Home Malware Programs Droppers Trojan-Dropper.Win32.Agent.bot


Posted: August 29, 2011

Trojan-Dropper.Win32.Agent.bot is a harmful Trojan infection designed to advertise fake security applications and help them access the compromised PCs. Once installed, Trojan-Dropper.Win32.Agent.bot adds infected files and entries onto the computer system. Trojan-Dropper.Win32.Agent.bot uses malicious code to block anti-virus programs. Trojan-Dropper.Win32.Agent.bot can also download and install other malware items and steal your confidential information. Delete Trojan-Dropper.Win32.Agent.bot immediately after detection to protect your computer and privacy.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Trojan-Dropper.Win32.Agent.bot may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner*

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:

%AppData%\.exe File name: %AppData%\.exe
File type: Executable File
Mime Type: unknown/exe
%Temp%\pinch3.exe File name: %Temp%\pinch3.exe
File type: Executable File
Mime Type: unknown/exe
%Temp%\4571-1.jpg File name: %Temp%\4571-1.jpg
Mime Type: unknown/jpg

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "fake antivirus"