     Detlef Virus

     Name         : Detlef

     Aliases      : No Aliases

     Clones       : No Clones 

     Type         : Bootblock
     Size         : 1024 bytes

     Symptoms     : No Symptoms

     Discovered   : 12 september 1993

     Way to infect: Boot infection

     Rating       : Harmless

     Kickstarts   : 1.2
                    2.0 (Only DD-Disks)

     Damage       : Overwrites boot

     Visible text : -
     Alert screen :                    "Guten Tag."
                                   ">> Ich heiße DETLEF <<"
                      "Ich werde Sie in der nächsten Zeit etwas nerven"
                            "Gemacht wurde ich von     M A X    "     

     Comments     : The Detlef-Virus is a harmless one. It copies  itself
                    to a  CHIP-Memory-Area which was  first  allocated by
                    the virus. The DoIO()  vector is used to infect other
                    disks  and to stay  resident in memory the virus uses
                    the KICKVectors which will be manipulated.

                    The  DOIO()-Check routine is  a little  bit bad coded
                    because the virus test for block 880. Because of this
                    fact it`s very unlikely that the virus infects 
                    HD-Disks (BUT NOT UNTHINKABLE!). The  whole bootblock
                    is crypted  depending of  $dff00a.  Sometimes while a
                    Reset the virus gives out an alert

     Removal      : Kickstart 1.2 & 1.3 : VT-Schutz v3.17
                    Kickstart all others: VirusZ III with Xvs.library installed
     Test made by : Safe Hex International

     Screenshot of Detlef Virus:

     Ascii of Detlef virus (Decoded):


