[Eddie Family], 2091 byte(s).
This is the family of memory resident parasitic viruses. They hook INT 21h
and write themselves to the end of the files. These viruses contain the
strings:

"Eddie.651": Eddie lives
"Eddie.1797": McAfee and Associated (C)1992
Diana P.
This program was written in the city of Sofia
(C) 1988-89 Dark Avenger
"Eddie.1799" Francis lives...in Hong Kong!
Diana P.
This program was written in the city of Sofia
(C) 1988-89 Dark Avenger
"Eddie.1800": Eddie lives...somewhere in time
Diana P.
This program was written in the city of Sofia
(C) 1988-89 Dark Avenger
"Eddie.1800.b" Never buy Quest computers again!
This program is not dangerous stamp.
All new software seriosly danger
"Eddie.2000": ä¿á¡á Å.
(c) 1989 by Vesselin Bontchev
Zopy me - I want to trawel
"Eddie.2100": ä¿á¡á Å.
(c) 1989 by Vesselin Bontchev
Eddie lives
"Eddie.2000.b": 1994 Satan Virus[ Ver 3.09 ]
1994 by [Mad Satan] in TAIWAN.
"Eddie.2000.c": Only the Good die young...
(c) 1989 by Vesselin Bontchev.
"Eddie.2000.d": go, go with a smile (CK)
by McAfee Associates. (408-38

Eddie.651

This virus infects COM and EXE files that are executed. It sets the file's
time stamp to 62 sec. The virus does not manifest itself in any way, it

The virus hooks the DOS functions FindFirst/Next FCB (DIR command) and
"reduces" lengths of infected files. During "reducing" the file lengths the
virus determines their state of health using the value of seconds in the
date of the last modification (62 sec.) and does not check actual lengths of
the files. If such value of seconds is found in a file of small length (less
than 651 bytes), than the DIR command will show a strange length of the file
- about 4 Gigabytes.

Eddie.1800

It is a dangerous memory resident virus. It hooks INT 13h, 21h, 27h and
spreads quickly: it infects COM and EXE files that are loaded into memory
for execution, created, renamed, opened and closed.

The virus takes some effective measures to stay undetected:
- on running any program it marks the program segment as the last one, and
becomes invisible for this program, after the program operation is finished,
the virus marks the program segment as not the last one.
- by the same way changes the interrupt vector 21h as a program is started -
restores its initial value.
- does not allow programs to change the interrupt vector 21h and in this way
protects itself from memory-resident anti-viruses, installed after the virus
has been activated.
- attempts to bypass programs, watching for interrupt 13h, and to set this
interrupt vector to its initial value.

This virus is very dangerous one, periodically it erases a sector with a
random number. The virus analyses 2 bytes (8-th and 10-th) of the boot
sector of the disk, from which the infected program has been started. This
infector increments by 1 the value of the 10-th byte and saves it into the
boot sector. If a new value of the 10-th byte is a multiple of 16, the virus
erases on the disk a sector with a random number, which depends on the value
of the 8-th byte.

Eddie.2000, Eddie.2100

These are very dangerous viruses. They hook INT 13h, 21h, 27h and quickly
replicate themselves. They infect a file as it is loaded into memory for
execution, created, renamed, closed, read or as its attributes are changed.

The viruses act in such a way, that the lengths of infected files increase
exactly by 2000 (or 2100) bytes (to EXE files after paragraph alignment the
necessary number of bytes is added). In infected files a new value of
seconds in the date of the last modification is set - 62 seconds.

The "Eddie.2000" virus takes some effective measures to stay undetected,
many of them are similar to those, taken by the "Eddie.1800" virus. The
masking function is performed by the virus length: it is difficult enough to
spot the length increase, multiple of 1000 bytes. Other protective function
has as well been introduced: the virus hooks the Dos functions FindFirst and
FindNext FCB and "reduces" lengths of infected files by 2000 bytes.

In addition "Eddie.2100" handles the DOS functions FindFirst/Next ASCII; the
error because of which the DIR command reported that the file length was
about 4 Gigabytes (see description of "Eddie.651") has been corrected. In
incomprehension manner the "Eddie.2100" manipulates with hard disk sectors -
possibly tries to activate or cure a boot virus unknown to me.

The "Eddie.2000" and "Eddie.2100" viruses are very dangerous - as the
"Eddie.1800" virus they erase sectors with random numbers. The viruses
directly address to the disk handling driver and bypass many memory resident
antiviral monitors.

If the body of a program to be run has the string "Vesselin Bontchev"
(author of known bulgarian antiviruses) the viruses begin to cycle and hang
up the system.

Eddie.1028

It is a modification of "Eddie.1800": the text strings are overwrote by INT
1Ch handler. This handler contain the delay loop. The code of damage writing
on disk are removed.

Eddie.1530

This is a dangerous virus. It resets computer and erases a part of CMOS.

Eddie.Father

It's a harmless virus. It contains the text:
In memory of my father.(C)Nduk '91

Eddie.Jasper

It is a very dangerous encrypted virus. It hooks INT 08h, 21h, 27h.
Depending on system date it deletes the files or displays the message:
If You Liked This Virus,Call Asaf, At +972-4-225288!

It also contains the text string:
Written By Jasper,and Dedicated to Freddie Mercury.

Eddie.Jericho

These viruses contain the text strings:
"Eddie.Jericho.a": JERICHO by Eurystheus<FoG>_Calgary
"Eddie.Jericho.b": JERICHO_Eurystheus_Calgary AB

"Eddie.Jericho.b" is a harmless variant of "Eddie" virus. It does not hook
INT 27h, and does not corrupt the disk sectors. It has the error in
infection routine and does not infect EXE files.

Eddie.Korea

That plagiarism from "Eddie.1800" contains the texts:
If you are a thieve man, virus lives...somewhere always!
You must become good man!
Kang Yong Il.
This program was adjustted in 'Commputer Home' of KOREA
(C) 1988-89 ,LSR+KYL".

Eddie.Major

This virus is variant of "Eddie.1800". It contains the strings:
Written In Turbo Assembler v2.84
(C) 1992 MajorBBS Patch v1.0
This Program Was Written To Patch The Backdoor Of MajorBBS
(C) 1992 by Leroy Janowa

Eddie.Oliver

This virus contains the text strings:
Bill the Cat Lives!
by Oliver Wendell Jones
Politically Incorrect Personal Computers Presents:
the OLIVER VIRUS! Nya Ha Ha! Men Rule! America Kicks Butt! Rap Sucks!
Eat Fatty Food! Dames Melt Like Jell-O for Naughty Men!
Ted Kennedy Sucks Barney Frank`s Fag Cock!
Berk B.
Banana 6000 P.I.P.C. (C) I spell -Lightening- wrong!

Eddie.Psko

This virus contains the text strings:
The Ps!ko Virus - Version 1.0
SiTT
The Ps!ko Virus - Written in the USA, (C)1991 by SiTT and The Violator

Eddie.Satan.1800

Variant of "Eddie.1800", it contains the texts:
* Satan Virus * Satan Ver 2.09
- Satan Virus - 1994 Written by Mad Satan in TAIWAN. =Ver 2.09=

Eddie.Shyster

Variant of "Eddie.1800", it contains the text: "Shyster".

Eddie.Sign

It is also plagiarism of "Eddie.1800" (practically the same). It contains
the text:
#.I.R. *-*-*-* Sign of the time! &^%s%c%d

Eddie.Uriel

From January, 15th it formats disk sectors. It has the bugs which can halt
the system. It contains the internal text strings:
___
Uriel 1.00·Eur<FoG>

Back, 16042 byte(s).