| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 20:39:13 | 2026-05-28 20:42:57 | 224s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:52:07,597 [root] INFO: Date set to: 20260528T20:39:20, timeout set to: 200
2026-05-28 20:39:20,016 [root] DEBUG: Starting analyzer from: C:\_3mo6uuq
2026-05-28 20:39:20,016 [root] DEBUG: Storing results at: C:\QJqaJqCEA
2026-05-28 20:39:20,017 [root] DEBUG: Pipe server name: \\.\PIPE\hvcjHyn
2026-05-28 20:39:20,017 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 20:39:20,018 [root] INFO: analysis running as an admin
2026-05-28 20:39:20,018 [root] INFO: analysis package specified: "edge"
2026-05-28 20:39:20,019 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 20:39:20,022 [root] DEBUG: imported analysis package "edge"
2026-05-28 20:39:20,023 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 20:39:20,026 [root] DEBUG: New location of moved file: https://github.com/ytisf/theZoo
2026-05-28 20:39:20,026 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 20:39:20,026 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 20:39:20,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 20:39:20,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 20:39:20,036 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 20:39:20,106 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 20:39:20,114 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 20:39:20,132 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 20:39:20,135 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 20:39:20,135 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 20:39:20,136 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 20:39:20,141 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 20:39:20,141 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 20:39:20,141 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 20:39:20,142 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 20:39:20,142 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 20:39:20,143 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 20:39:20,143 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 20:39:20,143 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 20:39:20,143 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 20:39:20,144 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 20:39:20,144 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 20:39:20,144 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 20:39:20,144 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 20:39:20,144 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 20:39:20,144 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 20:39:20,144 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 20:39:20,164 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 1380)
2026-05-28 20:39:20,164 [modules.auxiliary.disguise] INFO: Disguising GUID to 87319691-f9d4-47d8-ada7-65a54a3cbaa3
2026-05-28 20:39:20,165 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 20:39:20,165 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 20:39:20,165 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 20:39:20,166 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 20:39:20,166 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 20:39:20,166 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 20:39:20,166 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 20:39:20,167 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 20:39:20,167 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 20:39:20,167 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 20:39:20,168 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 20:39:20,168 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 20:39:20,168 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 20:39:20,169 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 20:39:20,169 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 20:39:20,170 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 20:39:20,172 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 20:39:20,172 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 20:39:20,172 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 20:39:20,208 [lib.api.process] INFO: Monitor config for process 4372: C:\_3mo6uuq\dll\4372.ini
2026-05-28 20:39:20,210 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:20,212 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:20,238 [root] DEBUG: Loader: Injecting process 4372 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:20,411 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:39:20,412 [root] DEBUG: 4372: Disabling sleep skipping.
2026-05-28 20:39:20,412 [root] DEBUG: 4372: Interactive desktop enabled.
2026-05-28 20:39:20,412 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 20:39:20,413 [root] DEBUG: 4372: Interactive desktop - injecting Explorer Shell
2026-05-28 20:39:20,418 [root] DEBUG: 4372: YaraInit: Compiled 44 rule files
2026-05-28 20:39:20,419 [root] DEBUG: 4372: YaraInit: Compiled rules saved to file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:39:20,435 [root] DEBUG: 4372: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:39:20,436 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:39:20,495 [root] DEBUG: 4372: Monitor initialised: 64-bit capemon loaded in process 4372 at 0x00007FFEAF1A0000, thread 2856, image base 0x00007FF65F9E0000, stack from 0x000000000A7C2000-0x000000000A7D0000
2026-05-28 20:39:20,496 [root] DEBUG: 4372: Commandline: C:\Windows\Explorer.EXE
2026-05-28 20:39:20,508 [root] DEBUG: 4372: Hooked 69 out of 69 functions
2026-05-28 20:39:20,538 [root] DEBUG: 4372: Syscall hook installed, syscall logging level 1
2026-05-28 20:39:20,550 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:39:20,551 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:20,553 [lib.api.process] INFO: Injected into 64-bit <Process 4372 explorer.exe>
2026-05-28 20:39:27,685 [root] INFO: Restarting WMI Service
2026-05-28 20:39:29,710 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 20:39:29,711 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 20:39:29,711 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 20:39:29,712 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://github.com/ytisf/theZoo"" with pid 7496
2026-05-28 20:39:29,713 [lib.api.process] INFO: Monitor config for process 7496: C:\_3mo6uuq\dll\7496.ini
2026-05-28 20:39:29,714 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:29,715 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:29,719 [root] DEBUG: Loader: Injecting process 7496 (thread 7504) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:29,720 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:29,720 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:29,721 [lib.api.process] INFO: Injected into 64-bit <Process 7496 msedge.exe>
2026-05-28 20:39:31,732 [lib.api.process] INFO: Successfully resumed process with pid 7496
2026-05-28 20:39:31,853 [root] DEBUG: 7496: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:39:31,854 [root] DEBUG: 7496: Disabling sleep skipping.
2026-05-28 20:39:31,855 [root] DEBUG: 7496: Interactive desktop enabled.
2026-05-28 20:39:31,856 [root] DEBUG: 7496: Dropped file limit defaulting to 100.
2026-05-28 20:39:31,883 [root] DEBUG: 7496: Edge-specific hook-set enabled.
2026-05-28 20:39:31,885 [root] DEBUG: 7496: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:39:31,898 [root] DEBUG: 7496: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:39:31,898 [root] DEBUG: 7496: Monitor initialised: 64-bit capemon loaded in process 7496 at 0x00007FFEAF1A0000, thread 7504, image base 0x00007FF60A060000, stack from 0x000000FA135F4000-0x000000FA13600000
2026-05-28 20:39:31,899 [root] DEBUG: 7496: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://github.com/ytisf/theZoo"
2026-05-28 20:39:31,909 [root] DEBUG: 7496: Hooked 2 out of 2 functions
2026-05-28 20:39:31,945 [root] DEBUG: 7496: Syscall hook installed, syscall logging level 1
2026-05-28 20:39:31,950 [root] DEBUG: 7496: RestoreHeaders: Restored original import table.
2026-05-28 20:39:31,951 [root] INFO: Loaded monitor into process with pid 7496
2026-05-28 20:39:31,953 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:39:31,958 [root] DEBUG: 7496: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:39:31,959 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:39:31,960 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:39:31,961 [root] DEBUG: 7496: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:39:31,962 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:39:31,963 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:39:32,114 [root] DEBUG: 7496: DLL loaded at 0x00007FFED8180000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 20:39:32,115 [root] DEBUG: 7496: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:39:32,118 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDD470000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 20:39:32,120 [root] DEBUG: 7496: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:39:32,125 [root] DEBUG: 7496: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:39:32,126 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 8048: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:32,126 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 8048
2026-05-28 20:39:32,126 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:39:32,128 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 8048
2026-05-28 20:39:32,129 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE5AA0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 20:39:32,130 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:39:32,130 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:39:32,134 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:39:32,135 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEDFA0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:39:32,136 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:39:32,137 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:39:32,139 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:39:32,139 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE5A30000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 20:39:32,141 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:39:32,141 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:39:32,142 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 20:39:32,142 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:39:32,143 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 20:39:32,143 [root] DEBUG: 7496: DLL loaded at 0x00007FFED4750000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 20:39:32,143 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE59F0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 20:39:32,144 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:39:32,145 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:39:32,146 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:39:32,147 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:39:32,147 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:39:32,147 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 20:39:32,149 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF640000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:39:32,158 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE5A80000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 20:39:32,159 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:39:32,160 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE6360000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:39:32,161 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:39:32,161 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:39:32,163 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE23A0000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 20:39:32,165 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 20:39:32,166 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 20:39:32,167 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:39:32,168 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:39:32,170 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEAE30000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 20:39:32,172 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:39:32,173 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:39:32,174 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE8E40000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:39:32,175 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE5AC0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 20:39:32,175 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE8D30000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:39:32,176 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEB280000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 20:39:32,177 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEB10000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:39:32,180 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:39:32,182 [root] DEBUG: 7496: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:39:32,183 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:39:32,183 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEC530000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:39:32,183 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 20:39:32,185 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDF7D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 20:39:32,187 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:39:32,189 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 20:39:32,191 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:39:32,192 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE9A90000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 20:39:32,196 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE96E0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:39:32,196 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE3950000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 20:39:32,197 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:39:32,198 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDEC10000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 20:39:32,199 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 20:39:32,204 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:39:32,207 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE8F40000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 20:39:32,207 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE8F60000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 20:39:32,208 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 20:39:32,209 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:39:32,210 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:39:32,223 [root] DEBUG: 7496: DLL loaded at 0x00007FFE99CC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 20:39:32,243 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE2620000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 20:39:32,245 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE0DA0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 20:39:32,245 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 1440: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:32,246 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 1440
2026-05-28 20:39:32,248 [root] DEBUG: 7496: caller_dispatch: Added region at 0x00007FF60A060000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF60A157D66, thread 3516).
2026-05-28 20:39:32,249 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 1440
2026-05-28 20:39:32,255 [root] DEBUG: 7496: ProcessImageBase: Main module image at 0x00007FF60A060000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:39:32,256 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 1656: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:32,257 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 1656
2026-05-28 20:39:32,258 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 1656
2026-05-28 20:39:32,275 [root] DEBUG: 7496: DLL loaded at 0x00007FFED7420000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 20:39:32,276 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 2484: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:32,278 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 2484
2026-05-28 20:39:32,280 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 2484
2026-05-28 20:39:32,298 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF4A0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 20:39:32,304 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:39:32,305 [root] DEBUG: 7496: DLL loaded at 0x00007FFED6CB0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 20:39:32,313 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 20:39:32,314 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEBC70000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 20:39:32,315 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEC340000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 20:39:32,315 [root] DEBUG: 7496: DLL loaded at 0x00007FFED88A0000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 20:39:32,346 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE59C0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 20:39:32,362 [root] DEBUG: 7496: DLL loaded at 0x00007FFEED220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 20:39:32,369 [root] DEBUG: 7496: DLL loaded at 0x00007FFED8910000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 20:39:32,370 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 508: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:32,370 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 508
2026-05-28 20:39:32,371 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 892: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:32,371 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE1330000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 20:39:32,373 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 892
2026-05-28 20:39:32,374 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 508
2026-05-28 20:39:32,375 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 892
2026-05-28 20:39:32,398 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDA250000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 20:39:32,401 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:39:32,431 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:39:32,434 [root] DEBUG: 4372: caller_dispatch: Added region at 0x00007FF65F9E0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00007FF65FA4B354, thread 5628).
2026-05-28 20:39:32,459 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDFDE0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 20:39:32,470 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:39:32,470 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:39:32,506 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:39:32,518 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:39:32,523 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:39:32,524 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:39:32,547 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDCBB0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 20:39:32,552 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:39:32,555 [root] DEBUG: 7496: DLL loaded at 0x00007FFED9A80000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 20:39:32,578 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE5860000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-28 20:39:32,583 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDFA20000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 20:39:33,795 [root] DEBUG: 7496: DLL loaded at 0x00007FFED5C90000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 20:39:34,132 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:39:34,133 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:39:38,090 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 2772: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:39:38,094 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:39:38,095 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 2772
2026-05-28 20:39:38,097 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 20:39:38,098 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 2772
2026-05-28 20:39:38,197 [root] DEBUG: 7496: DLL loaded at 0x00007FFED8C50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 20:39:38,633 [root] DEBUG: 7496: DLL loaded at 0x00007FFE96BA0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 20:39:38,780 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:39:38,784 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:39:38,787 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:39:38,791 [root] DEBUG: 7496: DLL loaded at 0x00007FFE99850000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 20:39:38,795 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE330000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 20:39:38,797 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE2C0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 20:39:38,827 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDFC80000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 20:39:38,857 [root] DEBUG: 7496: DLL loaded at 0x00007FFED9A00000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 20:39:38,954 [root] DEBUG: 7496: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:39:38,956 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:39:38,958 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:39:39,366 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 1180: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7EB0E0000
2026-05-28 20:39:39,367 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 1180
2026-05-28 20:39:39,368 [lib.api.process] INFO: Monitor config for process 1180: C:\_3mo6uuq\dll\1180.ini
2026-05-28 20:39:39,369 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:39,976 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:39:39,976 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:39:39,981 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:39,985 [root] DEBUG: Loader: Injecting process 1180 (thread 4504) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:39,986 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:39,986 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:39,988 [lib.api.process] INFO: Injected into 64-bit <Process 1180 identity_helper.exe>
2026-05-28 20:39:39,992 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:39:39,993 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:39:39,994 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 6168: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7EB0E0000
2026-05-28 20:39:39,995 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 6168
2026-05-28 20:39:39,995 [lib.api.process] INFO: Monitor config for process 6168: C:\_3mo6uuq\dll\6168.ini
2026-05-28 20:39:39,996 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:40,072 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:39:40,073 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:39:40,075 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:40,079 [root] DEBUG: Loader: Injecting process 6168 (thread 6164) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:40,080 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:40,080 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:40,082 [lib.api.process] INFO: Injected into 64-bit <Process 6168 identity_helper.exe>
2026-05-28 20:39:40,083 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 6168
2026-05-28 20:39:40,084 [lib.api.process] INFO: Monitor config for process 6168: C:\_3mo6uuq\dll\6168.ini
2026-05-28 20:39:40,084 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:40,157 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:39:40,158 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:39:40,160 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:40,164 [root] DEBUG: Loader: Injecting process 6168 (thread 6164) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:40,164 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:39:40,166 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:40,168 [lib.api.process] INFO: Injected into 64-bit <Process 6168 identity_helper.exe>
2026-05-28 20:39:40,192 [root] DEBUG: 6168: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:39:40,193 [root] DEBUG: 6168: Interactive desktop enabled.
2026-05-28 20:39:40,193 [root] DEBUG: 6168: Dropped file limit defaulting to 100.
2026-05-28 20:39:40,199 [root] DEBUG: 6168: Disabling sleep skipping.
2026-05-28 20:39:40,201 [root] DEBUG: 6168: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:39:40,208 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE6BA0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 20:39:40,213 [root] DEBUG: 6168: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:39:40,214 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,231 [root] DEBUG: 6168: Monitor initialised: 64-bit capemon loaded in process 6168 at 0x00007FFEAF1A0000, thread 6164, image base 0x00007FF7EB0E0000, stack from 0x000000F920704000-0x000000F920710000
2026-05-28 20:39:40,231 [root] DEBUG: 6168: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5884,i,12977939333027544551,17542578104501272867,524288 --field-trial-handle=2408,i,420509895758983111,2918215219286569779,262144 --variations-seed-version --pseudonymization-salt-handle=2272,i,14365779423756358386,13313620214298922
2026-05-28 20:39:40,232 [root] DEBUG: 6168: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 20:39:40,241 [root] DEBUG: 6168: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:39:40,266 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:39:40,266 [root] DEBUG: 6168: set_hooks: Unable to hook LockResource
2026-05-28 20:39:40,272 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:39:40,273 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEA040000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 20:39:40,276 [root] DEBUG: 6168: Hooked 627 out of 628 functions
2026-05-28 20:39:40,292 [root] DEBUG: 6168: Syscall hook installed, syscall logging level 1
2026-05-28 20:39:40,297 [root] DEBUG: 6168: RestoreHeaders: Restored original import table.
2026-05-28 20:39:40,297 [root] INFO: Loaded monitor into process with pid 6168
2026-05-28 20:39:40,298 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,410 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,434 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,458 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,482 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,506 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,532 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:39:40,558 [root] DEBUG: 6168: caller_dispatch: Added region at 0x00007FFEAECE0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFEAEEDF156, thread 6164).
2026-05-28 20:39:40,559 [root] DEBUG: 6168: caller_dispatch: Scanning calling region at 0x00007FFEAECE0000...
2026-05-28 20:39:40,570 [root] DEBUG: 6168: ProcessTrackedRegion: Region at 0x00007FFEAECE0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 20:39:40,571 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:39:40,599 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,621 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,635 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,650 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,666 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,683 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,701 [root] DEBUG: 6168: caller_dispatch: Added region at 0x00007FF7EB0E0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7EB1D4096, thread 6164).
2026-05-28 20:39:40,701 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7EB0E0000, size 0x28b4d8
2026-05-28 20:39:40,710 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 20:39:40,711 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:39:40,712 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE6DC0000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 20:39:40,713 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:39:40,713 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 20:39:40,714 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDBC30000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 20:39:40,717 [root] DEBUG: 6168: ProcessImageBase: Main module image at 0x00007FF7EB0E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:39:40,720 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:39:40,740 [root] DEBUG: 6168: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:39:40,743 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:39:40,752 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:39:40,782 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:39:40,854 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEEDE0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:39:40,983 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:39:40,987 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:39:40,988 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEB280000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 20:39:40,988 [root] DEBUG: 6168: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:39:40,989 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDCB10000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 20:39:40,995 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:39:40,997 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:39:40,997 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:39:40,998 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:39:40,998 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:39:41,012 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:39:41,025 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDE2F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 20:39:41,031 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:39:41,031 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:39:41,034 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:39:41,044 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:39:41,047 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:39:41,053 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:39:41,054 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:39:41,060 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF210000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:39:41,075 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:39:41,082 [root] DEBUG: 6168: DLL loaded at 0x000002A603880000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 20:39:41,087 [lib.api.process] INFO: Monitor config for process 848: C:\_3mo6uuq\dll\848.ini
2026-05-28 20:39:41,088 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:41,089 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:41,093 [root] DEBUG: Loader: Injecting process 848 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:41,094 [root] DEBUG: 848: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:39:41,094 [root] DEBUG: 848: Disabling sleep skipping.
2026-05-28 20:39:41,095 [root] DEBUG: 848: Interactive desktop enabled.
2026-05-28 20:39:41,095 [root] DEBUG: 848: Dropped file limit defaulting to 100.
2026-05-28 20:39:41,099 [root] DEBUG: 848: Services hook set enabled
2026-05-28 20:39:41,100 [root] DEBUG: 848: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:39:41,111 [root] DEBUG: 848: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:39:41,112 [root] DEBUG: 848: Monitor initialised: 64-bit capemon loaded in process 848 at 0x00007FFEAF1A0000, thread 9396, image base 0x00007FF6A8D80000, stack from 0x0000006A4DD74000-0x0000006A4DD80000
2026-05-28 20:39:41,112 [root] DEBUG: 848: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 20:39:41,124 [root] DEBUG: 848: Hooked 69 out of 69 functions
2026-05-28 20:39:41,124 [root] INFO: Loaded monitor into process with pid 848
2026-05-28 20:39:41,125 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:39:41,125 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:41,126 [lib.api.process] INFO: Injected into 64-bit <Process 848 svchost.exe>
2026-05-28 20:39:43,147 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE5370000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 20:39:43,148 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE4650000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 20:39:43,149 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDAE80000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 20:39:43,150 [root] DEBUG: 6168: DLL loaded at 0x00007FFED4AB0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 20:39:43,160 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE9FE0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 20:39:43,179 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 20:39:43,180 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEBC70000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 20:39:43,582 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE1590000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 20:39:43,583 [root] DEBUG: 6168: DLL loaded at 0x00007FFED4800000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 20:39:43,608 [root] DEBUG: 6168: DLL loaded at 0x00007FFED5E10000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 20:39:43,627 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:39:43,628 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF080000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 20:39:43,628 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:39:43,629 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE4250000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:39:43,629 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDA8F0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 20:39:43,649 [root] DEBUG: 6168: DLL loaded at 0x00007FFED4BF0000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 20:39:43,665 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:39:43,690 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:39:53,788 [root] INFO: Process with pid 6168 has terminated
2026-05-28 20:39:53,792 [root] DEBUG: 6168: NtTerminateProcess hook: Attempting to dump process 6168
2026-05-28 20:39:53,796 [root] DEBUG: 6168: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:39:54,957 [root] DEBUG: 4372: DLL loaded at 0x00007FFED99E0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:39:54,972 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9668: C:\Windows\system32\ApplicationFrameHost.exe, ImageBase: 0x00007FF6477E0000
2026-05-28 20:39:54,973 [root] INFO: Announced 64-bit process name: ApplicationFrameHost.exe pid: 9668
2026-05-28 20:39:54,973 [lib.api.process] INFO: Monitor config for process 9668: C:\_3mo6uuq\dll\9668.ini
2026-05-28 20:39:54,974 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:54,975 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:54,976 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9712: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe, ImageBase: 0x00007FF7D7CD0000
2026-05-28 20:39:54,976 [root] INFO: Announced 64-bit process name: WinStore.App.exe pid: 9712
2026-05-28 20:39:54,977 [lib.api.process] INFO: Monitor config for process 9712: C:\_3mo6uuq\dll\9712.ini
2026-05-28 20:39:54,977 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:54,979 [root] DEBUG: Loader: Injecting process 9668 (thread 9672) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:54,979 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:54,980 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:54,981 [lib.api.process] INFO: Injected into 64-bit <Process 9668 ApplicationFrameHost.exe>
2026-05-28 20:39:54,983 [root] INFO: Announced 64-bit process name: ApplicationFrameHost.exe pid: 9668
2026-05-28 20:39:54,983 [lib.api.process] INFO: Monitor config for process 9668: C:\_3mo6uuq\dll\9668.ini
2026-05-28 20:39:54,984 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:54,985 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:54,989 [root] DEBUG: Loader: Injecting process 9668 (thread 9672) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:54,989 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:54,990 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:54,991 [lib.api.process] INFO: Injected into 64-bit <Process 9668 ApplicationFrameHost.exe>
2026-05-28 20:39:54,997 [root] DEBUG: 9668: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:39:54,997 [root] DEBUG: 9668: Interactive desktop enabled.
2026-05-28 20:39:54,998 [root] DEBUG: 9668: Dropped file limit defaulting to 100.
2026-05-28 20:39:54,999 [root] DEBUG: 9668: Disabling sleep skipping.
2026-05-28 20:39:55,000 [root] DEBUG: 9668: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:39:55,012 [root] DEBUG: 9668: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:39:55,012 [root] DEBUG: 9668: YaraScan: Scanning 0x00007FF6477E0000, size 0x14222
2026-05-28 20:39:55,013 [root] DEBUG: 9668: Monitor initialised: 64-bit capemon loaded in process 9668 at 0x00007FFEAF1A0000, thread 9672, image base 0x00007FF6477E0000, stack from 0x0000004D0DDF4000-0x0000004D0DE00000
2026-05-28 20:39:55,014 [root] DEBUG: 9668: Commandline: C:\Windows\system32\ApplicationFrameHost.exe -Embedding
2026-05-28 20:39:55,023 [root] DEBUG: 9668: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:39:55,043 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:39:55,044 [root] DEBUG: 9668: set_hooks: Unable to hook LockResource
2026-05-28 20:39:55,048 [root] DEBUG: 9668: Hooked 627 out of 628 functions
2026-05-28 20:39:55,049 [root] DEBUG: 9668: Syscall hook installed, syscall logging level 1
2026-05-28 20:39:55,053 [root] DEBUG: 9668: RestoreHeaders: Restored original import table.
2026-05-28 20:39:55,054 [root] INFO: Loaded monitor into process with pid 9668
2026-05-28 20:39:55,057 [root] DEBUG: 9668: caller_dispatch: Added region at 0x00007FF6477E0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6477E2DE1, thread 9672).
2026-05-28 20:39:55,057 [root] DEBUG: 9668: YaraScan: Scanning 0x00007FF6477E0000, size 0x14222
2026-05-28 20:39:55,059 [root] DEBUG: 9668: ProcessImageBase: Main module image at 0x00007FF6477E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:39:55,060 [root] DEBUG: 9668: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:39:55,061 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:39:55,063 [root] DEBUG: 9668: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:39:55,067 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEB280000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 20:39:55,068 [root] DEBUG: 9668: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:39:55,068 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:39:55,068 [root] DEBUG: 9668: DLL loaded at 0x00007FFEED0B0000: C:\Windows\System32\UxTheme (0x9e000 bytes).
2026-05-28 20:39:55,069 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:39:55,069 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\System32\DEVOBJ (0x33000 bytes).
2026-05-28 20:39:55,070 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE41E0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 20:39:55,070 [root] DEBUG: 9668: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\System32\TWINAPI (0xa9000 bytes).
2026-05-28 20:39:55,071 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEB6B0000: C:\Windows\System32\d2d1 (0x5c0000 bytes).
2026-05-28 20:39:55,071 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEBC70000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 20:39:55,071 [root] DEBUG: 9668: DLL loaded at 0x00007FFEED220000: C:\Windows\System32\dwmapi (0x2f000 bytes).
2026-05-28 20:39:55,072 [root] DEBUG: 9668: DLL loaded at 0x00007FFED78B0000: C:\Windows\System32\ApplicationFrame (0xa9000 bytes).
2026-05-28 20:39:55,075 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:55,079 [root] DEBUG: Loader: Injecting process 9712 (thread 9716) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,079 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:55,079 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,080 [lib.api.process] INFO: Injected into 64-bit <Process 9712 WinStore.App.exe>
2026-05-28 20:39:55,081 [root] INFO: Announced 64-bit process name: WinStore.App.exe pid: 9712
2026-05-28 20:39:55,082 [lib.api.process] INFO: Monitor config for process 9712: C:\_3mo6uuq\dll\9712.ini
2026-05-28 20:39:55,082 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:55,089 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:39:55,097 [root] DEBUG: 9668: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:39:55,100 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE6F40000: C:\Windows\system32\D3D10Warp (0x6f6000 bytes).
2026-05-28 20:39:55,102 [root] DEBUG: 9668: DLL loaded at 0x00007FFEED200000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 20:39:55,109 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE6D80000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-28 20:39:55,112 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEC340000: C:\Windows\System32\dcomp (0x1e3000 bytes).
2026-05-28 20:39:55,114 [root] DEBUG: 9668: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:39:55,127 [root] DEBUG: 9668: DLL loaded at 0x00007FFED4310000: C:\Windows\system32\UIAutomationCore (0x2f5000 bytes).
2026-05-28 20:39:55,134 [root] DEBUG: 9668: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49E2A1000, size: 0x1000.
2026-05-28 20:39:55,137 [root] DEBUG: 9668: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49E291000, size: 0x1000.
2026-05-28 20:39:55,138 [root] DEBUG: 9668: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49E281000, size: 0x1000.
2026-05-28 20:39:55,139 [root] DEBUG: 9668: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49E271000, size: 0x1000.
2026-05-28 20:39:55,154 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:39:55,155 [root] DEBUG: 9668: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:39:55,158 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEF640000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:39:55,160 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:39:55,167 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE9310000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-05-28 20:39:55,171 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE3D00000: C:\Windows\SYSTEM32\mrmcorer (0xf4000 bytes).
2026-05-28 20:39:55,172 [root] DEBUG: 9668: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:39:55,174 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 20:39:55,181 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:55,184 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEA040000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 20:39:55,186 [root] DEBUG: Loader: Injecting process 9712 (thread 9716) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,186 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:55,186 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,188 [lib.api.process] INFO: Injected into 64-bit <Process 9712 WinStore.App.exe>
2026-05-28 20:39:55,188 [root] INFO: Announced 64-bit process name: WinStore.App.exe pid: 9712
2026-05-28 20:39:55,189 [lib.api.process] INFO: Monitor config for process 9712: C:\_3mo6uuq\dll\9712.ini
2026-05-28 20:39:55,189 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:55,191 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:39:55,192 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE96E0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:39:55,192 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:39:55,193 [root] DEBUG: 9668: DLL loaded at 0x00007FFEEC530000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:39:55,193 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\System32\TextInputFramework (0xf9000 bytes).
2026-05-28 20:39:55,193 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE3950000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 20:39:55,194 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:39:55,196 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE0BF0000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 20:39:55,205 [root] DEBUG: 9668: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49E261000, size: 0x1000.
2026-05-28 20:39:55,276 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:55,281 [root] DEBUG: Loader: Injecting process 9712 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,282 [root] DEBUG: GetProcessInitialThreadId: ReadProcessMemory failed (0x0000007E72BFE048).
2026-05-28 20:39:55,282 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed (SessionId=1).
2026-05-28 20:39:55,282 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,294 [root] DEBUG: 9668: FreeHandler: Address: 0x00007DF49E280000.
2026-05-28 20:39:55,295 [root] DEBUG: 9668: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:39:55,295 [root] DEBUG: 9668: FreeHandler: Address: 0x00007DF49E260000.
2026-05-28 20:39:55,296 [root] DEBUG: 9668: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:39:55,297 [root] DEBUG: 9668: FreeHandler: Address: 0x00007DF49E270000.
2026-05-28 20:39:55,297 [root] DEBUG: 9668: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:39:55,298 [root] DEBUG: 9668: FreeHandler: Address: 0x00007DF49E290000.
2026-05-28 20:39:55,298 [root] DEBUG: 9668: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:39:55,300 [root] DEBUG: 9668: FreeHandler: Address: 0x00007DF49E2A0000.
2026-05-28 20:39:55,300 [root] DEBUG: 9668: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:39:55,801 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 8972: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62D550000
2026-05-28 20:39:55,802 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8972
2026-05-28 20:39:55,803 [lib.api.process] INFO: Monitor config for process 8972: C:\_3mo6uuq\dll\8972.ini
2026-05-28 20:39:55,803 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:55,804 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:55,808 [root] DEBUG: Loader: Injecting process 8972 (thread 8676) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,809 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:39:55,809 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,811 [lib.api.process] INFO: Injected into 64-bit <Process 8972 backgroundTaskHost.exe>
2026-05-28 20:39:55,812 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8972
2026-05-28 20:39:55,813 [lib.api.process] INFO: Monitor config for process 8972: C:\_3mo6uuq\dll\8972.ini
2026-05-28 20:39:55,813 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:55,815 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:55,819 [root] DEBUG: Loader: Injecting process 8972 (thread 8676) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,819 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:39:55,820 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,821 [lib.api.process] INFO: Injected into 64-bit <Process 8972 backgroundTaskHost.exe>
2026-05-28 20:39:55,822 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8972
2026-05-28 20:39:55,822 [lib.api.process] INFO: Monitor config for process 8972: C:\_3mo6uuq\dll\8972.ini
2026-05-28 20:39:55,823 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:39:55,824 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:39:55,830 [root] DEBUG: Loader: Injecting process 8972 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,831 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8676, handle 0x120
2026-05-28 20:39:55,831 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:39:55,832 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:39:55,833 [lib.api.process] INFO: Injected into 64-bit <Process 8972 backgroundTaskHost.exe>
2026-05-28 20:40:02,122 [root] DEBUG: 7496: DLL loaded at 0x00007FFED9910000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 20:40:02,216 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 9776: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:40:02,217 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 9776
2026-05-28 20:40:02,218 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 9776
2026-05-28 20:40:14,066 [root] DEBUG: 4372: DLL loaded at 0x00007FFED98F0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:40:14,076 [root] DEBUG: 9668: DLL loaded at 0x00007FFEE6F40000: C:\Windows\system32\D3D10Warp (0x6f6000 bytes).
2026-05-28 20:40:14,077 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9596: C:\Windows\ImmersiveControlPanel\SystemSettings.exe, ImageBase: 0x00007FF7F77A0000
2026-05-28 20:40:14,078 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 9596
2026-05-28 20:40:14,078 [lib.api.process] INFO: Monitor config for process 9596: C:\_3mo6uuq\dll\9596.ini
2026-05-28 20:40:14,079 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:14,087 [root] DEBUG: 9668: AllocationHandler: Allocation already in tracked region list: 0x00007DF49E2A0000.
2026-05-28 20:40:14,089 [root] DEBUG: 9668: AllocationHandler: Allocation already in tracked region list: 0x00007DF49E290000.
2026-05-28 20:40:14,089 [root] DEBUG: 9668: AllocationHandler: Allocation already in tracked region list: 0x00007DF49E280000.
2026-05-28 20:40:14,091 [root] DEBUG: 9668: AllocationHandler: Allocation already in tracked region list: 0x00007DF49E270000.
2026-05-28 20:40:14,118 [root] DEBUG: 9668: api-rate-cap: NtSetInformationThread hook disabled due to rate
2026-05-28 20:40:14,119 [root] DEBUG: 9668: api-rate-cap: NtSetInformationThread hook disabled due to rate
2026-05-28 20:40:14,119 [root] DEBUG: 9668: api-rate-cap: NtSetInformationThread hook disabled due to rate
2026-05-28 20:40:14,164 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:14,168 [root] DEBUG: Loader: Injecting process 9596 (thread 8900) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,169 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:14,169 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,170 [lib.api.process] INFO: Injected into 64-bit <Process 9596 SystemSettings.exe>
2026-05-28 20:40:14,173 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 9596
2026-05-28 20:40:14,173 [lib.api.process] INFO: Monitor config for process 9596: C:\_3mo6uuq\dll\9596.ini
2026-05-28 20:40:14,173 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:14,252 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:14,257 [root] DEBUG: Loader: Injecting process 9596 (thread 8900) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,257 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:14,258 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,259 [lib.api.process] INFO: Injected into 64-bit <Process 9596 SystemSettings.exe>
2026-05-28 20:40:14,260 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 9596
2026-05-28 20:40:14,260 [lib.api.process] INFO: Monitor config for process 9596: C:\_3mo6uuq\dll\9596.ini
2026-05-28 20:40:14,260 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:14,335 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:14,339 [root] DEBUG: Loader: Injecting process 9596 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,340 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8900, handle 0x120
2026-05-28 20:40:14,340 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:14,341 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,342 [lib.api.process] INFO: Injected into 64-bit <Process 9596 SystemSettings.exe>
2026-05-28 20:40:14,349 [root] DEBUG: 9596: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:14,350 [root] DEBUG: 9596: Interactive desktop enabled.
2026-05-28 20:40:14,350 [root] DEBUG: 9596: Dropped file limit defaulting to 100.
2026-05-28 20:40:14,351 [root] DEBUG: 9596: Disabling sleep skipping.
2026-05-28 20:40:14,352 [root] DEBUG: 9596: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:14,363 [root] DEBUG: 9596: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:14,364 [root] DEBUG: 9596: YaraScan: Scanning 0x00007FF7F77A0000, size 0x1903c
2026-05-28 20:40:14,364 [root] DEBUG: 9596: Monitor initialised: 64-bit capemon loaded in process 9596 at 0x00007FFEAF1A0000, thread 8900, image base 0x00007FF7F77A0000, stack from 0x000000658A6E4000-0x000000658A6F0000
2026-05-28 20:40:14,365 [root] DEBUG: 9596: Commandline: "C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
2026-05-28 20:40:14,373 [root] DEBUG: 9596: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:14,394 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:14,394 [root] DEBUG: 9596: set_hooks: Unable to hook LockResource
2026-05-28 20:40:14,400 [root] DEBUG: 9596: Hooked 627 out of 628 functions
2026-05-28 20:40:14,401 [root] DEBUG: 9596: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:14,405 [root] DEBUG: 9596: RestoreHeaders: Restored original import table.
2026-05-28 20:40:14,405 [root] INFO: Loaded monitor into process with pid 9596
2026-05-28 20:40:14,406 [root] DEBUG: 9596: caller_dispatch: Added region at 0x00007FF7F77A0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7F77A43D1, thread 8900).
2026-05-28 20:40:14,406 [root] DEBUG: 9596: YaraScan: Scanning 0x00007FF7F77A0000, size 0x1903c
2026-05-28 20:40:14,407 [root] DEBUG: 9596: ProcessImageBase: Main module image at 0x00007FF7F77A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:14,410 [root] DEBUG: 9596: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:14,410 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:14,413 [root] DEBUG: 9596: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:14,416 [root] DEBUG: 9596: DLL loaded at 0x00007FFEECCF0000: C:\Windows\SYSTEM32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:40:14,417 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:40:14,417 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE4250000: C:\Windows\SYSTEM32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:40:14,417 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 20:40:14,418 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEC340000: C:\Windows\SYSTEM32\dcomp (0x1e3000 bytes).
2026-05-28 20:40:14,419 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE2840000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 20:40:14,422 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 20:40:14,434 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:40:14,434 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:40:14,435 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEB280000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 20:40:14,436 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE3D00000: C:\Windows\SYSTEM32\MrmCoreR (0xf4000 bytes).
2026-05-28 20:40:14,436 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEB6B0000: C:\Windows\SYSTEM32\d2d1 (0x5c0000 bytes).
2026-05-28 20:40:14,437 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:40:14,437 [root] DEBUG: 9596: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:40:14,438 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE3E40000: C:\Windows\SYSTEM32\wincorlib (0x6f000 bytes).
2026-05-28 20:40:14,438 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:40:14,439 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEE250000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-05-28 20:40:14,439 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:40:14,440 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:40:14,440 [root] DEBUG: 9596: DLL loaded at 0x0000023ABA620000: C:\Windows\SYSTEM32\WinLangdb (0x34000 bytes).
2026-05-28 20:40:14,441 [root] DEBUG: 9596: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:40:14,442 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEC8B0000: C:\Windows\SYSTEM32\elscore (0x19000 bytes).
2026-05-28 20:40:14,442 [root] DEBUG: 9596: DLL loaded at 0x00007FFE965A0000: C:\Windows\ImmersiveControlPanel\SystemSettings (0x5fb000 bytes).
2026-05-28 20:40:14,444 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:40:14,458 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:40:14,462 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:40:14,463 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE94D0000: C:\Windows\SYSTEM32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:40:14,463 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE96E0000: C:\Windows\SYSTEM32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:40:14,463 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEC530000: C:\Windows\SYSTEM32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:40:14,464 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\SYSTEM32\TextInputFramework (0xf9000 bytes).
2026-05-28 20:40:14,464 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE3950000: C:\Windows\SYSTEM32\InputHost (0x152000 bytes).
2026-05-28 20:40:14,465 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:40:14,469 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE3900000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 20:40:14,473 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE41E0000: C:\Windows\SYSTEM32\bcp47mrm (0x2d000 bytes).
2026-05-28 20:40:14,475 [root] DEBUG: 9596: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:40:14,511 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:40:14,518 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE61A0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 20:40:14,519 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE5430000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 20:40:14,528 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 20:40:14,530 [root] DEBUG: 9596: DLL loaded at 0x00007FFEED200000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 20:40:14,534 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEBC70000: C:\Windows\SYSTEM32\d3d11 (0x263000 bytes).
2026-05-28 20:40:14,536 [root] DEBUG: 9596: DLL loaded at 0x00007FFED98F0000: C:\Windows\ImmersiveControlPanel\Telemetry.Common (0x12000 bytes).
2026-05-28 20:40:14,537 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE6F40000: C:\Windows\SYSTEM32\d3d10warp (0x6f6000 bytes).
2026-05-28 20:40:14,541 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:40:14,542 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE6D80000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-28 20:40:14,546 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE23A0000: C:\Windows\SYSTEM32\dwrite (0x27f000 bytes).
2026-05-28 20:40:14,550 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE0BF0000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-05-28 20:40:14,553 [root] DEBUG: 9596: AllocationHandler: Adding allocation to tracked region list: 0x00007DF479CB1000, size: 0x1000.
2026-05-28 20:40:14,556 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE1A70000: C:\Windows\System32\Windows.UI.Xaml.Controls (0x3dc000 bytes).
2026-05-28 20:40:14,565 [root] DEBUG: 9596: DLL loaded at 0x00007FFE97140000: C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop (0xbc000 bytes).
2026-05-28 20:40:14,573 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:40:14,578 [root] DEBUG: 9596: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\msctf (0x114000 bytes).
2026-05-28 20:40:14,581 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDEB00000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 20:40:14,586 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDE2F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 20:40:14,592 [root] DEBUG: 9596: DLL loaded at 0x00007FFEED4F0000: C:\Windows\SYSTEM32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:40:14,598 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDC530000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 20:40:14,616 [root] DEBUG: 9596: DLL loaded at 0x00007FFED61D0000: C:\Windows\SYSTEM32\windows.ui.core.textinput (0x104000 bytes).
2026-05-28 20:40:14,626 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF640000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:40:14,627 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE2620000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 20:40:14,634 [root] DEBUG: 9596: DLL loaded at 0x00007FFED88A0000: C:\Windows\system32\DataExchange (0x3e000 bytes).
2026-05-28 20:40:14,671 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE6360000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:40:14,676 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE9FE0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 20:40:14,679 [root] DEBUG: 9596: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:40:14,689 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:40:14,690 [root] DEBUG: 9596: DLL loaded at 0x00007FFED0720000: C:\Windows\SYSTEM32\REGAPI (0x3b000 bytes).
2026-05-28 20:40:14,690 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:40:14,691 [root] DEBUG: 9596: DLL loaded at 0x00007FFED0760000: C:\Windows\SYSTEM32\SettingsEnvironment.Desktop (0x94000 bytes).
2026-05-28 20:40:14,692 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:40:14,712 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:40:14,714 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:40:14,716 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE1520000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 20:40:14,721 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:40:14,722 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 20:40:14,723 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE14E0000: C:\Windows\System32\EthernetMediaManager (0x34000 bytes).
2026-05-28 20:40:14,724 [root] DEBUG: 9596: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:40:14,726 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:40:14,730 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:40:14,745 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:40:14,782 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE6180000: C:\Windows\SYSTEM32\samcli (0x19000 bytes).
2026-05-28 20:40:14,783 [root] DEBUG: 9596: DLL loaded at 0x00007FFED96E0000: C:\Windows\system32\credprovhost (0x69000 bytes).
2026-05-28 20:40:14,829 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE21F0000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2026-05-28 20:40:14,843 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE20B0000: C:\Windows\System32\Windows.UI.Xaml.Phone (0x13c000 bytes).
2026-05-28 20:40:14,876 [root] DEBUG: 9596: DLL loaded at 0x00007FFEED220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 20:40:14,877 [root] DEBUG: 9596: DLL loaded at 0x00007FFED7960000: C:\Windows\SYSTEM32\pdh (0x49000 bytes).
2026-05-28 20:40:14,878 [root] DEBUG: 9596: DLL loaded at 0x00007FFED79B0000: C:\Windows\system32\twinui (0x5f4000 bytes).
2026-05-28 20:40:14,898 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:40:14,901 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:40:14,906 [root] DEBUG: 9596: DLL loaded at 0x00007FFED98A0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:40:14,911 [root] DEBUG: 9596: DLL loaded at 0x00007FFED95F0000: C:\Windows\System32\CloudExperienceHostBroker (0x57000 bytes).
2026-05-28 20:40:14,914 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDCBB0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 20:40:14,938 [root] INFO: Added new file to list with pid 9596 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\36V4GAXVF4P4EYJ30M8G.temp
2026-05-28 20:40:14,942 [root] INFO: Added new file to list with pid 9596 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f18460fded109990.customDestinations-ms
2026-05-28 20:40:14,951 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f18460fded109990.customDestinations-ms~RF1c9b3.TMP to files\90bf6baa6f968a285f88620fbf91e1f5aa3e66e2bad50fd16f37913280ad8228; Size is 24; Max size: 100000000
2026-05-28 20:40:14,956 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:40:14,956 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\dsreg (0x141000 bytes).
2026-05-28 20:40:14,957 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDE340000: C:\Windows\SYSTEM32\cdp (0x4d4000 bytes).
2026-05-28 20:40:14,957 [root] DEBUG: 9596: DLL loaded at 0x00007FFED6EF0000: C:\Windows\System32\TaskFlowDataEngine (0x17e000 bytes).
2026-05-28 20:40:14,964 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:14,964 [root] DEBUG: 9596: OpenProcessHandler: Injection info created for process 4372, handle 0xa84: Error obtaining target process name
2026-05-28 20:40:14,968 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4372
2026-05-28 20:40:14,969 [lib.api.process] INFO: Monitor config for process 4372: C:\_3mo6uuq\dll\4372.ini
2026-05-28 20:40:14,969 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:14,970 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:14,971 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:40:14,971 [root] DEBUG: 9596: DLL loaded at 0x00007FFED95D0000: C:\Windows\SYSTEM32\credui (0x19000 bytes).
2026-05-28 20:40:14,971 [root] DEBUG: 9596: DLL loaded at 0x00007FFE96F90000: C:\Windows\SYSTEM32\DUI70 (0x1ae000 bytes).
2026-05-28 20:40:14,972 [root] DEBUG: 9596: DLL loaded at 0x00007FFED5DA0000: C:\Windows\System32\oobe\UserOOBE (0x6d000 bytes).
2026-05-28 20:40:14,974 [root] DEBUG: Loader: Injecting process 4372 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:14,974 [root] DEBUG: 4372: caller_dispatch: Added region at 0x0000000008800000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000008800042, thread 10684).
2026-05-28 20:40:14,975 [root] DEBUG: 4372: DumpPEsInRange: Scanning range 0x0000000008800000 - 0x0000000008800133.
2026-05-28 20:40:14,975 [root] DEBUG: 4372: ScanForDisguisedPE: Size too small: 0x133 bytes
2026-05-28 20:40:14,976 [root] DEBUG: 9596: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\wdscore (0x43000 bytes).
2026-05-28 20:40:14,977 [lib.common.results] INFO: Uploading file C:\QJqaJqCEA\CAPE\4372_395241440029552026 to CAPE\528fb972646bc4cf2ca9c22cd99d9235a577b8d1b9467c8870ed1cd2b8d3bfd8; Size is 307; Max size: 100000000
2026-05-28 20:40:14,978 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDE100000: C:\Windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:40:14,979 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDE0C0000: C:\Windows\SYSTEM32\dbgcore (0x34000 bytes).
2026-05-28 20:40:14,981 [root] DEBUG: 4372: DumpMemory: Payload successfully created: C:\QJqaJqCEA\CAPE\4372_395241440029552026 (size 307 bytes)
2026-05-28 20:40:14,982 [root] DEBUG: 4372: DumpRegion: Dumped entire allocation from 0x0000000008800000, size 4096 bytes.
2026-05-28 20:40:14,983 [root] DEBUG: 4372: ProcessTrackedRegion: Dumped region at 0x0000000008800000.
2026-05-28 20:40:14,983 [root] DEBUG: 4372: YaraScan: Scanning 0x0000000008800000, size 0x133
2026-05-28 20:40:14,984 [root] DEBUG: 4372: Monitor config - unrecognised key host-ip.
2026-05-28 20:40:14,985 [root] DEBUG: 4372: Monitor config - unrecognised key host-port.
2026-05-28 20:40:14,985 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:14,985 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 20:40:14,995 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:40:15,000 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 10752: C:\Windows\System32\oobe\UserOOBEBroker.exe, ImageBase: 0x00007FF725E30000
2026-05-28 20:40:15,001 [root] INFO: Announced 64-bit process name: UserOOBEBroker.exe pid: 10752
2026-05-28 20:40:15,001 [lib.api.process] INFO: Monitor config for process 10752: C:\_3mo6uuq\dll\10752.ini
2026-05-28 20:40:15,002 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,005 [root] DEBUG: 4372: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:15,044 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:15,045 [root] DEBUG: 4372: set_hooks: Unable to hook LockResource
2026-05-28 20:40:15,052 [root] DEBUG: 9596: DLL loaded at 0x00007FFED47D0000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 20:40:15,055 [root] DEBUG: 9596: DLL loaded at 0x00007FFED95A0000: C:\Windows\System32\Windows.Internal.Taskbar (0x30000 bytes).
2026-05-28 20:40:15,056 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 10812: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF6D0370000
2026-05-28 20:40:15,057 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 10812
2026-05-28 20:40:15,057 [lib.api.process] INFO: Monitor config for process 10812: C:\_3mo6uuq\dll\10812.ini
2026-05-28 20:40:15,058 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE02C0000: C:\Windows\System32\threadpoolwinrt (0x14000 bytes).
2026-05-28 20:40:15,058 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,060 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,064 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:40:15,065 [root] DEBUG: Loader: Injecting process 10812 (thread 10816) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,065 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,066 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,066 [root] DEBUG: 4372: Hooked 627 out of 628 functions
2026-05-28 20:40:15,067 [lib.api.process] INFO: Injected into 64-bit <Process 10812 MoUsoCoreWorker.exe>
2026-05-28 20:40:15,068 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 10812
2026-05-28 20:40:15,069 [lib.api.process] INFO: Monitor config for process 10812: C:\_3mo6uuq\dll\10812.ini
2026-05-28 20:40:15,069 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,069 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\System32\twinapi (0xa9000 bytes).
2026-05-28 20:40:15,071 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,075 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 9596, handle 0xf50: C:\Windows\ImmersiveControlPanel\SystemSettings.exe
2026-05-28 20:40:15,076 [root] DEBUG: Loader: Injecting process 10812 (thread 10816) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,076 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,077 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,078 [lib.api.process] INFO: Injected into 64-bit <Process 10812 MoUsoCoreWorker.exe>
2026-05-28 20:40:15,084 [root] DEBUG: 10812: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:15,085 [root] DEBUG: 10812: Interactive desktop enabled.
2026-05-28 20:40:15,086 [root] DEBUG: 10812: Dropped file limit defaulting to 100.
2026-05-28 20:40:15,089 [root] DEBUG: 10812: VerifyCodeSection: Exception rebasing image from 0x00007FF6D0370000 to 0x0000000140000000.
2026-05-28 20:40:15,091 [root] DEBUG: 10812: Disabling sleep skipping.
2026-05-28 20:40:15,092 [root] DEBUG: 10812: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:15,095 [root] INFO: Loaded monitor into process with pid 4372
2026-05-28 20:40:15,097 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 20:40:15,098 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,100 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,101 [root] DEBUG: 9596: DLL loaded at 0x00007FFED0260000: C:\Windows\System32\Windows.Management.InprocObjects (0x4f000 bytes).
2026-05-28 20:40:15,104 [root] DEBUG: 10812: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:15,104 [root] DEBUG: 10812: YaraScan: Scanning 0x00007FF6D0370000, size 0x1ad000
2026-05-28 20:40:15,105 [root] DEBUG: Loader: Injecting process 10752 (thread 10756) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,105 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,107 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,108 [lib.api.process] INFO: Injected into 64-bit <Process 10752 UserOOBEBroker.exe>
2026-05-28 20:40:15,110 [root] INFO: Announced 64-bit process name: UserOOBEBroker.exe pid: 10752
2026-05-28 20:40:15,110 [lib.api.process] INFO: Monitor config for process 10752: C:\_3mo6uuq\dll\10752.ini
2026-05-28 20:40:15,110 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,114 [root] DEBUG: 10812: Monitor initialised: 64-bit capemon loaded in process 10812 at 0x00007FFEAF1A0000, thread 10816, image base 0x00007FF6D0370000, stack from 0x000000B936674000-0x000000B936680000
2026-05-28 20:40:15,115 [root] DEBUG: 10812: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 20:40:15,125 [root] DEBUG: 10812: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:15,143 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE1330000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 20:40:15,146 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:15,146 [root] DEBUG: 10812: set_hooks: Unable to hook LockResource
2026-05-28 20:40:15,151 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDA210000: C:\Windows\System32\CapabilityAccessManagerClient (0x3f000 bytes).
2026-05-28 20:40:15,152 [root] DEBUG: 10812: Hooked 627 out of 628 functions
2026-05-28 20:40:15,158 [root] DEBUG: 9596: DLL loaded at 0x00007FFED0560000: C:\Windows\SYSTEM32\MFPlat (0x1bb000 bytes).
2026-05-28 20:40:15,162 [root] DEBUG: 10812: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:15,163 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDFD90000: C:\Windows\SYSTEM32\RTWorkQ (0x34000 bytes).
2026-05-28 20:40:15,166 [root] DEBUG: 10812: RestoreHeaders: Restored original import table.
2026-05-28 20:40:15,167 [root] INFO: Loaded monitor into process with pid 10812
2026-05-28 20:40:15,173 [root] DEBUG: 10812: caller_dispatch: Added region at 0x00007FF6D0370000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6D048F712, thread 10816).
2026-05-28 20:40:15,174 [root] DEBUG: 10812: YaraScan: Scanning 0x00007FF6D0370000, size 0x1ad000
2026-05-28 20:40:15,180 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE9310000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-05-28 20:40:15,184 [root] DEBUG: 10812: ProcessImageBase: Main module image at 0x00007FF6D0370000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:15,187 [root] DEBUG: 10812: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:15,188 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:15,194 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\msftedit (0x34d000 bytes).
2026-05-28 20:40:15,203 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,207 [root] DEBUG: Loader: Injecting process 10752 (thread 10756) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,208 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,208 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,210 [lib.api.process] INFO: Injected into 64-bit <Process 10752 UserOOBEBroker.exe>
2026-05-28 20:40:15,216 [root] DEBUG: 10812: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:40:15,216 [root] DEBUG: 10752: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:15,217 [root] DEBUG: 10752: Interactive desktop enabled.
2026-05-28 20:40:15,217 [root] DEBUG: 10752: Dropped file limit defaulting to 100.
2026-05-28 20:40:15,220 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:40:15,221 [root] DEBUG: 10752: Disabling sleep skipping.
2026-05-28 20:40:15,222 [root] DEBUG: 10752: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:15,232 [root] DEBUG: 10812: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:15,233 [root] DEBUG: 10752: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:15,233 [root] DEBUG: 10752: YaraScan: Scanning 0x00007FF725E30000, size 0x192fe
2026-05-28 20:40:15,234 [root] DEBUG: 10752: Monitor initialised: 64-bit capemon loaded in process 10752 at 0x00007FFEAF1A0000, thread 10756, image base 0x00007FF725E30000, stack from 0x000000B1631E4000-0x000000B1631F0000
2026-05-28 20:40:15,235 [root] DEBUG: 10752: Commandline: C:\Windows\System32\oobe\UserOOBEBroker.exe -Embedding
2026-05-28 20:40:15,245 [root] DEBUG: 10752: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:15,247 [root] DEBUG: 10812: DLL loaded at 0x00007FFED0B00000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 20:40:15,259 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE78F0000: C:\Windows\System32\Windows.Graphics (0x8d000 bytes).
