Skip to main content
Skip to main content
Microsoft Security Intelligence
Published May 24, 2013 | Updated Sep 15, 2017

Worm:JS/Proslikefan.gen!inf

Detected by Microsoft Defender Antivirus

Aliases: Trojan.Win32.Buzus.dzwk (Kaspersky) doslegacy/Suspicious_Gen2.RIILM (Norman) INF/AutoRun!tr (other) TROJ_OTORUN.ITW (Trend Micro) HTML/ExpKit.Gen3 (Avira) Worm.JS.Proslikefan (Ikarus) W32/AutoInf-DQ (Sophos)

Summary

Windows Defender detects and removes this threat.

This threat is an autorun.inf file created by a worm so it can spread and infect other computers through network and local drives, and removable devices, such as a USB flash drive. 

Autorun.inf files on their own are not necessarily a sign of infection, as they are used by legitimate programs and installation media.

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

Disable Autorun functionality

This threat tries to use the Windows Autorun function to spread via removable drives, such as USB flash drives. You can find out how to turn off this feature in the article How to disable the Autorun functionality in Windows.

Recovering from recurring infections on a network

The following additional steps may need to be taken to completely remove this threat from an infected network, and to stop infections from recurring from this and other similar types of network-spreading malware:

  1. Ensure that an antivirus product is installed on all computers connected to the network that can access or host shares.
  2. Ensure that all available network shares are scanned with an up-to-date antivirus product.
  3. Restrict permissions as appropriate for network shares on your network. There is more information on how to do this in the article Use access control to restrict who can use files.
  4. Remove any unnecessary network shares or mapped drives.

It may also be necessary to temporarily change the permission on network shares to read-only until the disinfection process is complete.

Follow us