We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Sobig.F@mm
Aliases: Win32.Sobig.F (CA) W32.Sobig.F@mm (Symantec) I-Worm.Win32.Sobig.F (Global Hauri) Sobig.F (Panda) W32/Sobig-F (Sophos) W32/Sobig.F@mm (Norman) WORM_SOBIG.F (Trend Micro) W32/Sobig.f@MM (McAfee)
Summary
- Disconnect from the Internet.
- End the worm process.
- Delete the worm file from your computer.
- Delete the worm registry entry.
- Take steps to prevent re-infection.
Disconnect from the Internet
End the worm process
- Press CTRL+ALT+DEL once and click Task Manager.
- Click Processes and click Image Name to sort the running processes by name.
- Select the process winppr32.exe, and click End Process.
Delete the worm file from your computer
- Click Start, and click Run.
- In the Open field, type %Windir%
- Click OK.
- Click Name to sort files by name.
- If the file winppr32.exe is in the list, delete it.
- On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
- Click Yes.
- Press CTRL+ALTlt+DEL once and click Task Manager.
- Click Processes and click Image Name to sort the running processes by name.
- Confirm that winppr32.exe is not in the list.
Delete the worm registry entry
- On the Start menu, click Run.
- Type regedit and click OK.
- In the left pane, navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run - In the right pane, right-click the value:
TrayX = %Windir%\winppr32.exe - Select Delete and click Yes to delete the value.
- Repeat steps 3 to step 5 for the following registry key if it exists:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run - Close the Registry Editor.