by ?
Server:
dropped file:
c:\WINDOWS\sysreg.exe 
size: 31 KB
                 
startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "sysreg" 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "sysreg" 
MegaSecurity