Sophos

W32/Looked-Y

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Infected files
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from February 2009 (4.38)
Protection available since 22 September 2006 05:34:53 (GMT)
Last updated 5 December 2008 05:27:30 (GMT)
Detected by All Sophos products

Action

More Information

W32/Looked-Y is a Windows executable virus and network worm.

The virus includes functionalities to:

- access the internet and communicate with a remote server via HTTP
- disable AV related processes
- silently download, install and run new software

When first run W32/Looked-Y copies itself to <Windows>\rundl132.exe and creates the file <Windows>\Dll.dll. This file is also detected as W32/Looked-S.

The virus infects EXE files found on the infected computer. The virus also attempts to copy itself to remote network shares.

Many files with the name "_desktop.ini" are created, in various folders on the infected computer. These files are harmless text files.

The following registry entry is created in order to run the virus on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer