We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Yeltminky.A!inf
Aliases: Trojan.Win32.Buzus.dzwk (Kaspersky) doslegacy/Suspicious_Gen2.RIILM (Norman) INF/AutoRun!tr (other) TROJ_OTORUN.ITW (Trend Micro)
Summary
Windows Defender detects and removes this threat.
This threat is an autorun.inf file created by the Win32/Yeltminky family of worms. The family creates this autorun file to help them spread and infect other computers through network and local drives, and removable devices, such as a USB flash drive.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials or, for Windows 8, Windows Defender
- Microsoft Safety Scanner
Disable Autorun functionality
This threat tries to use the Windows Autorun function to spread via removable drives, such as USB flash drives. This is a common malware behavior. You can find out how to turn off this feature in the article How to disable the Autorun functionality in Windows.
Recovering from recurring infections on a network
You may need to do the following to completely remove this threat from an infected network, and to stop infections from recurring from this and other similar types of network-spreading malware:
- Ensure that an antivirus product is installed on all computers connected to the network that can access or host shares.
- Ensure that all available network shares are scanned with an up-to-date antivirus product.
- Restrict permissions as appropriate for network shares on your network. There is more information on how to do this in the article Use access control to restrict who can use files.
- Remove any unnecessary network shares or mapped drives.
It may also be necessary to temporarily change the permission on network shares to read-only until the disinfection process is complete.