Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AdobeMe' = '%WINDIR%\AdobeMeeD\lava.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{GE2GC77T-3R7W-5OMI-42S5-L7N3KVJ45356}] 'StubPath' = '%WINDIR%\AdobeMeeD\lava.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{GE2GC77T-3R7W-5OMI-42S5-L7N3KVJ45356}] 'StubPath' = '%WINDIR%\AdobeMeeD\lava.exe restart'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AdobeMe' = '%WINDIR%\AdobeMeeD\lava.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MdobeMe' = '%WINDIR%\AdobeMeeD\lava.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %WINDIR%\AdobeMeeD\lava.exe
- 'sd####.no-ip.biz':8000
- 'localhost':1037
- DNS ASK sd####.no-ip.biz