Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 30 September 2006 14:25:11 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for disinfecting PE executables.
Please read the instructions for removing W32/Looked-AB.
More Information
W32/Looked-AB is a virus for the Windows platform.
The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.
When first run the virus copies itself to <Windows>\rundl132.exe and creates a file <Windows>\Dll.dll, also detected as W32/Looked-AB. This file attempts to download further executable code. W32/Looked-AB is a virus for the Windows platform.
The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.
When first run the virus copies itself to <Windows>\rundl132.exe and creates a file <Windows>\Dll.dll, also detected as W32/Looked-AB. This file attempts to download further executable code.
The following registry entry is created to run rundl132.exe on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe
Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.
