Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\winrarupdate.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath '%APPDATA%\.cache'
- %TEMP%\winrarupdate.exe
- %TEMP%\onedriveupdate.exe
- %TEMP%\_mei7082\cryptodome\cipher\_arc4.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_salsa20.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_chacha20.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_aes.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_aesni.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_arc2.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_blowfish.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_cast.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_cbc.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_cfb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ctr.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_des.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_des3.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ecb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ocb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ofb.pyd
- %TEMP%\_mei7082\cryptodome\hash\_blake2b.pyd
- %TEMP%\_mei7082\cryptodome\hash\_blake2s.pyd
- %TEMP%\_mei7082\cryptodome\hash\_md2.pyd
- %TEMP%\_mei7082\cryptodome\hash\_md4.pyd
- %TEMP%\_mei7082\cryptodome\hash\_md5.pyd
- %TEMP%\_mei7082\cryptodome\hash\_ripemd160.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha1.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha224.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha256.pyd
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %TEMP%\_mei7082\cryptodome\hash\_sha384.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha512.pyd
- %TEMP%\_mei7082\cryptodome\hash\_ghash_clmul.pyd
- %TEMP%\_mei7082\cryptodome\hash\_ghash_portable.pyd
- %TEMP%\_mei7082\cryptodome\hash\_keccak.pyd
- %TEMP%\_mei7082\cryptodome\hash\_poly1305.pyd
- %TEMP%\_mei7082\cryptodome\math\_modexp.pyd
- %TEMP%\_mei7082\cryptodome\protocol\_scrypt.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_curve25519.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_curve448.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_ec_ws.pyd
- %TEMP%\_mei9642\81d243bd2c585b0f4821__mypyc.cp310-win_amd64.pyd
- %TEMP%\_mei9642\vcruntime140.dll
- %TEMP%\_mei7082\cryptodome\publickey\_ed25519.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_ed448.pyd
- %TEMP%\_mei9642\variables.py
- %TEMP%\_mei9642\_asyncio.pyd
- %TEMP%\_mei7082\cryptodome\util\_cpuid_c.pyd
- %TEMP%\_mei9642\_bz2.pyd
- %TEMP%\_mei7082\cryptodome\util\_strxor.pyd
- %TEMP%\_mei7082\pil\_avif.cp310-win_amd64.pyd
- %TEMP%\_mei9642\_ctypes.pyd
- %TEMP%\_mei9642\_decimal.pyd
- %TEMP%\_mei9642\_hashlib.pyd
- %TEMP%\_mei9642\_lzma.pyd
- %TEMP%\_mei9642\_multiprocessing.pyd
- %TEMP%\_mei9642\_overlapped.pyd
- %TEMP%\_mei9642\_pytransform.dll
- %TEMP%\_mei9642\_queue.pyd
- %TEMP%\_mei9642\_socket.pyd
- %TEMP%\_mei9642\_ssl.pyd
- %TEMP%\_mei9642\_uuid.pyd
- %TEMP%\_mei9642\aiohttp\_http_parser.cp310-win_amd64.pyd
- %TEMP%\_mei9642\aiohttp\_http_writer.cp310-win_amd64.pyd
- %TEMP%\_mei9642\aiohttp\_websocket\mask.cp310-win_amd64.pyd
- %TEMP%\_mei9642\aiohttp\_websocket\reader_c.cp310-win_amd64.pyd
- %TEMP%\_mei9642\attrs-26.1.0.dist-info\installer
- %TEMP%\_mei9642\attrs-26.1.0.dist-info\metadata
- %TEMP%\_mei9642\attrs-26.1.0.dist-info\record
- %TEMP%\_mei9642\attrs-26.1.0.dist-info\wheel
- %TEMP%\_mei9642\attrs-26.1.0.dist-info\licenses\license
- %TEMP%\_mei9642\base_library.zip
- %TEMP%\_mei9642\certifi\cacert.pem
- %TEMP%\_mei9642\changepass.py
- %TEMP%\_mei9642\charset_normalizer\cd.cp310-win_amd64.pyd
- %TEMP%\_mei9642\charset_normalizer\md.cp310-win_amd64.pyd
- %TEMP%\_mei9642\checkedtokens.py
- %TEMP%\_mei9642\clipboard.py
- %TEMP%\_mei9642\directory.py
- %TEMP%\_mei9642\frozenlist\_frozenlist.cp310-win_amd64.pyd
- %TEMP%\_mei9642\geolocate.py
- %TEMP%\_mei9642\getenv.py
- %TEMP%\_mei9642\hidefile.py
- %TEMP%\_mei9642\libcrypto-1_1.dll
- %TEMP%\_mei7082\pil\_imaging.cp310-win_amd64.pyd
- %TEMP%\_mei9642\libffi-7.dll
- %TEMP%\_mei9642\libssl-1_1.dll
- %TEMP%\_mei9642\multidict\_multidict.cp310-win_amd64.pyd
- %TEMP%\_mei9642\propcache\_helpers_c.cp310-win_amd64.pyd
- %TEMP%\_mei9642\psutil\_psutil_windows.pyd
- %TEMP%\_mei9642\pyexpat.pyd
- %TEMP%\_mei9642\python3.dll
- %TEMP%\_mei9642\python310.dll
