W32.LOOKED.P - cleanable?

CeeBee

Expert Member
Joined
Jul 27, 2006
Messages
2,281
Reaction score
101
Location
Pta mostly
Any advice from Antivirus experts or anybody with similar exp will be welcome!
We've picked up on one of our servers the virus/worm W32.LOOKED.P, that apparently affects exe in shared folders.
Dunno why this server, that gets the antivirus updates first, and is actually the antivirus manage server, did not pick it up and stop it before causing ****, only after infecting the exes did it quarantine them.
And it seems to be unable to clean the files of the infection :mad::sick:

Anybody know of a tool/program to clean the infected files so I can restore?
 
which antivir u using?

According to symantec it's not very common at all so you're quite unlucky. Sophos has some removal instructions if you use their product.

Here's manual remonal instructions:

MANUAL REMOVAL:

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Reboot computer in SafeMode.
4. Run a full system scan and delete all files it detected.
5. Delete any values added to the registry.Navigate to the subkey and delete the value:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Value:
"load" = "%Windir%\rundl132.exe"

Navigate to and delete the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Soft\DownloadWWW

6. Exit registry editor and restart the computer.
7. In order to make sure that W32.Looked.P is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.
 
Last edited:
thanx for advice,
we use Symantec Antivirus Corp, on our network.
its strange that some computers only quarantine the worm after it's screwed ups some exes, while others stop it immidiately. Removing the frigging thing from pc is one thing, but need to clean the infected files tooo.
I don't find anything on the server of the registry keys, so looks like its stopped, only issue is to get the infected exes cleaned from the quarantine area. Symantec just tunes me clean failed.

edit... I got a w32looked fixer tool from Cyber Detectives, so I disabled Realtime protection and restored all the files, then run the tool, ... seems to have fixed most (all?), and found some other nasties in registry, fixed.
It is a bit worrying to see how many files it deleted... suppose I'll only know if it was a needed file when i need it....

I see w32.jeefo are also quite a lot.
Strange thing is that Symantec shows the looked and jeefo viruses/worms as LOW risk.... doh! not to me when it deletes exes and cannot be cleaned!
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X