Sophos

Troj/BagleDl-BR

Aliases
  • Email-Worm.Win32.Bagle.gh
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 29 May 2006 11:28:26 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/BagleDl-BR is a Trojan for the Windows platform.

The Trojan has the functionality to silently download, install and run new software from preconfigured sources via HTTP.

When the Trojan is installed the following folder and files are created:

<Temp>\~11.exe
<Temp>\~12.exe
<System>\hldrrr.exe

The following registry entries are created to run hldrrr.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
hldrrr
<System>\hldrrr.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hldrrr
<System>\hldrrr.exe

Registry entries are created under:

HKCU\Software\FirstRRRun\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer