face.252
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Face.2521
It's a not dangerous memory resident parasitic virus. It hits COM-, EXE- and SYS-files. On execution of infected COM- or EXE-file the virus reads the C:\CONFIG.SYS file and writes itself to the beginning of first SYS-file that is marked in CONFIG.SYS, and then the virus returns control to the host program. On loading of infected SYS-file the virus stays memory resident and hooks INT 21h. Then the virus writes itself to the end of COM- and EXE-files (except COMMAND.COM) that are executed. Sometimes it launches a running face (ASCII 1) on the screen. It contains the internal text string:
COMMAND.COMEXECOMSPEC=C:\CONFIG.SYS DEVICE
Copyright @2006 face.252