Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /F /IM 5468
- %TEMP%\_mei35162\vcruntime140.dll
- %TEMP%\_mei35162\_bz2.pyd
- %TEMP%\_mei35162\_decimal.pyd
- %TEMP%\_mei35162\_hashlib.pyd
- %TEMP%\_mei35162\_lzma.pyd
- %TEMP%\_mei35162\_socket.pyd
- %TEMP%\_mei35162\libcrypto-1_1.dll
- %TEMP%\_mei35162\python310.dll
- %TEMP%\_mei35162\select.pyd
- %TEMP%\_mei35162\unicodedata.pyd
- %TEMP%\_mei35162\base_library.zip
- <Current directory>\runtime broker.exe
- %TEMP%\_mei40842\crypto\cipher\_arc4.pyd
- %TEMP%\_mei40842\crypto\cipher\_salsa20.pyd
- %TEMP%\_mei40842\crypto\cipher\_chacha20.pyd
- %TEMP%\_mei40842\crypto\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_aes.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_aesni.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_arc2.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_blowfish.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_cast.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_cbc.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_cfb.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ctr.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_des.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_des3.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ecb.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ocb.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ofb.pyd
- %TEMP%\_mei40842\crypto\hash\_blake2b.pyd
- %TEMP%\_mei40842\crypto\hash\_blake2s.pyd
- %TEMP%\_mei40842\crypto\hash\_md2.pyd
- %TEMP%\_mei40842\crypto\hash\_md4.pyd
- %TEMP%\_mei40842\crypto\hash\_md5.pyd
- %TEMP%\_mei40842\crypto\hash\_ripemd160.pyd
- %TEMP%\_mei40842\crypto\hash\_sha1.pyd
- %TEMP%\_mei40842\crypto\hash\_sha224.pyd
- %TEMP%\_mei40842\crypto\hash\_sha256.pyd
- %TEMP%\_mei40842\crypto\hash\_sha384.pyd
- %TEMP%\_mei40842\crypto\hash\_sha512.pyd
- %TEMP%\_mei40842\crypto\hash\_ghash_clmul.pyd
- %TEMP%\_mei40842\crypto\hash\_ghash_portable.pyd
- %TEMP%\_mei40842\crypto\hash\_keccak.pyd
- %TEMP%\_mei40842\crypto\hash\_poly1305.pyd
- %TEMP%\_mei40842\crypto\math\_modexp.pyd
- %TEMP%\_mei40842\crypto\protocol\_scrypt.pyd
- %TEMP%\_mei40842\crypto\publickey\_ec_ws.pyd
- <Current directory>\registry.exe
- %TEMP%\_mei40842\crypto\util\_cpuid_c.pyd
- %TEMP%\_mei40842\crypto\util\_strxor.pyd
- %TEMP%\_mei40842\msvcp140.dll
- %TEMP%\_mei40842\pil\_imaging.cp310-win_amd64.pyd
- %TEMP%\_mei40842\pil\_imagingtk.cp310-win_amd64.pyd
- %TEMP%\_mei40842\pil\_webp.cp310-win_amd64.pyd
- %TEMP%\_mei40842\vcruntime140.dll
- %TEMP%\_mei40842\vcruntime140_1.dll
- %TEMP%\_mei40842\_asyncio.pyd
- %TEMP%\_mei40842\_bz2.pyd
- %TEMP%\_mei40842\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei40842\_ctypes.pyd
- %TEMP%\_mei40842\_decimal.pyd
- %TEMP%\_mei40842\_elementtree.pyd
- %TEMP%\_mei40842\_hashlib.pyd
- %TEMP%\_mei40842\_lzma.pyd
- %TEMP%\_mei40842\_multiprocessing.pyd
- %TEMP%\_mei40842\_overlapped.pyd
- %TEMP%\_mei40842\_queue.pyd
- %TEMP%\_mei40842\_socket.pyd
- %TEMP%\_mei40842\_sqlite3.pyd
- %TEMP%\_mei40842\_ssl.pyd
- %TEMP%\_mei40842\_uuid.pyd
- %TEMP%\_mei40842\_win32sysloader.cp310-win_amd64.pyd
- %TEMP%\_mei40842\libcrypto-1_1.dll
- %TEMP%\_mei40842\libffi-7.dll
- %TEMP%\_mei40842\libssl-1_1.dll
- %TEMP%\_mei44442\crypto\cipher\_arc4.pyd
- %TEMP%\_mei44442\crypto\cipher\_salsa20.pyd
- %TEMP%\_mei40842\mfc140u.dll
- %TEMP%\_mei44442\crypto\cipher\_chacha20.pyd
- %TEMP%\_mei44442\crypto\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_aes.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_aesni.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_arc2.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_blowfish.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_cast.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_cbc.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_cfb.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ctr.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_des.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_des3.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ecb.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ocb.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ofb.pyd
- %TEMP%\_mei44442\crypto\hash\_blake2b.pyd
- %TEMP%\_mei44442\crypto\hash\_blake2s.pyd
- %TEMP%\_mei44442\crypto\hash\_md2.pyd
- %TEMP%\_mei44442\crypto\hash\_md4.pyd
- %TEMP%\_mei44442\crypto\hash\_md5.pyd
- %TEMP%\_mei44442\crypto\hash\_ripemd160.pyd
