Posted: August 29, 2011

Trojan-Dropper.Win32.Agent.bot is a harmful Trojan infection designed to advertise fake security applications and help them access the compromised PCs. Once installed, Trojan-Dropper.Win32.Agent.bot adds infected files and entries onto the computer system. Trojan-Dropper.Win32.Agent.bot uses malicious code to block anti-virus programs. Trojan-Dropper.Win32.Agent.bot can also download and install other malware items and steal your confidential information. Delete Trojan-Dropper.Win32.Agent.bot immediately after detection to protect your computer and privacy.

Technical Details

File System Modifications

The following files were created in the system:

%AppData%\.exe File name: %AppData%\.exe
File type: Executable File
Mime Type: unknown/exe
%Temp%\pinch3.exe File name: %Temp%\pinch3.exe
File type: Executable File
Mime Type: unknown/exe
%Temp%\4571-1.jpg File name: %Temp%\4571-1.jpg
Mime Type: unknown/jpg

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "fake antivirus"