by Shadow
Server: dropped file: C:\WINDOWS\SYSTEM\BLAKHARAZ.EXE startup: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunMegaSecurity