W32.Looked
Aliases: Virus.Win32.Delf.62976, W32/HLLP.Philis.j, Net-Worm.Win32.Zorin.a, Worm.Win32.Zorin.a, W32.Looked.B
Variants: Win32.HLLW.Looked, W32/LegMir-X, PE_LEOX.A, BehavesLike:Win32.FileInfector, NewHeur_PE
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Moderate
Geographical info: N/A
Removal: Easy
Platform: W32
Discovered: 17 Dec 2004
Damage: Medium
Characteristics: The W32.Looked is designed with certain similarities to viruses in the context that it attempts to target and infect files that use the EXE file extension. It scans the contents of the infected machine to search for more executable files. It has been observed by various computer experts to spread its codes using mainly shared folders as transport mechanism. This malware is capable of downloading files into the infected computer system and executing it.
W32.Looked Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Looked from your computer.
More details about W32.Looked
Computer systems which are infected with the W32.Looked will experience the illegal terminations of certain security firewall programs running in the machine. The malware will also attempt to stop other security related processes active in the computer system background. This routine is intended to lower the system's security settings and make it more vulnerable to attack. The W32.Looked will create a new Dynamic Link Library file into its directory folder location and uses it to hook functionalities of the Web browser. The hooked browser will be used to download a password thief malware that will be introduced into the already infected machine. Executable files in all logical, removable, and network drives identified in the compromised computer system will be corrupted by the W32.Looked malware.The malicious author of the W32.Looked malware designed the threat to avoid infecting executable files stored in directory locations that contain specific text strings. This is presumed to be a ploy to maintain the infected computer system's operation to make it a transport mechanism to spread infection. A file infected by the W32.Looked will experience an increase in size due to the additional codes that are added at the beginning of the file. An executable file copy of itself will be placed into the operating system directory. The W32.Looked will use unprotected network shares to send a copy of itself.
Browse for more malware information
- W32.Looked
- W32.Looksky.A@mm
- W32.Lorac
- W32.Losabel
- W32.Lovena.A@mm
- W32.Lovgate.AB@mm
- W32.Loxbot.A
- W32.Lunalight@mm
- W32.Mabezat.A
- W32.Madag.A
- W32.Madangel
- W32.Maddis.B
- W32.Mafeg
- W32.Magflag.A@mm
- W32.Mailbancos@mm
- W32.Maldal.C@mm
- W32.Mancsyn
- W32.Mandaph
- W32.Maniccum
- W32.Mant.Worm
- W32.Mapson.C.Worm
- W32.Mari@mm
- W32.Marque.Worm
- W32.Masy.Worm
- W32.Matcher.Worm
- W32.Mdmbot
- W32.Medbot.A
- W32.Meetot
- W32.Melting.Worm
- W32.Mertian.Worm