We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Msblast.I
Aliases: WORM_MSBLAST.I (Trend Micro) W32/Blaster.worm.k (McAfee) W32.Blaster.T.Worm (Symantec) W32/Blaster-G (Sophos) Win32.Poza.L (CA) Worm.Win32.Blaster.66048 (Global Hauri) Blaster.H (Panda)
Summary
- Disconnect from the Internet
- End the worm process
- Delete the worm files from your computer
- Delete the worm registry entry
- Take steps to prevent re-infection
Disconnect from the Internet
End the worm process
- Press CTRL+ALT+DEL once and click Task Manager.
- Click the Processes tab.
- On the Processes tab, click Image Name to sort the running processes by name.
- Select the process eschlp.exe, and click End Process.
- Select the process svchosthlp.exe, and click End Process.
Delete the worm files from your computer
- Click Start, and then click Run.
- In the Open field, type %windir%\system32
- Press Enter.
- Click the Name column to sort files by name.
- Find the files eschlp.exe, svchosthlp.exe and delete them.
- Press CTRL+ALT+DEL once and click Task Manager.
- Click the Processes tab.
- Confirm that eschlp.exe or svchosthlp.exe is not in the list.
Delete the worm registry entry
- Click Start, and then click Run.
- In the Open field, type regedit
- Press Enter.
- Navigate to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- Right-click the value MSUpdate = "%System%\svchosthlp.exe" and click Delete.
- Click Yes.
- Right-click the value SPUpdate = "%System%\svchosthlp.exe" and click Delete.
- Click Yes.
- Right-click the value Helper = "%System%\eschlp.exe" and click Delete.
- Click Yes.
- Exit the registry.