We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Msblast.B
Aliases: W32.Blaster.C.Worm (Symantec) W32/Lovsan.worm.b (McAfee) WORM_MSBLAST.C (Trend Micro) Win32.Poza.B (CA) Lovsan.B (F-secure) W32/Blaster.B (Norman) W32/Blaster-B (Sophos) Blaster.C (Panda)
Summary
- Disconnect from the Internet
- End the worm process
- Delete the worm files from your computer
- Delete the worm registry entry
- Take steps to prevent re-infection
Disconnect from the Internet
End the worm process
- Press CTRL+ALT+DEL once and click Task Manager.
- Click the Processes tab.
- On the Processes tab, click Image Name to sort the running processes by name.
- Select the process teekids.exe, and click End Process.
Delete the worm files from your computer
- Click Start, and then click Run.
- In the Open field, type %windir%\system32
- Press Enter.
- Click the Name column to sort files by name.
- Find the file teekids.exe and delete it.
- Press CTRL+ALT+DEL once and click Task Manager.
- Click the Processes tab.
- Confirm that teekids.exe is not in the list.
Delete the worm registry entry
- Click Start, and then click Run.
- In the Open field, type regedit
- Press Enter.
- Navigate to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- Right-click the value Microsoft Inet Xp.. %System%\teekids.exe and click Delete.
- Click Yes.
- Exit the registry.