Fairz is a memory resident, encrypted COM and EXE infector. If an infected file is executed the virus modifies the interrupts INT 1 (single step) and INT 3 (break point) services so as to make its analysis more difficult. In addition to that it uses the interrupt INT 3 service for decoding the rest of the virus body. It attacks files when they are executed and opened. The virus marks infected files so that it levels their lengths to multiples of 16. It does not contain any destructive activity. Only in case that a fragment of the virus Keypress is found in the file the following text is displayed:

This is an [ illegal copy ] of KeyPress virus remover System halted

and the computer “freezes”. In the virus body there is the following encrypted string:

Eternal Fair

