W32/Agent.NAA!tr
Analysis
- undefinedSYSTEMundefined\adir.dll
- _alanchum
- key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- value: taskdir
- data: undefinedSYSTEMundefined\taskdir.exe
- key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
- value: taskdir
- data: undefinedSYSTEMundefined\taskdir.exe
- http://81.17{REMOVED}/cp/bin/lim
- http://81.17REMOVED}/cp/rule.php
- http://69.50REMOVED}/cp/rule
- http://205.20REMOVED}/cp/rule.php
- http://209.12REMOVED}/cp/rule.php
Recommended Action
-
FortiGate Systems
- Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.