Sophos

Sophos blogs

W32/Looked-A

Aliases
  • Worm.Win32.Viking.j
  • W32/Gavir.worm
  • Win32/Viking.J
  • W32.Looked.I
  • PE_LOOKED.O-O
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Infected files
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 5 June 2006 21:00:16 (GMT)
Last updated 22 November 2006 06:12:43 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Looked-A is a Windows executable virus and network worm.

The virus infects EXE files found on the infected computer. The virus also attempts to copy itself to remote network shares. W32/Looked-A is a Windows executable virus and network worm.

The virus infects EXE files found on the infected computer. The virus also attempts to copy itself to remote network shares.

When first run the virus copies itself to <Windows folder>\rundl132.exe and creates a file <Windows folder>\vDll.dll, also detected as W32/Looked-A. This file attempts to download further malicious code.

Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows folder>\rundl132.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer