PDA

View Full Version : FunLove Virus or WHAT...?



Smitty
12-02-2001, 02:52 AM
Internet Explorer 5.5SP2 has been acting up so I did local virus scan with McAfee...nothing

I paid a visit to Housecall for their free scan...nothing

Still not satisfied I ran Regclean and examined log file. Noticed references to "misc.exe", perhaps 6 or 7 keys removed by regclean..

Ran a search for the file and found it..While searching I noticed "bindico.exe" so I searched web and found several contradictory webpages. One below indicates it is associated with a virus. [W32.FunLove.4099]
Another indicated it was an ICON used with Access or some other office application.

I also found on my drive executables which are not found on the web using GOOGLE. For example
I found _24ef2a94.exein folder C:\WINDOWS\Application Data\Microsoft\Installer\{8918AD50-F8D8-4E5C-A2DE-08C1B275B3B4}
bindico.exe in folder C:\WINDOWS\Application Data\Microsoft\Installer\{00170409-78E1-11D2-B60F-006097C998E7}

Searching the web I found this entry included in the log of an "infected machine:"

D:\WINNT\Installer\{00010409-78E1-11D2-B60F-006097C998E7}\bindico.exe
Virus name: W32.FunLove.4099

I went to Symantec and downloaded their FunLove virus removal tool, booted to DOS, ran the tool and it reports no infected files.

My question is, has anyone else found these files on their machines, are they trojan's, or do you have any knowledge of them?

Thanks for any and all responses.


Smitty

james3mg
12-02-2001, 07:16 AM
allright...I've got office 2000, and the first 2 files mentioned have icons that do APPEAR to be office icons I've seen. Doesn't mean anything, but a few similarities, and this machine isn't having any virus problems. So Misc.exe and bindico.exe, unlikely as they sound, seem to check out, at least with me. May try to find an install log with Office and see if it extracts those files.

_24ef2a94.exe I don't have...you may have stuff installed that I don't that extracted it, but who knows. Sorry I can't help much, maybe someone more knowledgable?

Smitty
12-02-2001, 07:46 AM
james3mg

Thanks for feedback..posted this on Tek-Tips forum also and reghakr responded similarily. I assume each of us has some "trash left over" from various installs/uninstalls as you mentioned. BTW, you can see the reason for my confusion if you check this link out.

<a target="_blank" href=http://lsp.memphis.edu/email/April2000/msg00046.html>http://lsp.memphis.edu/email/April2000/msg00046.html</a>

search for "bindico.exe" and I go what..??

Thanks again


Smitty