Sophos

W32/Looked-EC

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Infected files
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 11 February 2008 20:48:50 (GMT)
Detected by All Sophos products

Action

More Information

W32/Looked-EC is a virus and network worm for the Windows platform.

The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.

W32/Looked-EC is a virus and network worm for the Windows platform.

The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.

When first run the virus creates the following files:

<Windows>\rundl132.exe

and creates a file <Windows>\RichDll.dll, also detected as W32/Looked-EC. This file attempts to download further executable code.

Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.

The following registry entry is created to run rundl132.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load
<Windows>\uninstall\rundl132.exe

Registry entries are created under:

HKLM\SOFTWARE\Soft\DownloadWWW\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer