Technical Information
- <SYSTEM32>\tasks\mergerprotask
- %TEMP%\_mei43402\vcruntime140.dll
- %TEMP%\_mei43402\_bz2.pyd
- %TEMP%\_mei43402\_ctypes.pyd
- %TEMP%\_mei43402\_decimal.pyd
- %TEMP%\_mei43402\_hashlib.pyd
- %TEMP%\_mei43402\_lzma.pyd
- %TEMP%\_mei43402\_socket.pyd
- %TEMP%\_mei43402\_uuid.pyd
- %TEMP%\_mei43402\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei43402\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei43402\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei43402\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei43402\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei43402\base_library.zip
- %TEMP%\_mei43402\libcrypto-3.dll
- %TEMP%\_mei43402\libffi-8.dll
- %TEMP%\_mei43402\python311.dll
- %TEMP%\_mei43402\select.pyd
- %TEMP%\_mei43402\ucrtbase.dll
- %TEMP%\_mei43402\unicodedata.pyd
- <Current directory>\merger_run.log
- C:\users\root\appdata\roaming\microsoft\windows\themes\applied\backup_20260531_212738.exe
- C:\users\root\appdata\local\microsoft\windows\explorer\backup_20260531_212738.exe
- %TEMP%\893_vhhl
- %TEMP%\tmp8ry_4slp.vbs
- %TEMP%\fused_4c4z1k6u\exe.exe
- C:\users\root\appdata\roaming\microsoft\windows\themes\applied\backup_20260531_212738.exe
- C:\users\root\appdata\local\microsoft\windows\explorer\backup_20260531_212738.exe
- %TEMP%\893_vhhl
- %TEMP%\tmp8ry_4slp.vbs
- %TEMP%\_mei43402\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei43402\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei43402\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei43402\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei43402\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei43402\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei43402\base_library.zip
- %TEMP%\_mei43402\libcrypto-3.dll
- %TEMP%\_mei43402\libffi-8.dll
- %TEMP%\_mei43402\python311.dll
- %TEMP%\_mei43402\select.pyd
- %TEMP%\_mei43402\ucrtbase.dll
- %TEMP%\_mei43402\unicodedata.pyd
- %TEMP%\_mei43402\vcruntime140.dll
- %TEMP%\_mei43402\_bz2.pyd
- %TEMP%\_mei43402\_ctypes.pyd
- %TEMP%\_mei43402\_decimal.pyd
- %TEMP%\_mei43402\_hashlib.pyd
- %TEMP%\_mei43402\_lzma.pyd
- %TEMP%\_mei43402\_socket.pyd
- %TEMP%\_mei43402\_uuid.pyd
- '<SYSTEM32>\cscript.exe' //NoLogo %TEMP%\tmp8ry_4slp.vbs
- '%TEMP%\fused_4c4z1k6u\exe.exe'
- '<SYSTEM32>\cmd.exe' /c "tasklist"
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\cmd.exe' /c "ver"
- '%WINDIR%\syswow64\fondue.exe' /enable-feature:NetFx3 /caller-name:mscoreei.dll
- '<SYSTEM32>\fondue.exe' /enable-feature:NetFx3 /caller-name:mscoreei.dll
- '<SYSTEM32>\cmd.exe' /c "tasklist"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)