Virus Protection > computer-virus-f-page1 > - face.252

face.252

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
Face.2521

It's a not dangerous memory resident parasitic virus. It hits COM-, EXE- and SYS-files. On execution of infected COM- or EXE-file the virus reads the C:\CONFIG.SYS file and writes itself to the beginning of first SYS-file that is marked in CONFIG.SYS, and then the virus returns control to the host program. On loading of infected SYS-file the virus stays memory resident and hooks INT 21h. Then the virus writes itself to the end of COM- and EXE-files (except COMMAND.COM) that are executed. Sometimes it launches a running face (ASCII 1) on the screen. It contains the internal text string:
COMMAND.COMEXECOMSPEC=C:\CONFIG.SYS DEVICE

Updated: 02/24/2006
Copyright @2006 face.252
Webroot Software Inc.