W32 Blebla B worm

W32.Blebla.B.worm

"Windows cannot find sysrnj.exe.
This program is needed for opening files of type …."

 

W32.Blebla.B.Worm
Computer Worm Virus

 

Suddenly my son had some problems on his PC.
We scanned his PC with Mc Afee and Norton and we found
189 infected files with Subseven, subseven plugins, JS Seeker and W32 Blebla B worm.

Subseven and JS Seeker are Trojans
W32 Blebla B worm is a update of W32 Blebla worm. It normally arrives in an email.
My son didn’t opened any email, he downloaded a game exe with a program named Kazaa
and after deleting the game, the problems were there.

W32.Blebla.B.Worm

It arrives as an email message that has a HTML body and 2 attachments.
When you read the message, the 2 attachments are AUTOMATICALLY saved and LAUNCHED.

W32 Blebla B worm

  • when a file is opened, the worm will move it to the C:\ recycled under a different name and replace it the original file with itself by adding .exe to it.
    Example: mygame.zip become mygame.zip.exe and this file is now the worm.
  • starting a program after quarantine the sysrnj.exe, you get a popup window with the message:
  • "Windows cannot find sysrnj.exe.
    This program is needed for opening files of type …."
  • The virus has also its own email engine and send messages to several addresses with Microsoft Outlook.
  • runs only under Windows 95/98/2000
  • the worm also change some registry keys

 

Removal instructions, how we did it.

We run antivirus program Norton and quarantined all the 189 files.
We didn’t look for any infected files, to many, hopeless.
After this when we tried to open a program we get always the message

"Windows cannot find sysrnj.exe.
This program is needed for opening files of type …."

  1. Stop the computer. Shut down and power must turn off at least 30 sec.
    (remove worm from memory, no reset )
  2. start computer
    (win 95 press F8 when you see Windows 95,
    win 98 during startup, hold down the Ctrl key)
  3. Windows startup menu appears during start up
  4. Press the number to start in Safe Mode ( 3 ) and enter
  5. Go to MS-DOS prompt
  6. Type copy regedit.exe regedit.com and enter
    ( C:\windows>copy regedit.exe regedit.com )
    1 file (s) copied
  7. type start regedit.com enter
  8. Go to HKEY_CLASSES_ROOT\.exe
    ( .exe and not exefile father down in the list )
  9. In the right side of the window double click on the " Default" or "Standard"
  10. An edit dialog box appears
  11. Delete or overwrite the value with exefile and click OK
  12. Go to HKEY_CLASSES_ROOT\rnjfile
    (more down in the list, rnjfile RNJFILE )
  13. Delete this rnjfile
  14. Go to the edit menu and click find
  15. in the find box enter rnjfile
    ( now all the infected keys are showed one by one, change the key and press F3 to go to the next one, but first begin with the first one, go to 16 )
    All this keys are in HKEY_LOCAL_MACHINE_SOFTWARE_CLASSES but you go there automatically, view left in window screen.
  16. .arj default double click and enter WinZip then F3
  17. .avi AVIFile and F3
  18. .bmp Paint.Picture
  19. .doc Word.Document.8 default value
  20. .gif giffile
  21. .jpeg jpegfile
  22. .jpe jpegfile ??
  23. .jpg jpegfile
  24. .LHA write nothing here, leave it empty
  25. .mp2 mpegfile
  26. .mp3 mp3file
  27. .mpeg mpegfile
  28. .mpg mpegfile
  29. .rar ….
  30. .reg regfile
  31. .vqf leave it empty
  32. .wma Winamp.File
  33. .wmf
  34. .wmv videofile
  35. .xls Excel.Sheet.8 default value
  36. .zip WinZip
  37. RESTART computer

Optional check:

look for files like
xromeo.exe and xromeo*.*
xjuliet.chm and xjuliet*.*
001.txt
002.txt
Sysrnj.exe and sysrnj*.*
Is a folder named HI found, delete it.

If the worm is run more then once the files have different names like xromeo.lgc, xromeo(1).exe, xjuliet(2).chm etc….
Delete all this files

That’s it.

More info here at Symantec

 


W32.Blebla.B.Worm


 

 

Virus scanners

Download this full trial version from AVP, see at Trial Versions
Anti Virus Experts: Your First, Last, and Only Line of Defense

Anti Virus Experts, FULLY FUNCTIONAL for 30 days


You're not alone.

This ??


 

  mailto  Michel Beyens

W32.Blebla.B.Worm | W32.CIH.Spacefiller | BAT.Chone worm | Navidad - Emanuel
Site map | Internet Explorer | email | Backdoors | PC | Macro Warning | Virus Warning

HomePage | Overview Pages
Calpe-Spain | Entertainment | Favorite | Hockey | Reefaquarium | Virus | Waterdog

Sign My GuestbookGo to GuestWorld LycosView My Guestbook