W32/Looked-A is a Windows executable virus and network worm.
When first run the virus copies itself to <Windows>\rundl132.exe and creates a file <Windows>\vDll.dll, also detected as W32/Looked-A. This file attempts to download further malicious code.
The virus infects EXE files found on the infected computer. The virus also attempts to copy itself to remote network shares.
Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.
The following registry entry is created in order to run the virus on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe