Troj/BagleDl-BR is a Trojan for the Windows platform.
The Trojan has the functionality to silently download, install and run new software from preconfigured sources via HTTP.
When the Trojan is installed the following folder and files are created:
<Temp>\~11.exe
<Temp>\~12.exe
<System>\hldrrr.exe
The following registry entries are created to run hldrrr.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
hldrrr
<System>\hldrrr.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hldrrr
<System>\hldrrr.exe
Registry entries are created under:
HKCU\Software\FirstRRRun\