home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- DARK AVENGER
- ============
-
- DARK AVENGER is the pseudonym used by a particularly prolific and
- malicious Bulgarian virus writer. It is also the name given in the
- West to some of his earlier viruses. His viruses include:
-
- DARK AVENGER V651, V1800, V2000 and V2100
-
- NUMBER OF THE BEAST aka 512 (several versions)
-
- ANTHRAX (Infects both files and boot sectors)
-
- V800 and its derivatives: 1226, PROUD, EVIL & PHOENIX
-
- Some other viruses, eg NOMENKLATURA & DIAMOND are in his style but
- are believed to be the work of others. MURPHY has been strongly
- influenced by him but is known to be of different authorship.
- CRAZY EDDIE may also be his.
-
- Several 'hacks' are now appearing of V1800, V2100, MURPHY and
- DIAMOND.
-
- ************* more **********
-
- Eddie is the mascot of the British heavy metal group, Iron Maiden
- (hence 'up the irons'). It is a 20 foot high skeleton that appears
- on stage with them and is featured on the sleeves of all their
- albums.
-
- Anthrax and Damage Inc are other heavy metal groups whose names have
- been featured in some Dark Avenger viruses. Iron Maiden numbers have
- also been mentioned including 'Somewhere in Time', 'Only the Good
- Die Young' and 'Number of the Beast'.
-
- ************** more **********
-
- Unusually, this virus writer has also produced a virus removal
- program together with a version log of his EDDIE series, as
- reproduced below with its original spelling and grammar.
-
- "DOCTOR QUICK! Virus Doctor for the Eddie Virus Version 2.01
- 10-31-89 Copyright (c) 1988-89 Dark Avenger. All rights reserved.
- DOCTOR /? for help
-
- It may be of interest to you to know that Eddie (also known as "Dark
- Avenger") is the most widespread virus in Bulgaria for the time
- being. However I have information that Eddie is well known in the
- USA, West Germany and USSR too.
-
- I started in writing the virus in early September 1988. In those
- times there were no any viruses in Bulgaria, so I decided to write
- the first Bulgarian virus. There were some different Eddie's
- versions:
-
- VERSION 1.1, 16-DEC-1988
-
- In December I've decided to enchance the virus. This version could
- infect files during their opening. For that reason, a read buffer
- was allocated in high end of memory, rather than using DOS function
- 48h when needed. The disk was destroyed instead of the infected
- files.
-
- VERSION 1.2, 19-DEC-1988
-
- This added a new feature that causes (for example) compiled programs
- to be infected at once if the virus is resident. Also, the "Eddie
- lives..." message was added (can you guess why exactly "Eddie"?)
-
- VERSION 1.31, 3-JAN-1989
-
- This became the most common version of Eddie. A code was added to
- find the INT 13 rom-vector on many popular XT's and AT's. Also,
- other messages were added so its length would be exactly 1800 bytes.
- There was a subsequent, 1.32 version (19-JAN-1989), which added
- self-checksum and other interesting features that was abandoned
- because it was extremely buggy.
-
- In early March 1989 version 1.31 was called into existence and
- started to live its own life to all engineers' and other suckers'
- terror. And, the last
-
- VERSION 1.4, 17-OCT-1989
-
- This was a bugfix for version 1.31, and added some interesting new
- features. Support has been added for DOS 2.x and DOS 4.x. For
- further information about this (the most terrible) version, and to
- learn how to find out a program author by its code, or why
- virus-writers are still not dead, contact Mr. Vesselin Bontchev (All
- Rights Reserved).
-
- So, never say die! Eddie lives on and on and on... Up the irons!"
-
- NOTE:
- Vesselin Bontchev, who the Dark Avenger is trying to discredit, is a
- leading virus researcher at the Bulgarian Academy of Sciences.
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++