- %TEMP%\_mei44442\crypto\hash\_sha1.pyd
- %TEMP%\_mei44442\crypto\hash\_sha224.pyd
- %TEMP%\_mei44442\crypto\hash\_sha256.pyd
- %TEMP%\_mei44442\crypto\hash\_sha384.pyd
- %TEMP%\_mei44442\crypto\hash\_sha512.pyd
- %TEMP%\_mei44442\crypto\hash\_ghash_clmul.pyd
- %TEMP%\_mei44442\crypto\hash\_ghash_portable.pyd
- %TEMP%\_mei44442\crypto\hash\_keccak.pyd
- %TEMP%\_mei44442\crypto\hash\_poly1305.pyd
- %TEMP%\_mei44442\crypto\math\_modexp.pyd
- %TEMP%\_mei44442\crypto\protocol\_scrypt.pyd
- %TEMP%\_mei44442\crypto\publickey\_ec_ws.pyd
- %TEMP%\_mei44442\crypto\util\_cpuid_c.pyd
- %TEMP%\_mei44442\crypto\util\_strxor.pyd
- %TEMP%\_mei44442\vcruntime140.dll
- %TEMP%\_mei44442\_bz2.pyd
- %TEMP%\_mei44442\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei44442\_ctypes.pyd
- %TEMP%\_mei44442\_decimal.pyd
- %TEMP%\_mei44442\_hashlib.pyd
- %TEMP%\_mei44442\_lzma.pyd
- %TEMP%\_mei44442\_multiprocessing.pyd
- %TEMP%\_mei44442\_queue.pyd
- %TEMP%\_mei44442\_socket.pyd
- <Current directory>\process builder.exe
- %TEMP%\_mei44442\_ssl.pyd
- %TEMP%\_mei44442\_uuid.pyd
- %TEMP%\_mei44442\_win32sysloader.cp310-win_amd64.pyd
- %TEMP%\_mei44442\cryptography\hazmat\bindings\_openssl.pyd
- %TEMP%\_mei40842\psutil\_psutil_windows.cp310-win_amd64.pyd
- %TEMP%\_mei40842\pyexpat.pyd
- %TEMP%\_mei40842\python310.dll
- %TEMP%\_mei44442\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei40842\pythoncom310.dll
- %TEMP%\_mei44442\libcrypto-1_1.dll
- %TEMP%\_mei40842\pywintypes310.dll
- %TEMP%\_mei40842\select.pyd
- %TEMP%\_mei40842\sqlite3.dll
- %TEMP%\_mei40842\unicodedata.pyd
- %TEMP%\_mei40842\win32api.cp310-win_amd64.pyd
- %TEMP%\_mei44442\libffi-7.dll
- %TEMP%\_mei40842\win32com\shell\shell.cp310-win_amd64.pyd
- %TEMP%\_mei44442\libssl-1_1.dll
- %TEMP%\_mei40842\win32crypt.cp310-win_amd64.pyd
- %TEMP%\_mei40842\win32trace.cp310-win_amd64.pyd
- %TEMP%\_mei40842\win32ui.cp310-win_amd64.pyd
- %TEMP%\_mei44442\mfc140u.dll
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\installer
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\license
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\metadata
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\record
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\wheel
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\top_level.txt
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\zip-safe
- %TEMP%\_mei40842\base_library.zip
- %TEMP%\_mei40842\certifi\cacert.pem
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\copying.txt
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\installer
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\metadata
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\record
- %TEMP%\_mei44442\pyexpat.pyd
- %TEMP%\_mei44442\python3.dll
- %TEMP%\_mei44442\python310.dll
- %TEMP%\_mei44442\pythoncom310.dll
- %TEMP%\_mei44442\pywintypes310.dll
- %TEMP%\_mei44442\select.pyd
- %TEMP%\_mei44442\unicodedata.pyd
- %TEMP%\_mei44442\win32api.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32com\shell\shell.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32crypt.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32trace.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32ui.cp310-win_amd64.pyd
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\installer
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\license
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\metadata
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\record
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\wheel
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\entry_points.txt
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\top_level.txt
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\installer
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\license
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\metadata
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\record
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\wheel
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\top_level.txt
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\zip-safe
- %TEMP%\_mei44442\base_library.zip
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\wheel
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\entry_points.txt
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\top_level.txt
- %TEMP%\_mei44442\certifi\cacert.pem
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\installer
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\license
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\metadata
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\record
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\wheel
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\entry_points.txt
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\top_level.txt
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\installer
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license.apache
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license.bsd
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license.psf
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\metadata
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\record
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\wheel
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\top_level.txt
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\copying.txt
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\installer
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\metadata
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\record
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\wheel
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\entry_points.txt
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\top_level.txt
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\installer
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\license
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\metadata
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\record
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\wheel
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\entry_points.txt
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\top_level.txt
- %TEMP%\mtx0lnqs
- %TEMP%\ms6ohtes
- nul
- %TEMP%\stealerium-latest.log
- %TEMP%\tmpe23d.tmp.bat
- <Current directory>\runtime broker.exe
- <Current directory>\registry.exe
- <Current directory>\process builder.exe
- %TEMP%\_mei35162\base_library.zip
- %TEMP%\_mei35162\libcrypto-1_1.dll
- %TEMP%\_mei35162\python310.dll
- %TEMP%\_mei35162\select.pyd
- %TEMP%\_mei35162\unicodedata.pyd
- %TEMP%\_mei35162\vcruntime140.dll
- %TEMP%\_mei35162\_bz2.pyd
- %TEMP%\_mei35162\_decimal.pyd
- %TEMP%\_mei35162\_hashlib.pyd
- %TEMP%\_mei35162\_lzma.pyd
- %TEMP%\_mei35162\_socket.pyd
- %TEMP%\mtx0lnqs
- %TEMP%\ms6ohtes
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\installer
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\license
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\metadata
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\record
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\top_level.txt
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\wheel
- %TEMP%\_mei44442\altgraph-0.17.2.dist-info\zip-safe
- %TEMP%\_mei44442\base_library.zip
- %TEMP%\_mei44442\certifi\cacert.pem
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\entry_points.txt
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\installer
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\license
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\metadata
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\record
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\top_level.txt
- %TEMP%\_mei44442\cffi-1.15.1.dist-info\wheel
- %TEMP%\_mei44442\crypto\cipher\_arc4.pyd
- %TEMP%\_mei44442\crypto\cipher\_chacha20.pyd
- %TEMP%\_mei44442\crypto\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_aes.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_aesni.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_arc2.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_blowfish.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_cast.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_cbc.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_cfb.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ctr.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_des.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_des3.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ecb.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ocb.pyd
- %TEMP%\_mei44442\crypto\cipher\_raw_ofb.pyd
- %TEMP%\_mei44442\crypto\cipher\_salsa20.pyd
- %TEMP%\_mei44442\crypto\hash\_blake2b.pyd
- %TEMP%\_mei44442\crypto\hash\_blake2s.pyd
- %TEMP%\_mei44442\crypto\hash\_ghash_clmul.pyd
- %TEMP%\_mei44442\crypto\hash\_ghash_portable.pyd
- %TEMP%\_mei44442\crypto\hash\_keccak.pyd
- %TEMP%\_mei44442\crypto\hash\_md2.pyd
- %TEMP%\_mei44442\crypto\hash\_md4.pyd
- %TEMP%\_mei44442\crypto\hash\_md5.pyd
- %TEMP%\_mei44442\crypto\hash\_poly1305.pyd
- %TEMP%\_mei44442\crypto\hash\_ripemd160.pyd
- %TEMP%\_mei44442\crypto\hash\_sha1.pyd
- %TEMP%\_mei44442\crypto\hash\_sha224.pyd
- %TEMP%\_mei44442\crypto\hash\_sha256.pyd
- %TEMP%\_mei44442\crypto\hash\_sha384.pyd
- %TEMP%\_mei44442\crypto\hash\_sha512.pyd
- %TEMP%\_mei44442\crypto\math\_modexp.pyd
- %TEMP%\_mei44442\crypto\protocol\_scrypt.pyd
- %TEMP%\_mei44442\crypto\publickey\_ec_ws.pyd
- %TEMP%\_mei44442\crypto\util\_cpuid_c.pyd
- %TEMP%\_mei44442\crypto\util\_strxor.pyd
- %TEMP%\_mei44442\cryptography\hazmat\bindings\_openssl.pyd
- %TEMP%\_mei44442\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\installer
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license.apache
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license.bsd
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\license.psf
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\metadata
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\record
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\top_level.txt
- %TEMP%\_mei44442\cryptography-37.0.4.dist-info\wheel
- %TEMP%\_mei44442\libcrypto-1_1.dll
- %TEMP%\_mei44442\libffi-7.dll
- %TEMP%\_mei44442\libssl-1_1.dll
- %TEMP%\_mei44442\mfc140u.dll
- %TEMP%\_mei44442\pyexpat.pyd
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\copying.txt
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\entry_points.txt
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\installer
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\metadata
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\record
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\top_level.txt
- %TEMP%\_mei44442\pyinstaller-5.2.dist-info\wheel
- %TEMP%\_mei44442\python3.dll
- %TEMP%\_mei44442\python310.dll
- %TEMP%\_mei44442\pythoncom310.dll
- %TEMP%\_mei44442\pywintypes310.dll
- %TEMP%\_mei44442\select.pyd
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\entry_points.txt
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\installer
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\license
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\metadata
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\record
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\top_level.txt
- %TEMP%\_mei44442\setuptools-58.1.0.dist-info\wheel
- %TEMP%\_mei44442\unicodedata.pyd
- %TEMP%\_mei44442\vcruntime140.dll
- %TEMP%\_mei44442\win32api.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32com\shell\shell.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32crypt.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32trace.cp310-win_amd64.pyd
- %TEMP%\_mei44442\win32ui.cp310-win_amd64.pyd
- %TEMP%\_mei44442\_bz2.pyd
- %TEMP%\_mei44442\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei44442\_ctypes.pyd
- %TEMP%\_mei44442\_decimal.pyd
- %TEMP%\_mei44442\_hashlib.pyd
- %TEMP%\_mei44442\_lzma.pyd
- %TEMP%\_mei44442\_multiprocessing.pyd
- %TEMP%\_mei44442\_queue.pyd
- %TEMP%\_mei44442\_socket.pyd
- %TEMP%\_mei44442\_ssl.pyd
- %TEMP%\_mei44442\_uuid.pyd
- %TEMP%\_mei44442\_win32sysloader.cp310-win_amd64.pyd
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\installer
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\license
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\metadata
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\record
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\top_level.txt
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\wheel
- %TEMP%\_mei40842\altgraph-0.17.2.dist-info\zip-safe
- %TEMP%\_mei40842\base_library.zip
- %TEMP%\_mei40842\certifi\cacert.pem
- %TEMP%\_mei40842\crypto\cipher\_arc4.pyd
- %TEMP%\_mei40842\crypto\cipher\_chacha20.pyd
- %TEMP%\_mei40842\crypto\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_aes.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_aesni.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_arc2.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_blowfish.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_cast.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_cbc.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_cfb.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ctr.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_des.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_des3.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ecb.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ocb.pyd
- %TEMP%\_mei40842\crypto\cipher\_raw_ofb.pyd
- %TEMP%\_mei40842\crypto\cipher\_salsa20.pyd
- %TEMP%\_mei40842\crypto\hash\_blake2b.pyd
- %TEMP%\_mei40842\crypto\hash\_blake2s.pyd
- %TEMP%\_mei40842\crypto\hash\_ghash_clmul.pyd
- %TEMP%\_mei40842\crypto\hash\_ghash_portable.pyd
- %TEMP%\_mei40842\crypto\hash\_keccak.pyd
- %TEMP%\_mei40842\crypto\hash\_md2.pyd
- %TEMP%\_mei40842\crypto\hash\_md4.pyd
- %TEMP%\_mei40842\crypto\hash\_md5.pyd
- %TEMP%\_mei40842\crypto\hash\_poly1305.pyd
- %TEMP%\_mei40842\crypto\hash\_ripemd160.pyd
- %TEMP%\_mei40842\crypto\hash\_sha1.pyd
- %TEMP%\_mei40842\crypto\hash\_sha224.pyd
- %TEMP%\_mei40842\crypto\hash\_sha256.pyd
- %TEMP%\_mei40842\crypto\hash\_sha384.pyd
- %TEMP%\_mei40842\crypto\hash\_sha512.pyd
- %TEMP%\_mei40842\crypto\math\_modexp.pyd
- %TEMP%\_mei40842\crypto\protocol\_scrypt.pyd
- %TEMP%\_mei40842\crypto\publickey\_ec_ws.pyd
- %TEMP%\_mei40842\crypto\util\_cpuid_c.pyd
- %TEMP%\_mei40842\crypto\util\_strxor.pyd
- %TEMP%\_mei40842\libcrypto-1_1.dll
- %TEMP%\_mei40842\libffi-7.dll
- %TEMP%\_mei40842\libssl-1_1.dll
- %TEMP%\_mei40842\mfc140u.dll
- %TEMP%\_mei40842\msvcp140.dll
- %TEMP%\_mei40842\pil\_imaging.cp310-win_amd64.pyd
- %TEMP%\_mei40842\pil\_imagingtk.cp310-win_amd64.pyd
- %TEMP%\_mei40842\pil\_webp.cp310-win_amd64.pyd
- %TEMP%\_mei40842\psutil\_psutil_windows.cp310-win_amd64.pyd
- %TEMP%\_mei40842\pyexpat.pyd
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\copying.txt
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\entry_points.txt
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\installer
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\metadata
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\record
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\top_level.txt
- %TEMP%\_mei40842\pyinstaller-5.2.dist-info\wheel
- %TEMP%\_mei40842\python310.dll
- %TEMP%\_mei40842\pythoncom310.dll
- %TEMP%\_mei40842\pywintypes310.dll
- %TEMP%\_mei40842\select.pyd
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\entry_points.txt
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\installer
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\license
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\metadata
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\record
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\top_level.txt
- %TEMP%\_mei40842\setuptools-58.1.0.dist-info\wheel
- %TEMP%\_mei40842\sqlite3.dll
- %TEMP%\_mei40842\unicodedata.pyd
- %TEMP%\_mei40842\vcruntime140.dll
- %TEMP%\_mei40842\vcruntime140_1.dll
- %TEMP%\_mei40842\win32api.cp310-win_amd64.pyd
- %TEMP%\_mei40842\win32com\shell\shell.cp310-win_amd64.pyd
- %TEMP%\_mei40842\win32crypt.cp310-win_amd64.pyd
- %TEMP%\_mei40842\win32trace.cp310-win_amd64.pyd
- %TEMP%\_mei40842\win32ui.cp310-win_amd64.pyd
- %TEMP%\_mei40842\_asyncio.pyd
- %TEMP%\_mei40842\_bz2.pyd
- %TEMP%\_mei40842\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei40842\_ctypes.pyd
- %TEMP%\_mei40842\_decimal.pyd
- %TEMP%\_mei40842\_elementtree.pyd
- %TEMP%\_mei40842\_hashlib.pyd
- %TEMP%\_mei40842\_lzma.pyd
- %TEMP%\_mei40842\_multiprocessing.pyd
- %TEMP%\_mei40842\_overlapped.pyd
- %TEMP%\_mei40842\_queue.pyd
- %TEMP%\_mei40842\_socket.pyd
- %TEMP%\_mei40842\_sqlite3.pyd
- %TEMP%\_mei40842\_ssl.pyd
- %TEMP%\_mei40842\_uuid.pyd
- %TEMP%\_mei40842\_win32sysloader.cp310-win_amd64.pyd
- DNS ASK google.com
- DNS ASK ip##pi.com
- DNS ASK di##ord.com
- ClassName: '' WindowName: ''
- '<Current directory>\runtime broker.exe'
- '<Current directory>\registry.exe'
- '<Current directory>\process builder.exe'
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "Runtime Broker.exe"
- '<SYSTEM32>\attrib.exe' +s +h "Runtime Broker.exe"
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "Registry.exe"
- '<SYSTEM32>\attrib.exe' +s +h "Registry.exe"
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "process builder.exe"
- '<SYSTEM32>\attrib.exe' +s +h "process builder.exe"
- '%WINDIR%\syswow64\cmd.exe' /C %TEMP%\tmpE23D.tmp.bat
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\timeout.exe' /T 2 /Nobreak
- '%WINDIR%\syswow64\cmd.exe' /C %TEMP%\tmpE23D.tmp.bat' (with hidden window)