by Cheitan, Mayhem and Phr33k
more versions
Server: dropped file: C:\WINDOWS\SYSTEM\WinZip.exe size: 228 KB port: 55555 TCP startup: HKLM\Software\Microsoft\Windows\CurrentVersion\Run