Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'patches' = '1'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AdobeARMS' = '%APPDATA%\AdobeARMS.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'AdobeARMS' = '\AdobeARMS.exe'
- adobearms.exe
- %APPDATA%\adobearms.exe
- %APPDATA%\adobearms.exe
- 'ol####ne.mine.nu':7562
- DNS ASK ol####ne.mine.nu
- '%APPDATA%\adobearms.exe' 364 "<Full path to file>"
- '%APPDATA%\adobearms.exe'
- '%APPDATA%\adobearms.exe' 364 "<Full path to file>"' (with hidden window)