Search Solo Products, Services and others Overview of the Site Design and Build a Career Contact us for customer service and other feedback info SRN Micro Privacy Statement

 


BEWARE OF W32/FUNLOVE VIRUS

Virus Name  : W32/FunLove

Alias             : FLC, W32.FunLove.4099, PE_FunLove

Virus type    : PE File Infector

Threat level : Medium

Virus details :

                     This virus is a Win32 PE file virus infects EXE, SCR, OCX files under Win9x and WinNT 4.0 platforms. The infected files will increase by 4099 bytes. What is notable about this virus is that it uses a new strategy to attack the Windows NT file security system and it runs as a service on Windows NT systems.

                     When the virus is first run, it drops a file called FLCSS.EXE into the SYSTEM folder. Then it directly infects all EXE, SCR, and OCX files in the folders Program Files and WINDOWS/WINNT, including any sub folders. It infects network shared drives too.

                     Under Windows NT it modifies the files NTOSKRNL.EXE and NTLDR if the current user is logged in with administrator rights. The modified files will activated after the next system restart, allows all users full administrator rights to the system. So any low level user can access the network with administrator rights.

                     The NTOSKRNL.EXE and NTLDR patches are executed by a routine picked up from the Bolzano virus. In fact, more than fifty percent of the virus code shows similarities to the Bolzano virus. It is very likely that the author of these two viruses is the same person.

                     When executed under DOS, the file FLCSS.EXE displays the message "~Fun Loving Criminal~" and then tries to reset the machine in order to load Windows.

The virus does not infect files that begin with the following characters in their names: aler, amon, avp, avp3, avpm, f-pr, navw, scan, smss, ddhe, dpla and mpla. Solo detects and removes W32/Funlove virus safely.

How can I protect my system?

                   Solo has incorporated  W32/FunLove in its signature file to protect users from this virus attack. Solo antivirus registered users are already protected from this virus. Make sure that you have installed registered version of Solo Antivirus to protect your system from all virus threats.

How to remove Win32/FunLove virus?

                   If you are already infected with this virus, you can remove it from your computer using Solo Antivirus software. Solo antivirus can detect and remove FunLove virus safely. Use the following link to Download 30 day trial version of Solo antivirus to remove viruses from your computer. A free utility is available to detect and clean this virus in Download Center.

                   Solo anti-virus not only scans for all viruses, it contains a unique System Integrity Checker to protect you from New Internet Worms, Backdoors and malicious VB, Java Scripts. It also effectively removes all existing Internet Worms, File viruses, malicious VB, Java scripts, Trojans, Backdoors, boot sector, partition table and macro viruses.

You can purchase Solo antivirus using the link