Technical Information
- <SYSTEM32>\tasks\dllhost
- <SYSTEM32>\tasks\services
- %TEMP%\_mei4482\vcruntime140.dll
- %TEMP%\_mei4482\_bz2.pyd
- %TEMP%\_mei4482\_ctypes.pyd
- %TEMP%\_mei4482\_decimal.pyd
- %TEMP%\_mei4482\_hashlib.pyd
- %TEMP%\_mei4482\_lzma.pyd
- %TEMP%\_mei4482\_socket.pyd
- %TEMP%\_mei4482\_ssl.pyd
- %TEMP%\_mei4482\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei4482\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei4482\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei4482\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei4482\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei4482\base_library.zip
- %TEMP%\_mei4482\libcrypto-3.dll
- %TEMP%\_mei4482\libffi-8.dll
- %TEMP%\_mei4482\libssl-3.dll
- %TEMP%\_mei4482\python313.dll
- %TEMP%\_mei4482\select.pyd
- %TEMP%\_mei4482\ucrtbase.dll
- %TEMP%\_mei4482\unicodedata.pyd
- %TEMP%\bi07ofgv
- %TEMP%\system32cache_747b36b60d8a\explorer747b.exe
- %ProgramFiles(x86)%\microsoft office\dllhost.exe
- %LOCALAPPDATA%\microsoft help\services.exe
- %TEMP%\system32cache_747b36b60d8a\explorer747b.exe
- %ProgramFiles(x86)%\microsoft office\dllhost.exe
- %LOCALAPPDATA%\microsoft help\services.exe
- %TEMP%\bi07ofgv
- %TEMP%\_mei4482\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei4482\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei4482\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei4482\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei4482\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei4482\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei4482\base_library.zip
- %TEMP%\_mei4482\libcrypto-3.dll
- %TEMP%\_mei4482\libffi-8.dll
- %TEMP%\_mei4482\libssl-3.dll
- %TEMP%\_mei4482\python313.dll
- %TEMP%\_mei4482\select.pyd
- %TEMP%\_mei4482\ucrtbase.dll
- %TEMP%\_mei4482\unicodedata.pyd
- %TEMP%\_mei4482\vcruntime140.dll
- %TEMP%\_mei4482\_bz2.pyd
- %TEMP%\_mei4482\_ctypes.pyd
- %TEMP%\_mei4482\_decimal.pyd
- %TEMP%\_mei4482\_hashlib.pyd
- %TEMP%\_mei4482\_lzma.pyd
- %TEMP%\_mei4482\_socket.pyd
- %TEMP%\_mei4482\_ssl.pyd
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- DNS ASK dn#.google
- 'dn#.google':443
- '18#.#14.96.1':443
- '1.#.1.1':443
- '17#.#7.160.75':443
- '8.#.112.6':443
- '18#.#14.97.1':443
- '%TEMP%\system32cache_747b36b60d8a\explorer747b.exe'
- '%LOCALAPPDATA%\microsoft help\services.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe'
- '%TEMP%\system32cache_747b36b60d8a\explorer747b.exe' ' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' ' (with hidden window)