Technical Information
- [HKLM\System\CurrentControlSet\Services\ALG] 'Start' = '00000002'
- %TEMP%\ixp000.tmp\ВїГ»§¶ë.exe
- %WINDIR%\syswow64\dna.dll
- %WINDIR%\syswow64\algdna.exe
- from %WINDIR%\syswow64\algdna.exe to %WINDIR%\syswow64\alg.exe
- '%TEMP%\ixp000.tmp\ВїГ»§¶ë.exe'