Sophos

Troj/BagleDl-BR

Aliases
  • Email-Worm.Win32.Bagle.gh
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Protection available since 29 May 2006 11:28:26 (GMT)
Detected by All Sophos products

Action

More Information

Troj/BagleDl-BR is a Trojan for the Windows platform.

The Trojan has the functionality to silently download, install and run new software from preconfigured sources via HTTP.

When the Trojan is installed the following folder and files are created:

<Temp>\~11.exe
<Temp>\~12.exe
<System>\hldrrr.exe

The following registry entries are created to run hldrrr.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
hldrrr
<System>\hldrrr.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hldrrr
<System>\hldrrr.exe

Registry entries are created under:

HKCU\Software\FirstRRRun\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer