Sophos

W32/Looked-L

Aliases
  • Worm.Win32.Viking.x
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Infected files
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 31 August 2006 05:53:18 (GMT)
Last updated 26 April 2008 20:30:06 (GMT)
Detected by All Sophos products

Action

More Information

W32/Looked-L is a virus for the Windows platform.

The virus includes functionalities to

- access the internet and communicate with a remote server via HTTP
- silently download, install and run new software
- terminate processes related to AV

When first run W32/Looked-L copies itself to <Windows>\rundl132.exe and <Windows>\logo1_.exe and creates the file viDll.dll in the current folder. This file is also detected as W32/Looked-L.

The virus infects EXE files found on the infected computer. The virus also attempts to copy itself to remote network shares.

Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe

W32/Looked-L terminates processes with the following process names:

EGHOST.EXE
IPARMOR.EXE
KAVPFW.EXE
MAILMON.EXE
mcshield.exe
RavMon.exe
Ravmond.EXE
regsvc.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer