by ?
Server: dropped file: c:\WINDOWS\sysreg.exe size: 31 KB startup: HKLM\Software\Microsoft\Windows\CurrentVersion\Run "sysreg" HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "sysreg"