
ExploreZip Worm
information
about ExploreZip worm:
ExploreZip
aka [I-Worm/Zipped Files] is a
destructive e-mail worm, it uses standard
e-mail software such as Outlook, Outlook
Express and Exchange to spread. It
infects Windows 95/98/NT systems and
damages the data. It searches for
the files with extensions doc, xls, ppt,
h, asm, c, cpp in the local hard drives
and mapped drives and reduces the file
size to zero byte. So it is
impossible to recover the data from the
infected files. It will infect other
networked computers too.

ExploreZip
worm uses two techniques to spread. First
one is automatic email reply to the mail
senders. This makes the virus to spread
rapidly. It will send an email attachment
"zipped_files.exe" with the
content "Hi
<Name>! I received your email and I
shall send you a reply ASAP. Till then,
take a look at the attached zipped docs
".
Second
method is infecting networked computers.
If one system is infected, it will spread
easily by dropping a file
"_setup.exe". Once rebooted it
will copy itself to
"explore.exe". To protect
networked computers, you should check all
the systems at one stretch.
Removing
ExploreZip worm from your system:
This
virus can be cleaned manually. To clean
the virus in Windows95 and 98, Restart
the machine in DOS mode. Then delete
"Explore.exe" in the Windows
system directory. Search for
"_setup.exe" in the windows
directory. If found delete it. Using the
editor remove the entries
"Run=C:\windows\system\explore.exe"
and "Run=_setup.exe" in
"win.ini" file.
To
clean this virus in Windows NT, close all
the programs using Task Manager. Then
delete "Explore.exe" in the
WinNT system32 directory. Search for
"_setup.exe" in the WinNT
directory. If found delete it. ExploreZip
virus will change the registry to load
automatically on every boot. To remove
this, open the registry using
"regedit.exe" and modify the
key value from "run
c:\windowsNT\system32\explore.exe"
to empty in the registry entry
"HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\Current
Version\Windows".
You
can check the system manually. This worm
creates "explore.exe" in
windows system folder. The presence of
"explore.exe" ensures you are
infected with this worm. A free
download [18KB]
is available to detect
and clean this worm.
To
find other viruses use our FireLite
version. A free download
of FireLite
[ 1100KB
]
version is available to detect
all viruses. If you find any virus, use
registered windows version of Fire to
remove. To get the registered version of
Fire call us at 044-28170440 or
mail to service@fireav.com
or
purchase Fire online using

|