Sophos

W32/Looked-EI

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Infected files
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from August 2008 (4.32)
Protection available since 30 June 2008 00:55:44 (GMT)
Detected by All Sophos products

Action

More Information

W32/Looked-EI infects executable files on the computer. It also attempts to copy itself to network shares.

W32/Looked-EI drops the files
<Windows>\dll.dll - detected as W32/Looked-W.
<Windows>\rundl132.exe - detected as W32/Looked-EI
<Windows>\logo1_.exe - detected as W32/Looked-EI

W32/Looked-EI edits the registry value:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer