We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Msblast.E
Aliases: W32.Blaster.E.Worm (Symantec) W32/Lovsan.worm.e (McAfee) WORM_MSBLAST.E (Trend Micro) Win32.Poza.E (CA) Lovsan.E (F-secure) Worm.Win32.Blaster.6176.B (Global Hauri) W32/Blaster.A (Norman) W32/Blaster-E (Sophos) Blaster.E (Panda)
Summary
- Disconnect from the Internet
- End the worm process
- Delete the worm files from your computer
- Delete the worm registry entry
- Take steps to prevent re-infection
Disconnect from the Internet
End the worm process
-
Press CTRL+ALT+DEL once and click Task Manager.
-
Click the Processes tab.
-
On the Processes tab, click Image Name to sort the running processes by name.
-
Select the process mslaugh.exe, and click End Process.
Delete the worm files from your computer
-
Click Start, and then click Run.
-
In the Open field, type %windir%\system32
-
Press Enter.
-
Click the Name column to sort files by name.
-
Find the file mslaugh.exe and delete it.
- Press CTRL+ALT+DEL once and click Task Manager.
- Click the Processes tab.
- Confirm that mslaugh.exe is not in the list.
Delete the worm registry entry
-
Click Start, and then click Run.
-
In the Open field, type regedit
-
Press Enter.
-
Navigate to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
-
Right-click the value Windows Automation %System%\mslaugh.exe and click Delete.
-
Click Yes.
-
Exit the registry.