- %TEMP%\_mei7082\pil\_imagingcms.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_imagingmath.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_imagingtk.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_webp.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pythonwin\mfc140u.dll
- %TEMP%\_mei9642\rawtokens.py
- %TEMP%\_mei9642\receivefile.py
- %TEMP%\_mei9642\runfile.py
- %TEMP%\_mei9642\screenshot.py
- %TEMP%\_mei9642\select.pyd
- %TEMP%\_mei9642\sendfile.py
- %TEMP%\_mei9642\shell.py
- %TEMP%\_mei9642\startup.py
- %TEMP%\_mei9642\systeminfo.py
- %TEMP%\_mei9642\tasklist.py
- %TEMP%\_mei9642\unicodedata.pyd
- %TEMP%\_mei9642\webcam.py
- %TEMP%\_mei9642\wifi.py
- %TEMP%\_mei9642\yarl\_quoting_c.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pythonwin\win32ui.pyd
- %TEMP%\_mei7082\vcruntime140.dll
- %TEMP%\_mei7082\vcruntime140_1.dll
- %TEMP%\_mei7082\_asyncio.pyd
- %TEMP%\_mei7082\_bz2.pyd
- %TEMP%\_mei7082\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei7082\_ctypes.pyd
- %TEMP%\_mei7082\_decimal.pyd
- %TEMP%\_mei7082\_elementtree.pyd
- %TEMP%\_mei7082\_hashlib.pyd
- %TEMP%\_mei7082\_lzma.pyd
- %TEMP%\_mei7082\_msi.pyd
- %TEMP%\_mei7082\_multiprocessing.pyd
- %TEMP%\_mei7082\_overlapped.pyd
- %TEMP%\_mei7082\_queue.pyd
- %TEMP%\_mei7082\_socket.pyd
- %TEMP%\_mei7082\_sqlite3.pyd
- %TEMP%\_mei7082\_ssl.pyd
- %TEMP%\_mei7082\base_library.zip
- %TEMP%\_mei7082\certifi\cacert.pem
- %TEMP%\_mei7082\charset_normalizer\md.cp310-win_amd64.pyd
- %TEMP%\_mei7082\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\installer
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\metadata
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\record
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\wheel
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\licenses\license
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei7082\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei7082\cv2\__init__.py
- %TEMP%\_mei7082\cv2\config-3.py
- %TEMP%\_mei7082\cv2\config.py
- %TEMP%\_mei7082\cv2\cv2.pyd
- %TEMP%\_mei7082\cv2\data\__init__.py
- %TEMP%\_mei7082\cv2\gapi\__init__.py
- %TEMP%\_mei7082\cv2\load_config_py3.py
- %TEMP%\_mei7082\cv2\mat_wrapper\__init__.py
- %TEMP%\_mei7082\cv2\misc\__init__.py
- %TEMP%\_mei7082\cv2\misc\version.py
- %TEMP%\_mei7082\cv2\opencv_videoio_ffmpeg4120_64.dll
- %TEMP%\_mei7082\cv2\typing\__init__.py
- %TEMP%\_mei7082\cv2\utils\__init__.py
- %TEMP%\_mei7082\cv2\version.py
- %TEMP%\_mei7082\libcrypto-1_1.dll
- %TEMP%\_mei7082\libffi-7.dll
- %TEMP%\_mei7082\libssl-1_1.dll
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\installer
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\metadata
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\record
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\wheel
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\licenses\license
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\top_level.txt
- %TEMP%\_mei7082\lz4\_version.cp310-win_amd64.pyd
- %TEMP%\_mei7082\lz4\block\_block.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\delvewheel
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\installer
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\license.txt
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\metadata
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\record
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\wheel
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\entry_points.txt
- %TEMP%\_mei7082\numpy.libs\libscipy_openblas64_-13e2df515630b4a41f92893938845698.dll
- %TEMP%\_mei7082\numpy.libs\msvcp140-263139962577ecda4cd9469ca360a746.dll
- %TEMP%\_mei7082\numpy\_core\_multiarray_tests.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\_core\_multiarray_umath.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\fft\_pocketfft_umath.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\linalg\_umath_linalg.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_bounded_integers.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_common.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_generator.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_mt19937.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_pcg64.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_philox.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_sfc64.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\bit_generator.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\mtrand.cp310-win_amd64.pyd
