View Full Version : Virus changed my registry
gentlebreeze
10-04-2001, 06:44 AM
Hi, I have a very complicated problem that has rendered my computer almost useless. I got this virus called the "verona.b worm" that totally messed up my registry. The anti-virus program that I used, InnoculateIT, was outdated and it handled the problem by deleting all files that were infected. The registry, however, was not repaired. Certain file associations were changed by the virus and I'm having problems restoring it. The files that were affected are:
EXE, .JPG, .JPEG, .JPE .GIF, .BMP, .DOC, .MP2, .MP3, .MPG .RAR, .REF, MPEG, .VQF .WMF, .WMA, .WMV, .XLS, .ZIP.
If I try to run any of these file types, the OS tries to access the file called "sysrnj.exe". That file was deleted by the anti-virus program. I can't even run regedit to fix it. What can I do to fix my registry? I am running Windows 98 SE. Any help would be much appreciated.
reghakr
10-04-2001, 11:32 PM
You'll find manuall removal instructions here:
<a target="_blank" href=http://rescomp.wustl.edu/doc/romeo.html>http://rescomp.wustl.edu/doc/romeo.html</a>
reghakr
mgrob
10-05-2001, 03:09 PM
You can copy regedit.exe to a new file called regedit.com and execute regedit.com.
Good luck!
GraveDigger
01-20-2002, 07:26 PM
hi there
I have a similar problem....
all my exe's call notepad, instead of starting....
I have w2k.... any hint's on that ?!?
please ;-)
.Ralph
TonyKlein
01-20-2002, 07:46 PM
As for 'Verona', it's also called the W32.BleBla.b. Worm: http://www.helpdesk.umd.edu/alerts/virus/blebla/files.shtml (http://www.sarc.com/avcenter/venc/data/w32.blebla.worm.html>http://www.sarc.com/avcenter/venc/data/w32.blebla.worm.html</a>
Download)
Additionally, download and install <a target="_blank" href=http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms99-032.asp>this patch from Microsoft </a>to prevent future infection.
However, this constitutes no defence against viruses itself.
Be sure you run a regularly updated antivirus.
Good luck, Tony
TonyKlein
01-20-2002, 07:48 PM
As for the Exe-file problem, download Exefix.zip from this site: <a target="_blank" href=http://home.earthlink.net/~rmbox/Reticulated/Toys.html>http://home.earthlink.net/~rmbox/Reticulated/Toys.html</a>
It restores the Windows file associations for exefiles, allowing you to execute them normally again.
Good luck, Tony
Mosaic1
01-20-2002, 07:55 PM
Great advice as always, Tony.
I have only one thing to add. If no exe can be run on the machine, using the exefix.exe is going to pose a problem. The exefix.com is an alternative.
To repair the exe associtaions in the registry. Download exefix08.com from HERE:
<a target="_blank" href=http://home.earthlink.net/~rmbox/Reticulated/Only_IE.html>http://home.earthlink.net/~rmbox/Reticulated/Only_IE.html</a>
TonyKlein
01-20-2002, 08:07 PM
Hi Mo,
Thanks for the compliment!
However, 'my' Exefix is a *.com file as well, once unzipped, , and it should run without a problem.
GraveDigger
01-20-2002, 08:46 PM
he guys...
thnks for the fast answer....
will this work as well for w2k ?!?
can you give me some more information about what exactly has to be changed in the registry ?!?
thnks...
.Ralph
Mosaic1
01-20-2002, 08:47 PM
Tony,
Thanks. I haven't used it myself. That's logical, though. I should think next time. DUH.
MO
Mosaic1
01-20-2002, 08:56 PM
Exefix is for Win95/98.
I'm not familiar with Win2000, but I don't think this will work.
You would need an inf file to restore the entries. I have one which restore both exe and regfile entries. I am hesitant to post it because I am not sure it is the same for Win2000.
Reghakr or someone else will be along, I'm sure and be able to help you.
TonyKlein
01-20-2002, 08:59 PM
I guess Mo's right.
But I'm sure there are people around here who're running Win2K, and who can assist you in restoring the correct reg keys and values.
Good luck, Tony
GraveDigger
01-20-2002, 11:38 PM
hi there....
I finally found it....
(it was much easier after the hint with the renaming of the exe's to com's.... this way I was able to run regedit and stuff under my screwed up w2k profile (other profiles on the machine were still ok))
the entry, in the registry, I found who caused windows to open all exe's with notepad was found in:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.exe\{Application Notepad.EXE}
I just had to delete this key, and everything just run's fine again....
thnks again for your help !
.Ralph
TonyKlein
01-20-2002, 11:51 PM
That is strictly a Windows 2000 thing, I gather.
It's done differently in Win98.
Glad to hear you got it cornered.
Cheers, Tony
Powered by vBulletin™ Version 4.1.0 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.