When the attached "ZIPPED_FILES.EXE" file is double clicked, it decompresses and places EXPLORE.EXE in your WINDOWSSYSTEM directory. It then proceeds to delete the data in Microsoft Word, Excel and PowerPoint files as well as assembly, C and C++ source files. You wind up with file names with 0 bytes. It also spreads to all the machines attached to the network.
Actual Damage
This is a small part of the damage done to one machine from the Worm.ExploreZip virus. Note that only the Microsoft files (Word, Excel and PowerPoint) were destroyed. This is one of those unfortunate times when you understand what offline backup really means.
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2008 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- Enterprise password management really isn't a good idea
- Being at a university and working for a government department allows me to understand this concept well. There are shared resources here, there and everywhere, provided by different people and providers, all open to a "certain type" of person - employees or students. By having a single sign-on SSO point...
- Blog posts 2008-09-05
- VMworld is bringing out the vendors
- Planning for an announcement is a challenging task. Large suppliers know that just about whatever they do will be picked up by the media and presented to the world. Smaller vendors have a much more difficult time getting heard. So, picking the right place and time for an announcement is...
- Blog posts 2008-09-05
- Should political postings stay or go? A survey.
- I've been blogging for ZD Net for several years, writing for ZD publications for almost 20 years. I've always found readers to be intelligent and thoughtful, which is why I continue to do this while doing other things as "work." My posting, A virus in your genes, think about that,...
- Blog posts 2008-09-04
- Critical WMP, MS Office bugs on Patch Tuesday swat list
- Microsoft today announced plans to ship four security bulletins next Tuesday (September 9, 2008) to cover worm holes affecting Windows users. All four bulletins in September's Patch Tuesday will be rated "critical," Microsoft's highest severity rating. A "critical" rating is used to rate a vulnerability that can...
- Blog posts 2008-09-04
- News to know: Oracle's Fusion guru quits; Dell; Windows 7 boot times
- Here are today's notable headlines. You can get News To Know via email alert and RSS daily: Dennis Howlett: Breaking: Oracle's Andersen gone, where now for Fusion and vertical plays? Adrian Kingsley-Hughes: New dual/quad core CPUs enter Intel price list, AMD drops prices ...
- Blog posts 2008-09-04
- A virus in our genes, think about that....
- A virus in our genes, think about that....Not bad...You were doing good until about halfway through the post, when you might as well have pulled out your Barack Hussein Obama flag and waved it from the rooftops.Your gallop off into politics ruined what would otherwise have been a good read.RE:...
- Discussion threads 2008-09-03
- Anyone bothering with client-side AV anymore?
- Anyone bothering with client-side AV anymore?God help your state’s taxpayers.God help your state’s taxpayers. Anyone who would take your view of client side protection in a school is incompetent.Since I use Linux for servers and clients...I only use ClamAV to scan inbound email.RE: Anyone bothering with client-side AV anymore?Do...
- Discussion threads 2008-09-03
- A virus in our genes, think about that....
- Really fascinating news: Virus is passed from parent to child in the DNA. Researchers found that roseola, an infection that everyone apparently gets but only 20 percent of children develop the characteristic rash that gives it its name, is actually in our DNA. It co-evolved into us, which raises some...
- Blog posts 2008-09-03
- Svchost Fix Wizard (exe)
- Get rid of Svchost error messages and fix Svchost performance problems like Svchost taking 100% CPU in one click with this automated Fix Wizard. The program fixes all known modifications of Svchost errors including generic host process error messages, performance issues and svchost virus infection. Additionally, live support will help...
- Software downloads 2008-09-03
- Sanmaxi Word File Repair (exe)
- Word File Repair Software repair restores damaged unoperable word files after instances of virus attacks, unexpected system shutdown, error opening file, and software crash. Repairing the corruptions in the corrupted words document files.This version is the first release on CNET Download.com.
- Software downloads 2008-09-03
- Sanmaxi PowerPoint File Repair (zip)
- MS Powerpoint file repair software repairs corrupt PowerPoint Presentation files. PowerPoint repair tool .ppt file repair program repairs Microsoft PowerPoint presentation files which are corrupted due to virus attacks or improper system shutdown. Demo version shows preview of repaired files. This version is the first release on CNET Download.com.
- Software downloads 2008-09-03
- Novaxe (exe)
- Novaxe is a report management tool used to enforce network security over the enterprise. His task is to read events from firewall log files, organize traffic flows and present data to the network administrator. Novaxe makes the inspection of data easy and allows quick detection of anomalies such users who...
- Software downloads 2008-09-03
- Sanmaxi Access File Repair (exe)
- Access database repair software repairs corrupt MDB files restore damaged access databases. Access repair software repair corrupt mdb files that can not be opened due to corruption like virus attacks, sudden system shutdown, and software corruption. Demo version shows preview of repaired files. This version is the first release on...
- Software downloads 2008-09-03
- NASA confirms infection, 'not the first time'
- NASA confirms infection, 'not the first time'Kind of makes me wonder.Why is Windows used at all? Infected through laptops in the upload link. Is WMP or Photoshop the official lock in of the space station? There is obviously a huge infrastructure in place to prevent infections. ...
- Discussion threads 2008-09-02
- NASA confirms infection, 'not the first time'
- As I noted a few days ago, the International Space Station has a virus, which NASA now confirms. From eFlux, a spokesperson explained: "This is not the first time we have had a worm or a virus," said NASA spokesman Kelly Humphries during a press...
- Blog posts 2008-09-02
- Migo Recover Lost Data (exe)
- Whether you accidentally deleted a file from your computer, suffered a hard drive crash, or experienced loss of data due to a virus infection, Migo Recover Lost Data offers a safe, fast and easy way to restore your valuable documents and digital memories. Version 3.1.2.1C includes unspecified updates.
- Software downloads 2008-09-02
- Windows Live Messenger 9 (What's new in Windows Live Messenger 9 )
- Windows Live Messenger 9 (What's new in Windows Live Messenger 9 )Whats the deal with OneCare?You mention that one should install the OneCare antivirus, but let me tell you this, you can very well make WLM use any antivirus scanner to scan recieved files. For e.g. you can use...
- Discussion threads 2008-09-01
- Anti-Virus Lab (msi)
- Anti-Virus Lab is a spyware, adware, and virus scanner and remover. With an up-to-date virus database, Anti-Virus Lab is able to search for and remove all viruses and malware on your computer. Anti-Virus Lab will neatly list all malware detected on your system and remove them with ease. With the...
- Software downloads 2008-09-01
- Weekend Gadget Guidance: Speed up Vista installation via thumb drive
- Weekend Gadget Guidance: Speed up Vista installation via thumb driveHate to say this...I never have to do a periodic re-install of the OS on my Mac. OK, let the games begin...My speedy install method is ...1. Reformat the hard disk with lots of partitions for different OS's, one for...
- Discussion threads 2008-08-29
- ZoneAlarm Internet Security Suite 2009
- The improvements within Check Point ZoneAlarm Internet Security 2009 are mostly under the hood, but they are nonetheless significant. Optimizing the resources for desktop and laptop Windows users is important within a suite of tools, and long-time ZoneAlarm users will notice the benefits almost immediately. There's a new user interface,...
- Product reviews 2008-08-28
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Which solar technology will survive?
-
At the Cleantech Forum in San Francisco, Todd Glass of Heller Ehrman moderates a discussion, among tech execs, on the various solar technologies making a difference in the green movement.
- Watch the video >>
- Demo: Virtualization with the Intel® Xeon® Processor
-
In this Flash demo, you'll learn about virtualization performance and features ideal for consolidation, load balancing, and disaster recovery with leading enterprise reliability.
- Watch how the Intel Xeon processor can increase performance and reliability of your servers >>
Ultraportables
- Understanding Ultraportable Laptops (BNET)
- Five steps to protect mobile devices anywhere, anytime (TechRepublic)
- View all ZDNet Toshiba laptop reviews
- From our sponsors
- Toshiba Satellite® U400 Series
-
- The ultra-portable, ultra-stylish Satellite® U405 is a smart choice for you and your small business. Only from the laptop expert, Toshiba. Explore the complete laptop lineup »