- %TEMP%\_mei7082\psutil\_psutil_windows.pyd
- %TEMP%\_mei7082\pyexpat.pyd
- %TEMP%\_mei7082\python3.dll
- %TEMP%\_mei7082\python310.dll
- %TEMP%\_mei7082\pywin32_system32\pythoncom310.dll
- %TEMP%\_mei7082\pywin32_system32\pywintypes310.dll
- %TEMP%\_mei7082\select.pyd
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\installer
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\license
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\metadata
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\record
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\wheel
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\entry_points.txt
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\top_level.txt
- %TEMP%\_mei7082\sqlite3.dll
- %TEMP%\_mei7082\unicodedata.pyd
- %TEMP%\_mei7082\win32\_win32sysloader.pyd
- %TEMP%\_mei7082\win32\win32api.pyd
- %TEMP%\_mei7082\win32\win32crypt.pyd
- %TEMP%\_mei7082\win32\win32event.pyd
- %TEMP%\_mei7082\win32\win32pdh.pyd
- %TEMP%\_mei7082\win32\win32trace.pyd
- %TEMP%\_mei7082\win32com\shell\shell.pyd
- %TEMP%\gen_py\3.10\__init__.py
- %TEMP%\gen_py\3.10\dicts.dat
- %TEMP%\_mei7082\base_library.zip
- %TEMP%\_mei7082\certifi\cacert.pem
- %TEMP%\_mei7082\charset_normalizer\md.cp310-win_amd64.pyd
- %TEMP%\_mei7082\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_arc4.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_chacha20.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_aes.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_aesni.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_arc2.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_blowfish.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_cast.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_cbc.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_cfb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ctr.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_des.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_des3.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ecb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ocb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_raw_ofb.pyd
- %TEMP%\_mei7082\cryptodome\cipher\_salsa20.pyd
- %TEMP%\_mei7082\cryptodome\hash\_blake2b.pyd
- %TEMP%\_mei7082\cryptodome\hash\_blake2s.pyd
- %TEMP%\_mei7082\cryptodome\hash\_ghash_clmul.pyd
- %TEMP%\_mei7082\cryptodome\hash\_ghash_portable.pyd
- %TEMP%\_mei7082\cryptodome\hash\_keccak.pyd
- %TEMP%\_mei7082\cryptodome\hash\_md2.pyd
- %TEMP%\_mei7082\cryptodome\hash\_md4.pyd
- %TEMP%\_mei7082\cryptodome\hash\_md5.pyd
- %TEMP%\_mei7082\cryptodome\hash\_poly1305.pyd
- %TEMP%\_mei7082\cryptodome\hash\_ripemd160.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha1.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha224.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha256.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha384.pyd
- %TEMP%\_mei7082\cryptodome\hash\_sha512.pyd
- %TEMP%\_mei7082\cryptodome\math\_modexp.pyd
- %TEMP%\_mei7082\cryptodome\protocol\_scrypt.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_curve25519.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_curve448.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_ec_ws.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_ed25519.pyd
- %TEMP%\_mei7082\cryptodome\publickey\_ed448.pyd
- %TEMP%\_mei7082\cryptodome\util\_cpuid_c.pyd
- %TEMP%\_mei7082\cryptodome\util\_strxor.pyd
- %TEMP%\_mei7082\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\installer
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\licenses\license
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\metadata
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\record
- %TEMP%\_mei7082\cryptography-46.0.3.dist-info\wheel
- %TEMP%\_mei7082\cv2\config-3.py
- %TEMP%\_mei7082\cv2\config.py
- %TEMP%\_mei7082\cv2\cv2.pyd
- %TEMP%\_mei7082\cv2\data\__init__.py
- %TEMP%\_mei7082\cv2\gapi\__init__.py
- %TEMP%\_mei7082\cv2\load_config_py3.py
- %TEMP%\_mei7082\cv2\mat_wrapper\__init__.py
- %TEMP%\_mei7082\cv2\misc\version.py
- %TEMP%\_mei7082\cv2\misc\__init__.py
- %TEMP%\_mei7082\cv2\opencv_videoio_ffmpeg4120_64.dll
- %TEMP%\_mei7082\cv2\typing\__init__.py
- %TEMP%\_mei7082\cv2\utils\__init__.py
- %TEMP%\_mei7082\cv2\version.py
- %TEMP%\_mei7082\cv2\__init__.py
- %TEMP%\_mei7082\libcrypto-1_1.dll
