by Slim
modified by ENZO86
pass: 1234567890123456pass Server: dropped file: c:\WINDOWS\rrrrr.exe size: 7.168 bytes port: 111 TCP startup: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "RegistryKeyName1234567890" HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "RegistryKeyName1234567890" HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "RegistryKeyName1234567890" c:\windows\win.ini, [windows] "run" c:\windows\system.ini, [boot] "shell" c:\windows\win.ini, [windows] "load"MegaSecurity