Discovered: January 10, 2003
Updated: February 13, 2007 11:59:24 AM
Also Known As: W32/ExploreZip.worm@M [McAfee], I-Worm.ZippedFiles.h [KAV], WORM_EXPLORZIP.M [Trend], Win32/ExploreZip.Worm [CA], W32/ExploreZip.E [F-Secure], W32/ExploreZip.worm.210432 [F-, W32/ExploreZi-N [Sophos]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
To manually remove this worm, follow the steps that apply to your version of Windows:
- Windows 95/98/Me
NOTE for Windows Me users only: Due to the file-protection process in Windows Me, a backup copy of the file you are to edit exists in the C:\Windows\Recent folder. Symantec recommends that you delete this file before you continue with the steps in this section. To do this using Windows Explorer, go to C:\Windows\Recent, and in the right pane select the Win.ini file, and then delete it. The file will be regenerated as a copy of the file you are to edit when you save your changes to that particular file.
- Click Start, and then click Run.
- Type the following:
edit c:\windows\win.ini
and then click OK.
(The MS-DOS Editor opens.)
NOTE: If Windows is installed in a different location, make the appropriate path substitution.
- In the [windows] section of the file, look for an entry similar to one of the following:
run=?\Explore.exe
run=?\_setup.exe
- If either of these entries exists, select the entire line. Make sure that you have not selected any other text, and then press Delete.
- Restart the computer.
- Open Windows Explorer.
- Navigate to the C:\Windows\System folder and, depending on which file name appeared in the run= line, delete Explore.exe or _setup.exe.
- Windows NT/2000/XP
- Start the Registry Editor (Regedit.exe).
- Navigate to the following key:
HKEY_CURRENT_USER\Software\Microsoft\
WindowsNT\CurrentVersion\Windows\Run
and remove the entry that refers to "Explore.exe" or "_setup.exe."
- Restart the computer, or kill the process using the Task Manager or Process View, if the file is currently in use.
- Depending on which file name appeared in the run line, delete Explore.exe or _setup.exe from the C:\Winnt\System32 folder.
NOTE: For information on file recovery, see the Norton Utilities document,
Error: "Cannot open file... if part of a ZIP format backup set..." and the Size of Many Files is Zero.
Writeup By: Jari Kytojoki