- %TEMP%\_mei7082\libffi-7.dll
- %TEMP%\_mei7082\libssl-1_1.dll
- %TEMP%\_mei7082\lz4\block\_block.cp310-win_amd64.pyd
- %TEMP%\_mei7082\lz4\_version.cp310-win_amd64.pyd
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\installer
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\licenses\license
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\metadata
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\record
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\top_level.txt
- %TEMP%\_mei7082\lz4-4.4.5.dist-info\wheel
- %TEMP%\_mei7082\numpy\fft\_pocketfft_umath.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\linalg\_umath_linalg.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\bit_generator.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\mtrand.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_bounded_integers.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_common.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_generator.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_mt19937.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_pcg64.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_philox.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\random\_sfc64.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\_core\_multiarray_tests.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy\_core\_multiarray_umath.cp310-win_amd64.pyd
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\delvewheel
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\entry_points.txt
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\installer
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\license.txt
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\metadata
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\record
- %TEMP%\_mei7082\numpy-2.2.6.dist-info\wheel
- %TEMP%\_mei7082\numpy.libs\libscipy_openblas64_-13e2df515630b4a41f92893938845698.dll
- %TEMP%\_mei7082\numpy.libs\msvcp140-263139962577ecda4cd9469ca360a746.dll
- %TEMP%\_mei7082\pil\_avif.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_imaging.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_imagingcms.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_imagingmath.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_imagingtk.cp310-win_amd64.pyd
- %TEMP%\_mei7082\pil\_webp.cp310-win_amd64.pyd
- %TEMP%\_mei7082\psutil\_psutil_windows.pyd
- %TEMP%\_mei7082\pyexpat.pyd
- %TEMP%\_mei7082\python3.dll
- %TEMP%\_mei7082\python310.dll
- %TEMP%\_mei7082\pythonwin\mfc140u.dll
- %TEMP%\_mei7082\pythonwin\win32ui.pyd
- %TEMP%\_mei7082\pywin32_system32\pythoncom310.dll
- %TEMP%\_mei7082\pywin32_system32\pywintypes310.dll
- %TEMP%\_mei7082\select.pyd
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\entry_points.txt
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\installer
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\license
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\metadata
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\record
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\top_level.txt
- %TEMP%\_mei7082\setuptools-63.2.0.dist-info\wheel
- %TEMP%\_mei7082\sqlite3.dll
- %TEMP%\_mei7082\unicodedata.pyd
- %TEMP%\_mei7082\vcruntime140.dll
- %TEMP%\_mei7082\vcruntime140_1.dll
- %TEMP%\_mei7082\win32\win32api.pyd
- %TEMP%\_mei7082\win32\win32crypt.pyd
- %TEMP%\_mei7082\win32\win32event.pyd
- %TEMP%\_mei7082\win32\win32pdh.pyd
- %TEMP%\_mei7082\win32\win32trace.pyd
- %TEMP%\_mei7082\win32\_win32sysloader.pyd
- %TEMP%\_mei7082\win32com\shell\shell.pyd
- %TEMP%\_mei7082\_asyncio.pyd
- %TEMP%\_mei7082\_bz2.pyd
- %TEMP%\_mei7082\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei7082\_ctypes.pyd
- %TEMP%\_mei7082\_decimal.pyd
- %TEMP%\_mei7082\_elementtree.pyd
- %TEMP%\_mei7082\_hashlib.pyd
- %TEMP%\_mei7082\_lzma.pyd
- %TEMP%\_mei7082\_msi.pyd
- %TEMP%\_mei7082\_multiprocessing.pyd
- %TEMP%\_mei7082\_overlapped.pyd
- %TEMP%\_mei7082\_queue.pyd
- %TEMP%\_mei7082\_socket.pyd
- %TEMP%\_mei7082\_sqlite3.pyd
- %TEMP%\_mei7082\_ssl.pyd
- 'localhost':49694
- '1.#.1.1':53
- DNS ASK google.com
- '%TEMP%\winrarupdate.exe'
- '%TEMP%\onedriveupdate.exe'
- '<SYSTEM32>\cmd.exe' /c "ver"
- '<SYSTEM32>\cmd.exe' /c "powershell Add-MpPreference -ExclusionPath '%APPDATA%\.cache'"
- '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell Add-MpPreference -ExclusionPath '%APPDATA%\.cache'"' (with hidden window)