCScan, ChAV, 
                    Sweep/N, Innoc, NProt, AVTK/N, NAV/N, IBMAV/N, NShld 
 Removal Instructions:  Delete infected files 
 
 General Comments: 
       The Frodo Soft virus was received in October, 1992.  It is originally 
       from Warsaw, Poland.  Frodo Soft is a non-resident, direct action 
       infector of .COM programs, including COMMAND.COM.  It should not be 
       confused with the  4096  or Frodo virus as they are not related. 
 
       When a program infected with the Frodo Soft virus is executed, this 
       virus will infect one .COM program located in the current directory. 
       If COMMAND.COM is located in this directory, it may become infected. 
       Programs infected with the Frodo Soft virus will have a file length 
       increase of 563 bytes with the virus being located at the end of 
       the file.  The program's date and time in the DOS disk directory 
       listing will not be altered.  The following text strings are 
       encrypted within the viral code, and hence not visible in infected 
       programs: 
 
               "*.com" 
               "Gmks*.exe" 
               "(c) Frodo Soft" 
 
       It is unknown what Frodo Soft does besides replicate. 
 
       Known variant(s) of Frodo Soft are: 
       Frodo Soft-458: An earlier version of the Frodo Soft virus 
                described above, this variant infects one .COM program 
                each time an infected program is executed.  Infected 
                programs have a file length increase of 458 bytes with 
                the virus being located at the end of the file.  The 
                following text strings are encrypted within the viral 
                code: 
                "????????com" 
                "mks?????.exe" 
                "(c) Frodo Soft" 
                Origin:  Warsaw, Poland  October, 1992. 
       Frodo Soft.633: Received in January, 1995, Frodo Soft.633 is 
                a 633 byte variant of the Frodo Soft virus described above. 
                It infects one .COM program in the current directory when 
                an infected program is executed.  Infected programs 
                increase in size by 633 bytes with the virus being located 
                at the end of the file.  The program's date and time in the 
                DOS disk directory listing will not be altered.  The 
                following text strings are encrypted within the viral code: 
                "*.com" 
                "mks*.exe" 
                "(c) Frodo Soft" 
                Origin:  Unknown  January, 1995. 
       Frodo Soft.656: Received in January, 1995, Frodo Soft.656 is 
                a 656 byte variant of the Frodo Soft virus described above. 
                It infects one .COM program in the current directory when 
                an infected program is executed.  Infected programs 
                increase in size by 656 bytes with the virus being located 
                at the end of the file.  The program's date and time in the 
                DOS disk directory listing will not be altered.  The 
                following text strings are encrypted within the viral code: 
                "*.com" 
                "mks*.exe" 
                "(c) Frodo Soft" 
                Origin:  Unknown  January, 1995. 

Show viruses from discovered during that infect .

Main Page