Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Meumeu Nevne] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Meumeu Nevne] 'ImagePath' = '%ProgramFiles(x86)%\Google\Meume.exe'
- 'Meumeu Nevne' %ProgramFiles(x86)%\Google\Meume.exe
- %ProgramFiles(x86)%\google\meume.exe
- '15#.#08.101.181':4264
- '%ProgramFiles(x86)%\google\meume.exe'
- '%ProgramFiles(x86)%\google\meume.exe' Win7
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> > nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> > nul