Virus Database


Win32.Slow.8192.a

Description Win32.Slow.8192.a

It is a dangerous nonmemory resident parasitic Windows virus. It searches for PE EXE files (Windows executable files) in the C:, D: and E: drives directory trees and infects them. While infecting the virus compresses victim file with LZ-like method, overwrites the file with its code and appends to the end the victim compressed data. As a result of this way of infection the infected file size may be decreased. To return control back to the host file, the virus extracts it from infected body, unpacks, saves on disk and executes it.
The virus enumerates all active application and closes those of them that contain "AV" or "EB" sub-strings in the caption (AVP and DrWeb anti-virus programs). If AVP32 files are located, the virus overwrites the C:AUTOEXEC.BAT with two instructions that displays the text:
Wait: AVP is searching viruses nowall

and delete all files in the Windows directory.
The virus contains the text string:
[SMF.LZSLOW]

Check other viruses! Be aware! Use Antiviral Software

Fist Family

Description Fist Family

These are harmless encrypted parasitic viruses. They write themselves to the end of the file.
Fist.403,625
These are nonmemory resident viruses. They search for .COM files of current directory, and infect them. They contain the texts:
"Fist.403": *.COM Screaming Fist (c)1
"Fist.625": *.COM Screaming Fist (c)10/91

Fist.683
It is a memory resident not encrypted virus. It hooks INT 21h and infects .COM files that are accessed. It contains the text string:
Screaming Fist (c)10/91 C:COMMAND.COM COMSPEC=

Fist.692,696,711,732,838,855,862, Fist.Stranger
These are memory resident viruses. "Stranger.709.b" is not encrypted. They hook INT 21h and infect COM and EXE files including COMMAND.COM. They contain the texts:
"Fist.696,732": C:COMMAND.COM Screaming Fist II
"Fist.692,711": Screaming FistC:COMMAND.COM
"Fist.855,862": Screaming Fist IIC:COMMAND.COM
"Stranger.709.a": I am a stranger in a strange landall
"Stranger.709.b": I am a Stranger in KOREA ...

Fist.927

Description Fist.927

It's a harmless memory resident encrypted virus. It infects COM- and EXE-files and MBR of the hard disk in a standard way. The MBR is hit when an infected file is started. The virus saves its part and the MBR sector at the location 0/0/2 (track/head/sector). The virus infects memory while booting from an infected disk. After that it infects files only. The virus hooks INT 13h, 1Ch, 21h.
This virus is a MBR-generation of the "Fist" file viruses.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Privatkliniken I Karlskrona Ab
Pettersson, Chris
Ikon BegravningsbyrÅ
Andreas Bilmek I Lund
HUOVINENS BYGGSERVICE AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com