| 
 The information in this article applies to: 
 IMPORTANT: This article contains information about editing the registry. Before you edit the registry, make sure you understand how to restore it if a problem occurs. For information about how to do this, view the "Restoring the Registry" Help topic in Regedit.exe or the "Restoring a Registry Key" Help topic in Regedt32.exe. SUMMARYWorm.Explore.Zip is a worm or Trojan horse that uses Messaging Application Program Interface (MAPI) capable e-mail programs on Windows-based computers to propagate itself. MORE INFORMATIONThe worm uses MAPI commands to propagate itself. An e-mail message is created with the worm as an attachment using the Zipped_files.exe filename. The body of the e-mail message may appear to come from a known e-mail correspondent and may contain the following text: Hi Recipient Name !The worm determines who to send mail to and what names to use based on the contents of the user's Inbox. You should delete any mail containing an attachment with the name "Zipped_files.exe" without opening the attachment. If you run the attachment, you may receive the following error message: Explore.Zip copies itself to the C:\%SystemRoot%\System folder with the filename Explore.exe and then modifies the Win.ini file to run itself each time Windows is started. The worm then uses your e-mail client to collect e-mail addresses to propagate itself. Additionally, Explore.Zip also searches all local and network mapped drives of your computer and arbitrarily selects a series of files to destroy by setting the file size to 0 bytes. This can result in data loss. Normal methods of virus protection should be employed to protect your environment from this virus. Virus scanning programs should be updated with the latest signature files and any other appropriate steps to prevent the virus from entering your environment should be employed. Specific questions regarding your virus software's ability to detect and clean this virus should be directed to your Anti-Virus software vendor. To remove the worm virus on the client side, perform the following steps: For Windows 95 or Windows 98
 Run = c:\windows\system\explore.exe For information about how to edit the registry, view the "Changing Keys and Values" Help topic in Registry Editor (Regedit.exe) or the "Add and Delete Information in the Registry" and "Edit Registry Data" Help topics in Regedt32.exe. Note that you should back up the registry before you edit it. If you are running Windows NT, you should also update your Emergency Repair Disk (ERD). For Windows NT
 Outlook Attachment Security PatchFor additional information about Outlook and security for e-mail attachments, please see the following article in the Microsoft Knowledge Base:Q235309 Outlook E-mail Attachment Security UpdateThe following sites contain additional information on the ExploreZip worm: Symantec: http://www.symantec.com/ Additional query words: 
Keywords          : kbenv kbnetwork ntsecurity  | 
| Last Reviewed: June 30, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |