Threat Description



Aliases: Murphy
Category: Malware
Type: Virus
Platform: W32


The authors of this virus are known. They are Lubomir Mateev Mateev and Iani Lubomirov Brankov, both in Bulgaria. Murphy is partially based on the 'Eddie' virus, but is not harmful. Inside it the following message can be found.

   Hello, I'm Murphy. Nice to meet you friend. I'm written since Nov/Dec.    Copywrite (c)1989 by Lubo & Ian, Sofia, USM Laboratory.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.

Technical Details


This variant is also written by the authors of Murphy. It is a bit longer, 1521 bytes, and the message is different:

  It's me - Murphy.  Copywrite (c)1990 by Lubo & Ian, Sofia, USM Laboratory.  

Originally this virus was reported to jump into ROM BASIC every exact hour, possibly causing some clones to "hang", but the samples available to researchers in the West produce the "Bouncing Ball" effect every time INT 18 is executed.

Variant:Amilia, AntiChrist, Bad Taste, Brothers, Cemetery, Diabolik, Erasmus, Finger, Goblin, HIV, Locker, Migram, Move, Pest, Smack, Swami, Tormentor

A series of non-interesting variants, most of which are said to be created by a person calling himself Cracker Jack. The effects vary, but the viruses are generally only "laboratory" specimens, not a serious threat in the wild.


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More