Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 11 February 2008 20:48:50 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for disinfecting PE executables.
More Information
W32/Looked-EC is a virus and network worm for the Windows platform.
The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.
The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.
When first run the virus creates the following files:
<Windows>\rundl132.exe
and creates a file <Windows>\RichDll.dll, also detected as W32/Looked-EC. This file attempts to download further executable code.
Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.
The following registry entry is created to run rundl132.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load
<Windows>\uninstall\rundl132.exe
Registry entries are created under:
HKLM\SOFTWARE\Soft\DownloadWWW\
