This malware uses complex routines to hide in the infected system's master boot record (MBR) in order to evade detection.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be dropped by other malware.
File size: 6,656 bytes
File type: SYS
Memory resident: Yes
Initial samples received date: 28 Jun 2011
Arrival Details
This Trojan may be dropped by the following malware:
Autostart Technique
This Trojan registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Service\hello_tt
ImagePath = "{malware path and file name}"
Other System Modifications
This Trojan adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Alg = "%System Root%\alg.exe"
Connect with us on
| | | |