W32/Blebla@mm.Worm

Download VIRUSfighter NOW
W32/Blebla@mm.Worm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 11/16/2000 • Type: Worm
• Virus characteristics first published: 11/16/2000 • Spreading mechanism: Email
• Virus characteristics latest update: 3/17/2004 • Overall risk: Low
• Alias: W32/Verona • Payload:
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: (several - see details below)
  • Body:
  • Attachment: MyJuliet.chm and MyRomeo.exe
The worm consists of two different files; MyJuliet.chm and MyRomeo.exe. These files are included in the e-mail as regular attachments. However, once the offending mail is opened in Outlook, the files will be saved to disk in the temp folder. The CHM file is run directly, and will in turn start the EXE file.

The MyRomeo.exe is a regular Win32 EXE file, written in Delphi and compressed using the well-known compressor UPX. When run it will access the user's Outlook Address Book and send itself to addresses listed there. The e-mail is sent through one out of six different Polish mail servers.

The mail will arrive with one out of twelve different subjects:
  • Romeo&Juliet
  • ::))))))
  • hello world
  • !!??!?!?
  • subject
  • ble bla, bee
  • I Love You ;)
  • sorry...
  • Hey you !
  • Matrix has you...
  • my picture
  • 'from shake-beer


Variants


W32/Blebla.B


This variant will arrive in email with one of the following subjects:

  • Romeo&Juliet
  • where is my Juliet ?
  • where is my romeo ?
  • Hi · last wish ???
  • Lol :)
  • ,,...
  • !!!
  • newborn
  • merry christmas!
  • surprise !
  • Caution : NEW VIRUS !
  • Scandal !
  • ^_^
  • Re:


W32/Blebla.B sends a message to the news group alt.comp.virus.

From: "Romeo&Juliet" <romeo@juliet.v>
Subject:[Romeo&Juliet] R.i.P.


Upon execution the worm copies itself to c:\windows\sysrnj.exe. It then modifies the Registry to executed itself when any file with one of the extensions mentioned below is opened.

The .B variant of the worm creates a new Registry key
HKEY_CLASSES_ROOT\rnjfile
\DefaultIcon=%1
\shell\open\command=sysrnj.exe "%1"%*


and then modifies the following keys so every file with one of these file types will be associated with rnjfile and opened by sysrnj.exe (defined in the abovementioned Registry key). The (Default) value in each of the following keys is changed to rnjfile

HKEY_CLASSES_ROOT
\.exe
\.jpg
\.jpeg
\.jpe
\.bmp
\.gif
\.avi
\.mpg
\.mpeg
\.wmf
\.wma
\.wmv
\.mp3
\.mp2
\.vqf
\.doc
\.xls
\.zip
\.rar
\.lha
\.arj
\.reg

# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter