Hosting Panama have several ranges that are or have been, involved in malicious activity. The latest of these being 184.108.40.206/24, which is responsible for this little baggage of fun;
The payload, adobeupdate.exe is a Zbot variant (these almost always come with a keylogger and backdoor trojan, which leaves YOUR machine compromised, in this case, it also comes with a rootkit).
Anubis error'd out when trying to analyze this, suggesting it's VM aware (not surprising given it's associated with the Fragus exploit pack), and I've not got my test machine on at present as I'm still busy going through a ton of stuff for work, but I'll see about running it later (I don't do VM's, only test machine I use is a "real" machine).
ThreatExpert was able to work with this one, and showed some interesting results;
You'll notice, this variant also steals your Facebook credentials .....
proanalytics.cn is registered to "Mareks Vabels" (firstname.lastname@example.org), via Tucows domain registration. Only reference to that name I could find, aside from MalwareURL and MalwareDomainList, was this one, suggesting the individual, if he/she is real, is alledgedly from Latvia.
This URL is amongst MANY others that are currently hiding in compromised websites, so if you're running a website yourself, or know a friend who has a website, PLEASE make sure you're peridically checking the files for signs of infection.
In the meantime, perhaps Hosting Panama would care to explain their lack of action?