We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:INF/Autorun.gen!H
Detected by Microsoft Defender Antivirus
Aliases: Mal/AutoInf-A (Sophos)
Summary
VirTool:INF/Autorun.gen!H is a generic detection for the "autorun.inf" configuration data file that performs automated actions associated with removable media drives. One such action is to open an executable named "\BUMARA\darica.exe" when the drive is first connected or accessed and Autorun is enabled.
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.