
BEWARE OF MINIZIP
WORM
MiniZip
is a
compressed variant of the original
ExploreZip worm,
it uses standard e-mail software such as
Outlook, Outlook Express and Exchange to
spread. It infects Windows 95/98/NT
systems and damages the data. It searches
for the files with extensions doc, xls,
ppt, h, asm, c, cpp in the local hard
drives and mapped drives and reduces the
file size to zero byte. So it is
impossible to recover the data from the
infected files. It will infect other
networked computers too.

MiniZip
worm uses two techniques to spread. First
one is automatic email reply to the mail
senders. This makes the virus to spread
rapidly. It will send an email attachment
"zipped_files.exe" with the
content "Hi
<Name>! I received your email and I
shall send you a reply ASAP. Till then,
take a look at the attached zipped docs
".
Second
method is infecting networked computers.
If one system is infected, it will spread
easily by dropping a file
"_setup.exe". Once rebooted it
will copy itself to
"explore.exe". To protect
networked computers, you should check all
the systems at one stretch.
Cleaning
Procedure:
This
virus can be cleaned manually. To clean
the virus in Windows95 and 98, Restart
the machine in DOS mode. Then delete
"Explore.exe" in the Windows
system directory. Search for
"_setup.exe" in the windows
directory. If found delete it. Using the
editor remove the entries
"Run=C:\windows\system\explore.exe"
and "Run=_setup.exe" in
"win.ini" file.
To
clean this virus in Windows NT, close all
the programs using Task Manager. Then
delete "Explore.exe" in the
WinNT system32 directory. Search for
"_setup.exe" in the WinNT
directory. If found delete it. MiniZip
virus will change the registry to load
automatically on every boot. To remove
this, open the registry using
"regedit.exe" and modify the
key value from "run
c:\windowsNT\system32\explore.exe"
to empty in the registry entry
"HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\Current
Version\Windows".
How can I
protect my system?
Fire has
incorporated MiniZip into its virus
signature file, with the aim of helping
users affected by this Worm attack to
detect and eliminate it from their
systems. Fire anti-virus users can update
this signature file from our web site. A
free utility also available to detect and
clean this virus in Download
Center.

|