by ?
Server:
dropped file:
c:\WINDOWS\sysreg.exe
size: 31 KB
startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "sysreg"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "sysreg"
MegaSecurity