Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | November 2006 (4.11) |
| Protection available since | 30 September 2006 14:25:11 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please read the instructions for removing W32/Looked-AB.
More Information
W32/Looked-AB is a virus for the Windows platform.
The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.
When first run the virus copies itself to <Windows>\rundl132.exe and creates a file <Windows>\Dll.dll, also detected as W32/Looked-AB. This file attempts to download further executable code. W32/Looked-AB is a virus for the Windows platform.
The virus infects EXE files found on the infected computer and attempts to spread to remote network shares with weak passwords.
When first run the virus copies itself to <Windows>\rundl132.exe and creates a file <Windows>\Dll.dll, also detected as W32/Looked-AB. This file attempts to download further executable code.
The following registry entry is created to run rundl132.exe on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe
Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.
