We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Msblast.F
Aliases: W32.Blaster.F.Worm (Symantec) W32/Lovsan.worm.f (McAfee) WORM_MSBLAST.F (Trend Micro) Win32.Poza.F (CA) Lovsan.F (F-secure) Worm.Win32.Blaster.11808 (Global Hauri) W32/Blaster.F (Norman) W32/Blaster-F (Sophos) Blaster.F (Panda)
Summary
- Disconnect from the Internet
- End the worm process
- Delete the worm files from your computer
- Delete the worm registry entry
- Take steps to prevent re-infection
Disconnect from the Internet
End the worm process
-
Press CTRL+ALT+DEL once and click Task Manager.
-
Click the Processes tab.
-
On the Processes tab, click Image Name to sort the running processes by name.
-
Select the process enbei.exe, and click End Process.
Delete the worm files from your computer
-
Click Start, and then click Run.
-
In the Open field, type %windir%\system32
-
Press Enter.
-
Click the Name column to sort files by name.
-
Find the file enbei.exe and delete it.
- Press CTRL+ALT+DEL once and click Task Manager.
- Click the Processes tab.
- Confirm that enbei.exe is not in the list.
Delete the worm registry entry
-
Click Start, and then click Run.
-
In the Open field, type regedit
-
Press Enter.
-
Navigate to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
-
Right-click the value www.hidro.4t.com %System%\enbei.exe and click Delete.
-
Click Yes.
-
Exit the registry.