This application requires Javascript for optimal performance.

W32/Agent.JA!worm - Released Oct 24, 2008 - Last Updated Oct 27, 2008

Alias/es

Worm.Win32.Agent.ja(Kaspersky), Trojan.Kobcka.GM(BitDefender)

Detection Availability

Active DatabaseExtended Database
FortiGate
low
high
FortiClient
FortiMail N/A

Visible Symptoms

  • Deletes itself from the current directory.

  • The following files exist under the %ProgramFiles%\Microsoft Common\ folder.
    • wuauclt.exe

    Detailed Analysis


    • This malware has similar behavior to W32/Agent.5190!tr.dldr. For more information, please see the description for W32/Agent.5190!tr.dldr.

    Recommended Action

      FortiGate Systems

    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

      FortiClient Systems

    • Quarantine/delete files that are detected and replace infected files with clean backup copies.

    Reference: ID - 600269