This application requires Javascript for optimal performance.

W32/Agent.AHVM!tr.dldr - Released Sep 27, 2008 - Last Updated Sep 29, 2008

Visible Symptoms

  • Possible termination of the firewall or other security applications, including antivirus monitors.

  • It deletes itself from the current directory.

  • The following file exists:
    • C:\{random characters}.tmp

    Detailed Analysis


    The behavior of this trojan is very similar to W32/Agent.AGGP!tr.dldr. For a more detailed description, please proceed to W32/Agent.AGGP!tr.dldr.

    Recommended Action

      FortiGate Systems

    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

      FortiClient Systems

    • Quarantine/delete files that are detected and replace infected files with clean backup copies.

    Reference: ID - 567993