Symantec.com > Security Response > Threats and Risks > W32.ExploreZip.L.Worm

W32.ExploreZip.L.Worm - Removal

Risk Level 2: Low

Printer Friendly Page

Discovered: January 10, 2003
Updated: February 13, 2007 11:59:24 AM
Also Known As: W32/ExploreZip.worm@M [McAfee], I-Worm.ZippedFiles.h [KAV], WORM_EXPLORZIP.M [Trend], Win32/ExploreZip.Worm [CA], W32/ExploreZip.E [F-Secure], W32/ExploreZip.worm.210432 [F-, W32/ExploreZi-N [Sophos]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


To manually remove this worm, follow the steps that apply to your version of Windows:
  • Windows 95/98/Me

    NOTE for Windows Me users only: Due to the file-protection process in Windows Me, a backup copy of the file you are to edit exists in the C:\Windows\Recent folder. Symantec recommends that you delete this file before you continue with the steps in this section. To do this using Windows Explorer, go to C:\Windows\Recent, and in the right pane select the Win.ini file, and then delete it. The file will be regenerated as a copy of the file you are to edit when you save your changes to that particular file.
    1. Click Start, and then click Run.
    2. Type the following:

      edit c:\windows\win.ini

      and then click OK.

      (The MS-DOS Editor opens.)

      NOTE: If Windows is installed in a different location, make the appropriate path substitution.
    3. In the [windows] section of the file, look for an entry similar to one of the following:

      run=?\Explore.exe
      run=?\_setup.exe
    4. If either of these entries exists, select the entire line. Make sure that you have not selected any other text, and then press Delete.
    5. Restart the computer.
    6. Open Windows Explorer.
    7. Navigate to the C:\Windows\System folder and, depending on which file name appeared in the run= line, delete Explore.exe or _setup.exe.

  • Windows NT/2000/XP
    1. Start the Registry Editor (Regedit.exe).
    2. Navigate to the following key:

      HKEY_CURRENT_USER\Software\Microsoft\
      WindowsNT\CurrentVersion\Windows\Run

      and remove the entry that refers to "Explore.exe" or "_setup.exe."
    3. Restart the computer, or kill the process using the Task Manager or Process View, if the file is currently in use.
    4. Depending on which file name appeared in the run line, delete Explore.exe or _setup.exe from the C:\Winnt\System32 folder.

NOTE: For information on file recovery, see the Norton Utilities document, Error: "Cannot open file... if part of a ZIP format backup set..." and the Size of Many Files is Zero.

Writeup By: Jari Kytojoki
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security