Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Eddie 2


Aliases:


Eddie 2
Eddie 2

Malware
Virus
W32

Summary

A fairly harmless virus from Bulgaria - called "Eddie II" because it contains the string "Eddie lives". This string is similar to the string contained in the original "Eddie" virus.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

Eddie II can infect .EXE files as well as .COM files, but unlike most other .EXE infecting viruses, it does not pad them so their length becomes a multiple of 16 bytes, before they are infected. Infected files are marked with a value of 62 in the "seconds" field of the timestamp, which makes them immune to infection by Vienna or Zero Bug. Infected files grow by 651 bytes, but this increase will not be seen if a "DIR" command is given, because the virus intercepts the "find-first" and "find-next" functions, and if the "seconds" field contains 62, the virus will decrement the file length by 651. Apart from this the virus does nothing of interest.







Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.