When it is run for the first time, it dropps a file named error.txt in C:\, and opens it with Nodepad. It will look like this:
Removal instructions:
Please let BitDefender disinfect your files.
Analyzed By
Raul Tosa, virus researcher
Technical Description:
The worm makes itself two copies:
%APPDATA%\hidn\hldrrr.exe
%APPDATA%\hidn\hidn2.exe
In older versions, Bagle used the same name, but it used a rootkit to hide the "hidn" folder, the two files and associated processes and registry entries. It is not the case in this version.
It creates the following registry entry to ensure it will be run at startup:
SHARE
THIS ON