REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Network Instruments\Observer\Filters\(Virus) SQL Slammer Worm] "FilterBuffer"=hex:aa,00,00,00,04,00,00,00,29,00,5a,00,31,00,1f,00,00,97,11,00,\ 01,00,01,00,02,00,01,24,00,00,00,01,02,05,9a,01,00,02,00,01,2a,00,00,00,01,\ 03,04,01,01,29,00,00,00,00,00,1f,00,00,4c,12,00,01,00,00,00,01,00,01,8c,00,\ 00,00,01,03,c9,b0,42,00,00,01,00,01,a0,01,00,00,01,02,eb,ca,27,00,00,00,81,\ 00,1f,00,00,3f,11,00,01,00,00,00,01,00,01,10,00,00,00,01,02,05,9a,00,00,01,\ 00,01,1c,00,00,00,01,01,04,29,00,00,00,00,00,1f,00,00,40,12,00,01,00,00,00,\ 01,00,01,7e,00,00,00,01,03,c9,b0,42,00,00,01,00,01,c0,00,00,00,01,02,eb,ca "szDescr"="The sending machine may have been infected with the W32.SQLExp.Worm (SQL Slammer Worm)." "RGBValue"=dword:00800080 "bFilterBasedAlarm"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Network Instruments\Observer\ProtocolPresetsV9]