2026-05-28 20:40:15,266 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:15,267 [root] DEBUG: 10752: set_hooks: Unable to hook LockResource
2026-05-28 20:40:15,271 [root] DEBUG: 10752: Hooked 627 out of 628 functions
2026-05-28 20:40:15,273 [root] DEBUG: 10752: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:15,278 [root] DEBUG: 10752: RestoreHeaders: Restored original import table.
2026-05-28 20:40:15,278 [root] INFO: Loaded monitor into process with pid 10752
2026-05-28 20:40:15,279 [root] DEBUG: 10752: caller_dispatch: Added region at 0x00007FF725E30000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF725E3D371, thread 10756).
2026-05-28 20:40:15,279 [root] DEBUG: 10752: YaraScan: Scanning 0x00007FF725E30000, size 0x192fe
2026-05-28 20:40:15,281 [root] DEBUG: 10752: ProcessImageBase: Main module image at 0x00007FF725E30000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:15,283 [root] DEBUG: 10752: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:15,283 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:15,285 [root] DEBUG: 10752: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:15,302 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:40:15,309 [root] DEBUG: 10752: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:40:15,310 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:40:15,310 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:40:15,311 [root] DEBUG: 10752: DLL loaded at 0x00007FFEE6180000: C:\Windows\SYSTEM32\samcli (0x19000 bytes).
2026-05-28 20:40:15,311 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:40:15,312 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:40:15,312 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:40:15,313 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:40:15,313 [root] DEBUG: 10752: DLL loaded at 0x00007FFED95D0000: C:\Windows\SYSTEM32\credui (0x19000 bytes).
2026-05-28 20:40:15,314 [root] DEBUG: 10752: DLL loaded at 0x00007FFE96F90000: C:\Windows\SYSTEM32\DUI70 (0x1ae000 bytes).
2026-05-28 20:40:15,314 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:40:15,315 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEE250000: C:\Windows\SYSTEM32\SLC (0x29000 bytes).
2026-05-28 20:40:15,315 [root] DEBUG: 10752: DLL loaded at 0x00007FFED5DA0000: C:\Windows\System32\oobe\UserOOBE (0x6d000 bytes).
2026-05-28 20:40:15,317 [root] DEBUG: 10752: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\wdscore (0x43000 bytes).
2026-05-28 20:40:15,318 [root] DEBUG: 10752: DLL loaded at 0x00007FFEDE100000: C:\Windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:40:15,319 [root] DEBUG: 10752: DLL loaded at 0x00007FFEDE0C0000: C:\Windows\SYSTEM32\dbgcore (0x34000 bytes).
2026-05-28 20:40:15,327 [root] DEBUG: 10752: DLL loaded at 0x00007FFEE88C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 20:40:15,331 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDEC10000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 20:40:15,332 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE88C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 20:40:15,338 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 11376: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe, ImageBase: 0x0000000000C00000
2026-05-28 20:40:15,339 [root] INFO: Announced 32-bit process name: FileCoAuth.exe pid: 11376
2026-05-28 20:40:15,339 [lib.api.process] INFO: Monitor config for process 11376: C:\_3mo6uuq\dll\11376.ini
2026-05-28 20:40:15,341 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,363 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDE9E0000: C:\Windows\SYSTEM32\FLTLIB (0xb000 bytes).
2026-05-28 20:40:15,364 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEC8E0000: C:\Windows\SYSTEM32\virtdisk (0x13000 bytes).
2026-05-28 20:40:15,382 [root] DEBUG: 9596: OpenProcessHandler: Injection info created for process 4100, handle 0xdbc: C:\Windows\System32\sihost.exe
2026-05-28 20:40:15,391 [root] DEBUG: 9596: DLL loaded at 0x00007FFEEB240000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2026-05-28 20:40:15,393 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDDAE0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 20:40:15,404 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:40:15,405 [root] DEBUG: 9596: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:40:15,407 [root] DEBUG: 9596: CreateProcessHandler: Injection info set for new process 11436: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:40:15,407 [root] INFO: Announced 64-bit process name: msedge.exe pid: 11436
2026-05-28 20:40:15,407 [lib.api.process] INFO: Monitor config for process 11436: C:\_3mo6uuq\dll\11436.ini
2026-05-28 20:40:15,408 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,409 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,413 [root] DEBUG: Loader: Injecting process 11436 (thread 11440) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,414 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,415 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,416 [lib.api.process] INFO: Injected into 64-bit <Process 11436 msedge.exe>
2026-05-28 20:40:15,418 [root] INFO: Announced 64-bit process name: msedge.exe pid: 11436
2026-05-28 20:40:15,422 [lib.api.process] INFO: Monitor config for process 11436: C:\_3mo6uuq\dll\11436.ini
2026-05-28 20:40:15,423 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,424 [root] DEBUG: 9596: AllocationHandler: Adding allocation to tracked region list: 0x00007DF479C91000, size: 0x1000.
2026-05-28 20:40:15,425 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,425 [root] DEBUG: 9596: AllocationHandler: Adding allocation to tracked region list: 0x00007DF479C81000, size: 0x1000.
2026-05-28 20:40:15,429 [root] DEBUG: Loader: Injecting process 11436 (thread 11440) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,430 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,430 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,431 [lib.api.process] INFO: Injected into 64-bit <Process 11436 msedge.exe>
2026-05-28 20:40:15,436 [root] DEBUG: 9596: DLL loaded at 0x00007FFEE8A00000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:40:15,437 [root] DEBUG: 9596: DLL loaded at 0x00007FFED0AA0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 20:40:15,439 [root] DEBUG: 9596: DLL loaded at 0x00007FFEDD4B0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 20:40:15,442 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-28 20:40:15,444 [root] DEBUG: 9596: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 20:40:15,447 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 20:40:15,448 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEF430000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 20:40:15,448 [root] DEBUG: 10812: DLL loaded at 0x00007FFED48E0000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 20:40:15,455 [root] DEBUG: 10812: DLL loaded at 0x00007FFEDDB70000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 20:40:15,456 [lib.api.process] INFO: 32-bit DLL to inject is C:\_3mo6uuq\dll\GOWHeq.dll, loader C:\_3mo6uuq\bin\HBkFsgf.exe
2026-05-28 20:40:15,457 [root] DEBUG: 10812: DLL loaded at 0x00007FFED0890000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 20:40:15,459 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:40:15,461 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEF440000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 20:40:15,465 [root] DEBUG: Loader: Injecting process 11376 (thread 11380) with C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:15,466 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:15,466 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:15,467 [lib.api.process] INFO: Injected into 32-bit <Process 11376 FileCoAuth.exe>
2026-05-28 20:40:15,468 [root] INFO: Announced 64-bit process name: msedge.exe pid: 11436
2026-05-28 20:40:15,468 [lib.api.process] INFO: Monitor config for process 11436: C:\_3mo6uuq\dll\11436.ini
2026-05-28 20:40:15,469 [root] INFO: Announced 32-bit process name: FileCoAuth.exe pid: 11376
2026-05-28 20:40:15,469 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,469 [lib.api.process] INFO: Monitor config for process 11376: C:\_3mo6uuq\dll\11376.ini
2026-05-28 20:40:15,469 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:15,470 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:15,474 [root] DEBUG: Loader: Injecting process 11436 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,474 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11440, handle 0x124
2026-05-28 20:40:15,475 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:15,475 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:15,476 [lib.api.process] INFO: Injected into 64-bit <Process 11436 msedge.exe>
2026-05-28 20:40:15,485 [root] DEBUG: 11436: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:15,485 [root] DEBUG: 11436: Interactive desktop enabled.
2026-05-28 20:40:15,486 [root] DEBUG: 11436: Dropped file limit defaulting to 100.
2026-05-28 20:40:15,489 [root] DEBUG: 11436: Edge-specific hook-set enabled.
2026-05-28 20:40:15,490 [root] DEBUG: 11436: Disabling sleep skipping.
2026-05-28 20:40:15,491 [root] DEBUG: 11436: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:15,502 [root] DEBUG: 11436: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:15,503 [root] DEBUG: 11436: Monitor initialised: 64-bit capemon loaded in process 11436 at 0x00007FFEAF1A0000, thread 11440, image base 0x00007FF60A060000, stack from 0x000000150DDF4000-0x000000150DE00000
2026-05-28 20:40:15,503 [root] DEBUG: 11436: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --default-search-provider=? --out-pipe-name=MSEdgeDefaultad05973dhc90ch40d6h8620h9830e2126520
2026-05-28 20:40:15,513 [root] DEBUG: 11436: Hooked 2 out of 2 functions
2026-05-28 20:40:15,540 [root] DEBUG: 11436: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:15,545 [root] DEBUG: 11436: RestoreHeaders: Restored original import table.
2026-05-28 20:40:15,546 [root] INFO: Loaded monitor into process with pid 11436
2026-05-28 20:40:15,548 [root] DEBUG: 11436: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:40:15,549 [root] DEBUG: 11436: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:40:15,550 [root] DEBUG: 11436: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:40:15,551 [root] DEBUG: 11436: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:40:15,562 [root] DEBUG: 10812: DLL loaded at 0x00007FFED0890000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 20:40:15,569 [root] DEBUG: 11436: DLL loaded at 0x00007FFED8180000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 20:40:15,570 [root] DEBUG: 11436: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:40:15,570 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-28 20:40:15,572 [root] DEBUG: 11436: DLL loaded at 0x00007FFEDD470000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 20:40:15,574 [root] DEBUG: 11436: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:40:15,574 [lib.api.process] INFO: 32-bit DLL to inject is C:\_3mo6uuq\dll\GOWHeq.dll, loader C:\_3mo6uuq\bin\HBkFsgf.exe
2026-05-28 20:40:15,579 [root] DEBUG: 11436: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:15,580 [root] DEBUG: Loader: Injecting process 11376 (thread 11380) with C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:15,581 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:15,581 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:15,583 [lib.api.process] INFO: Injected into 32-bit <Process 11376 FileCoAuth.exe>
2026-05-28 20:40:15,596 [root] DEBUG: 11376: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:15,597 [root] DEBUG: 11376: Interactive desktop enabled.
2026-05-28 20:40:15,598 [root] DEBUG: 11376: Dropped file limit defaulting to 100.
2026-05-28 20:40:15,599 [root] DEBUG: 11376: Disabling sleep skipping.
2026-05-28 20:40:15,601 [root] DEBUG: 11376: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:15,601 [root] DEBUG: 11376: YaraScan: Scanning 0x00C00000, size 0xa2732
2026-05-28 20:40:15,611 [root] DEBUG: 11376: Monitor initialised: 32-bit capemon loaded in process 11376 at 0x6c5b0000, thread 11380, image base 0xc00000, stack from 0x734000-0x740000
2026-05-28 20:40:15,611 [root] DEBUG: 11376: Commandline: "C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe" -Embedding
2026-05-28 20:40:15,612 [root] DEBUG: 11376: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\UpdateRingSettings.dll
2026-05-28 20:40:15,612 [root] DEBUG: 11376: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\LoggingPlatform.DLL
2026-05-28 20:40:15,613 [root] DEBUG: 11376: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\MSVCP140.dll
2026-05-28 20:40:15,613 [root] DEBUG: 11376: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\VCRUNTIME140.dll
2026-05-28 20:40:15,638 [root] DEBUG: 11376: hook_api: LdrpCallInitRoutine export address 0x776C2B50 obtained via GetFunctionAddress
2026-05-28 20:40:15,653 [root] DEBUG: 11376: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-28 20:40:15,654 [root] DEBUG: 11376: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-28 20:40:15,654 [root] DEBUG: 10812: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 20:40:15,658 [root] DEBUG: 11376: Hooked 632 out of 632 functions
2026-05-28 20:40:15,662 [root] DEBUG: 11376: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:15,666 [root] DEBUG: 11376: RestoreHeaders: Restored original import table.
2026-05-28 20:40:15,667 [root] INFO: Loaded monitor into process with pid 11376
2026-05-28 20:40:15,667 [root] DEBUG: 11376: YaraScan: Scanning 0x740B0000, size 0x13ac6
2026-05-28 20:40:15,668 [root] DEBUG: 11376: caller_dispatch: Added region at 0x740B0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x740B7916, thread 11380).
2026-05-28 20:40:15,669 [root] DEBUG: 11376: caller_dispatch: Scanning calling region at 0x740B0000...
2026-05-28 20:40:15,670 [root] DEBUG: 11376: ProcessTrackedRegion: Region at 0x740B0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\vcruntime140.dll appears unmodified, skipping
2026-05-28 20:40:15,671 [root] DEBUG: 11376: YaraScan: Scanning 0x740D0000, size 0x6c6de
2026-05-28 20:40:15,674 [root] DEBUG: 11376: caller_dispatch: Added region at 0x740D0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x740FE9DC, thread 11380).
2026-05-28 20:40:15,675 [root] DEBUG: 11376: caller_dispatch: Scanning calling region at 0x740D0000...
2026-05-28 20:40:15,676 [root] DEBUG: 11376: ProcessTrackedRegion: Region at 0x740D0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\msvcp140.dll appears unmodified, skipping
2026-05-28 20:40:15,677 [root] DEBUG: 11376: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:40:15,680 [root] DEBUG: 11376: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:40:15,684 [root] DEBUG: 11376: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:40:15,688 [root] DEBUG: 11376: caller_dispatch: Added region at 0x74140000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x7418AF34, thread 11380).
2026-05-28 20:40:15,688 [root] DEBUG: 11376: caller_dispatch: Scanning calling region at 0x74140000...
2026-05-28 20:40:15,691 [root] DEBUG: 11376: ProcessTrackedRegion: Region at 0x74140000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\LoggingPlatform.dll appears unmodified, skipping
2026-05-28 20:40:15,692 [root] DEBUG: 11376: DLL loaded at 0x76970000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-28 20:40:15,693 [root] DEBUG: 11376: YaraScan: Scanning 0x737B0000, size 0x6ce84
2026-05-28 20:40:15,697 [root] DEBUG: 11376: caller_dispatch: Added region at 0x737B0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x737F0864, thread 11380).
2026-05-28 20:40:15,698 [root] DEBUG: 11376: caller_dispatch: Scanning calling region at 0x737B0000...
2026-05-28 20:40:15,700 [root] DEBUG: 11376: ProcessTrackedRegion: Region at 0x737B0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\UpdateRingSettings.dll appears unmodified, skipping
2026-05-28 20:40:15,701 [root] DEBUG: 11376: caller_dispatch: Added region at 0x00C00000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00C52D18, thread 11380).
2026-05-28 20:40:15,701 [root] DEBUG: 11376: YaraScan: Scanning 0x00C00000, size 0xa2732
2026-05-28 20:40:15,706 [root] DEBUG: 11376: ProcessImageBase: Main module image at 0x00C00000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:15,886 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 12096, handle 0x1b24: C:\Windows\SysWOW64\WerFault.exe
2026-05-28 20:40:16,310 [root] INFO: Process with pid 11436 appears to have terminated
2026-05-28 20:40:16,612 [root] DEBUG: 10812: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 20:40:17,432 [root] INFO: Process with pid 11376 has terminated
2026-05-28 20:40:17,433 [root] DEBUG: 11376: NtTerminateProcess hook: Attempting to dump process 11376
2026-05-28 20:40:17,434 [root] DEBUG: 11376: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:40:18,323 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:40:18,324 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:40:18,329 [root] DEBUG: 10812: DLL loaded at 0x00007FFED47D0000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 20:40:18,331 [root] DEBUG: 10812: DLL loaded at 0x00007FFED8B50000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:40:18,333 [root] DEBUG: 10812: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:40:18,336 [root] DEBUG: 10812: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:40:18,341 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEB550000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:40:18,346 [root] DEBUG: 10812: DLL loaded at 0x00007FFEE5850000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 20:40:18,639 [root] INFO: Stopping Task Scheduler Service
2026-05-28 20:40:18,648 [root] INFO: Stopped Task Scheduler Service
2026-05-28 20:40:18,651 [root] INFO: Starting Task Scheduler Service
2026-05-28 20:40:18,659 [root] INFO: Started Task Scheduler Service
2026-05-28 20:40:18,660 [lib.api.process] INFO: Monitor config for process 1212: C:\_3mo6uuq\dll\1212.ini
2026-05-28 20:40:18,661 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:18,663 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:18,666 [root] DEBUG: Loader: Injecting process 1212 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:18,668 [root] DEBUG: 1212: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:18,669 [root] DEBUG: 1212: Disabling sleep skipping.
2026-05-28 20:40:18,669 [root] DEBUG: 1212: Interactive desktop enabled.
2026-05-28 20:40:18,670 [root] DEBUG: 1212: Dropped file limit defaulting to 100.
2026-05-28 20:40:18,671 [root] DEBUG: 1212: Services hook set enabled
2026-05-28 20:40:18,672 [root] DEBUG: 1212: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:18,684 [root] DEBUG: 1212: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:18,685 [root] DEBUG: 1212: Monitor initialised: 64-bit capemon loaded in process 1212 at 0x00007FFEAF1A0000, thread 11704, image base 0x00007FF6A8D80000, stack from 0x0000004FD9A74000-0x0000004FD9A80000
2026-05-28 20:40:18,686 [root] DEBUG: 1212: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 20:40:18,697 [root] DEBUG: 1212: Hooked 69 out of 69 functions
2026-05-28 20:40:18,698 [root] INFO: Loaded monitor into process with pid 1212
2026-05-28 20:40:18,699 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:40:18,700 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:18,701 [lib.api.process] INFO: Injected into 64-bit <Process 1212 svchost.exe>
2026-05-28 20:40:19,091 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,092 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6220, handle 0x247c: Error obtaining target process name
2026-05-28 20:40:19,093 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,094 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 8780, handle 0x2480: Error obtaining target process name
2026-05-28 20:40:19,097 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,098 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6028, handle 0x2484: Error obtaining target process name
2026-05-28 20:40:19,100 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,100 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6632, handle 0x2488: Error obtaining target process name
2026-05-28 20:40:19,101 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,101 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 9668, handle 0x2474: Error obtaining target process name
2026-05-28 20:40:19,102 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,102 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7496, handle 0x248c: Error obtaining target process name
2026-05-28 20:40:19,103 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:40:19,104 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7448, handle 0x2490: Error obtaining target process name
2026-05-28 20:40:20,716 [root] DEBUG: 10812: DLL loaded at 0x00007FFEEACF0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:40:20,760 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 20:40:20,761 [lib.api.process] INFO: Monitor config for process 708: C:\_3mo6uuq\dll\708.ini
2026-05-28 20:40:20,762 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:20,763 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:20,767 [root] DEBUG: Loader: Injecting process 708 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:20,768 [root] DEBUG: Loader: Copied config file C:\_3mo6uuq\dll\708.ini to system path C:\708.ini
2026-05-28 20:40:20,770 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 708 C:\_3mo6uuq\dll\lbpkzk.dll
2026-05-28 20:40:20,771 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:20,772 [lib.api.process] INFO: Injected into 64-bit <Process 708 services.exe>
2026-05-28 20:40:20,903 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 20:40:20,995 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 20:40:21,035 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 20:40:21,049 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2026-05-28 20:40:21,067 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 20:40:21,081 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12292: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:40:21,082 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12292
2026-05-28 20:40:21,082 [lib.api.process] INFO: Monitor config for process 12292: C:\_3mo6uuq\dll\12292.ini
2026-05-28 20:40:21,083 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:21,085 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:21,093 [root] DEBUG: Loader: Injecting process 12292 (thread 12296) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:21,094 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:21,094 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:21,097 [lib.api.process] INFO: Injected into 64-bit <Process 12292 dllhost.exe>
2026-05-28 20:40:21,099 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12292
2026-05-28 20:40:21,099 [lib.api.process] INFO: Monitor config for process 12292: C:\_3mo6uuq\dll\12292.ini
2026-05-28 20:40:21,099 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:21,102 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:21,110 [root] DEBUG: Loader: Injecting process 12292 (thread 12296) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:21,112 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:21,114 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:21,118 [lib.api.process] INFO: Injected into 64-bit <Process 12292 dllhost.exe>
2026-05-28 20:40:21,130 [root] DEBUG: 12292: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:21,133 [root] DEBUG: 12292: Interactive desktop enabled.
2026-05-28 20:40:21,133 [root] DEBUG: 12292: Dropped file limit defaulting to 100.
2026-05-28 20:40:21,138 [root] DEBUG: 12292: Disabling sleep skipping.
2026-05-28 20:40:21,139 [root] DEBUG: 12292: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:21,151 [root] DEBUG: 12292: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:21,151 [root] DEBUG: 12292: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:40:21,153 [root] DEBUG: 12292: Monitor initialised: 64-bit capemon loaded in process 12292 at 0x00007FFEAF1A0000, thread 12296, image base 0x00007FF6868D0000, stack from 0x000000FFFBCF4000-0x000000FFFBD00000
2026-05-28 20:40:21,154 [root] DEBUG: 12292: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:40:21,164 [root] DEBUG: 12292: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:21,172 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Discord\app.ico
2026-05-28 20:40:21,185 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:21,186 [root] DEBUG: 12292: set_hooks: Unable to hook LockResource
2026-05-28 20:40:21,190 [root] DEBUG: 12292: Hooked 627 out of 628 functions
2026-05-28 20:40:21,191 [root] DEBUG: 12292: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:21,196 [root] DEBUG: 12292: RestoreHeaders: Restored original import table.
2026-05-28 20:40:21,197 [root] INFO: Loaded monitor into process with pid 12292
2026-05-28 20:40:21,197 [root] DEBUG: 12292: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 12296).
2026-05-28 20:40:21,198 [root] DEBUG: 12292: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:40:21,200 [root] DEBUG: 12292: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:21,203 [root] DEBUG: 12292: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:21,204 [root] DEBUG: 12292: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:21,207 [root] DEBUG: 12292: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:21,212 [root] DEBUG: 4372: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 20:40:21,222 [root] DEBUG: 12292: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:40:21,245 [root] DEBUG: 12292: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:40:21,245 [root] DEBUG: 12292: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:40:21,251 [root] DEBUG: 12292: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:40:23,807 [root] DEBUG: 10812: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 20:40:23,932 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\8e6baafbf063ec02cacaf1b45665ca41ccd51fb9355a15da3f55152693c28ca5; Size is 8720; Max size: 100000000
2026-05-28 20:40:23,958 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\3d4734c9230df7e2351182382564ba51f59d6d6cada51706891b9944af1d7d3e; Size is 8720; Max size: 100000000
2026-05-28 20:40:23,984 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\0cd7e853bdff92c85c8799aee21a8993ade2c5d9f2201029695c1716c23347fa; Size is 8720; Max size: 100000000
2026-05-28 20:40:24,028 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\cf99c28914dc146d5d5d29ad88c5e32b46be45877c0a49954d85832fc85d8c89; Size is 8720; Max size: 100000000
2026-05-28 20:40:24,054 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\eb65fe5ec2d27ef6e7cecd6efa50124807dd20cf5e5caf06753b438565799a40; Size is 8720; Max size: 100000000
2026-05-28 20:40:24,103 [root] DEBUG: 10812: api-rate-cap: NtReadFile hook disabled due to rate
2026-05-28 20:40:24,132 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\5fc3567ebc840490dda703cce106d5385796d5da2a05979506f7624f6a1497a6; Size is 12824; Max size: 100000000
2026-05-28 20:40:24,934 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12936: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:40:24,935 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12936
2026-05-28 20:40:24,935 [lib.api.process] INFO: Monitor config for process 12936: C:\_3mo6uuq\dll\12936.ini
2026-05-28 20:40:24,936 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:24,938 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:24,942 [root] DEBUG: Loader: Injecting process 12936 (thread 12940) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:24,943 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:24,943 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:24,944 [lib.api.process] INFO: Injected into 64-bit <Process 12936 dllhost.exe>
2026-05-28 20:40:24,945 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12936
2026-05-28 20:40:24,946 [lib.api.process] INFO: Monitor config for process 12936: C:\_3mo6uuq\dll\12936.ini
2026-05-28 20:40:24,946 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:24,948 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:24,952 [root] DEBUG: Loader: Injecting process 12936 (thread 12940) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:24,953 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:24,954 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:24,955 [lib.api.process] INFO: Injected into 64-bit <Process 12936 dllhost.exe>
2026-05-28 20:40:24,961 [root] DEBUG: 12936: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:24,964 [root] DEBUG: 12936: Interactive desktop enabled.
2026-05-28 20:40:24,965 [root] DEBUG: 12936: Dropped file limit defaulting to 100.
2026-05-28 20:40:24,968 [root] DEBUG: 12936: Disabling sleep skipping.
2026-05-28 20:40:24,969 [root] DEBUG: 12936: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:24,971 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13208: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7D5630000
2026-05-28 20:40:24,972 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 13208
2026-05-28 20:40:24,972 [lib.api.process] INFO: Monitor config for process 13208: C:\_3mo6uuq\dll\13208.ini
2026-05-28 20:40:24,973 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:24,981 [root] DEBUG: 12936: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:24,982 [root] DEBUG: 12936: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:40:24,983 [root] DEBUG: 12936: Monitor initialised: 64-bit capemon loaded in process 12936 at 0x00007FFEAF1A0000, thread 12940, image base 0x00007FF6868D0000, stack from 0x000000FB5B144000-0x000000FB5B150000
2026-05-28 20:40:24,984 [root] DEBUG: 12936: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 20:40:24,995 [root] DEBUG: 12936: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:25,017 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:25,018 [root] DEBUG: 12936: set_hooks: Unable to hook LockResource
2026-05-28 20:40:25,023 [root] DEBUG: 12936: Hooked 627 out of 628 functions
2026-05-28 20:40:25,024 [root] DEBUG: 12936: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:25,028 [root] DEBUG: 12936: RestoreHeaders: Restored original import table.
2026-05-28 20:40:25,029 [root] INFO: Loaded monitor into process with pid 12936
2026-05-28 20:40:25,030 [root] DEBUG: 12936: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 12940).
2026-05-28 20:40:25,030 [root] DEBUG: 12936: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:40:25,032 [root] DEBUG: 12936: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:25,033 [root] DEBUG: 12936: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:25,035 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:25,037 [root] DEBUG: 12936: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:25,052 [root] DEBUG: 12936: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:40:25,068 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:40:25,069 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:40:25,069 [root] DEBUG: 12936: DLL loaded at 0x00007FFEE8D30000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:40:25,071 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:40:25,072 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:40:25,072 [root] DEBUG: 12936: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:40:25,074 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:40:25,075 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:40:25,075 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEF640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 20:40:25,076 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEB240000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:40:25,077 [root] DEBUG: 12936: DLL loaded at 0x00007FFEEEB10000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 20:40:25,078 [root] DEBUG: 12936: DLL loaded at 0x00007FFE95950000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 20:40:25,080 [root] DEBUG: 12936: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:40:25,086 [root] DEBUG: 12936: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:40:25,272 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:25,277 [root] DEBUG: Loader: Injecting process 13208 (thread 13212) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:25,278 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:25,278 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:25,280 [lib.api.process] INFO: Injected into 64-bit <Process 13208 WmiPrvSE.exe>
2026-05-28 20:40:25,281 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 13208
2026-05-28 20:40:25,281 [lib.api.process] INFO: Monitor config for process 13208: C:\_3mo6uuq\dll\13208.ini
2026-05-28 20:40:25,282 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:25,515 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:25,519 [root] DEBUG: Loader: Injecting process 13208 (thread 13212) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:25,520 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:25,521 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:25,522 [lib.api.process] INFO: Injected into 64-bit <Process 13208 WmiPrvSE.exe>
2026-05-28 20:40:25,528 [root] DEBUG: 13208: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:25,528 [root] DEBUG: 13208: Interactive desktop enabled.
2026-05-28 20:40:25,529 [root] DEBUG: 13208: Dropped file limit defaulting to 100.
2026-05-28 20:40:25,530 [root] DEBUG: 13208: Disabling sleep skipping.
2026-05-28 20:40:25,530 [root] DEBUG: 13208: Services hook set enabled
2026-05-28 20:40:25,532 [root] DEBUG: 13208: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:25,543 [root] DEBUG: 13208: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:25,544 [root] DEBUG: 13208: Monitor initialised: 64-bit capemon loaded in process 13208 at 0x00007FFEAF1A0000, thread 13212, image base 0x00007FF7D5630000, stack from 0x000000D04C270000-0x000000D04C280000
2026-05-28 20:40:25,545 [root] DEBUG: 13208: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 20:40:25,557 [root] DEBUG: 13208: Hooked 69 out of 69 functions
2026-05-28 20:40:25,561 [root] DEBUG: 13208: RestoreHeaders: Restored original import table.
2026-05-28 20:40:25,562 [root] INFO: Loaded monitor into process with pid 13208
2026-05-28 20:40:25,565 [root] DEBUG: 13208: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:25,565 [root] DEBUG: 13208: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:25,567 [root] DEBUG: 13208: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:25,568 [lib.api.process] INFO: Monitor config for process 1128: C:\_3mo6uuq\dll\1128.ini
2026-05-28 20:40:25,569 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:25,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:25,575 [root] DEBUG: Loader: Injecting process 1128 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:25,577 [root] DEBUG: 1128: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:25,578 [root] DEBUG: 1128: Disabling sleep skipping.
2026-05-28 20:40:25,578 [root] DEBUG: 1128: Interactive desktop enabled.
2026-05-28 20:40:25,579 [root] DEBUG: 1128: Dropped file limit defaulting to 100.
2026-05-28 20:40:25,579 [root] DEBUG: 1128: Services hook set enabled
2026-05-28 20:40:25,581 [root] DEBUG: 1128: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:25,592 [root] DEBUG: 1128: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:25,593 [root] DEBUG: 1128: Monitor initialised: 64-bit capemon loaded in process 1128 at 0x00007FFEAF1A0000, thread 13652, image base 0x00007FF6A8D80000, stack from 0x0000003C49275000-0x0000003C49280000
2026-05-28 20:40:25,593 [root] DEBUG: 1128: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 20:40:25,606 [root] DEBUG: 1128: Hooked 69 out of 69 functions
2026-05-28 20:40:25,608 [root] INFO: Loaded monitor into process with pid 1128
2026-05-28 20:40:25,608 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:40:25,609 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:25,610 [lib.api.process] INFO: Injected into 64-bit <Process 1128 svchost.exe>
2026-05-28 20:40:26,435 [root] INFO: Process with pid 12292 has terminated
2026-05-28 20:40:26,436 [root] DEBUG: 12292: NtTerminateProcess hook: Attempting to dump process 12292
2026-05-28 20:40:26,437 [root] DEBUG: 12292: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:40:27,622 [root] DEBUG: 13208: DLL loaded at 0x00007FFEDD9B0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:40:27,625 [root] DEBUG: 13208: DLL loaded at 0x00007FFED9650000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:40:27,633 [root] DEBUG: 13208: DLL loaded at 0x00007FFEB5DE0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:40:27,640 [root] DEBUG: 13208: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:40:27,641 [root] DEBUG: 13208: DLL loaded at 0x00007FFE94C20000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 20:40:27,641 [root] DEBUG: 13208: DLL loaded at 0x00007FFE94C80000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 20:40:27,642 [root] DEBUG: 13208: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:40:27,648 [root] DEBUG: 13208: DLL loaded at 0x0000027E6BED0000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 20:40:27,649 [root] DEBUG: 13208: DLL loaded at 0x00007FFEEA840000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 20:40:27,650 [root] DEBUG: 13208: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:40:30,093 [root] INFO: Process with pid 12936 has terminated
2026-05-28 20:40:30,094 [root] DEBUG: 12936: NtTerminateProcess hook: Attempting to dump process 12936
2026-05-28 20:40:30,094 [root] DEBUG: 12936: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:40:31,297 [root] DEBUG: 4372: DLL loaded at 0x00007FFE959A0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:40:31,299 [root] DEBUG: 4372: DLL loaded at 0x00007FFE959A0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:40:31,314 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:40:31,314 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:40:31,331 [root] DEBUG: 4372: DLL loaded at 0x000000000FFA0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 20:40:31,332 [root] DEBUG: 4372: DLL loaded at 0x000000000FFA0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 20:40:31,333 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95980000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:40:31,334 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95980000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:40:31,348 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94C20000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:40:31,349 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94C20000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:40:31,350 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:40:31,351 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:40:31,352 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94B40000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:40:31,353 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94B40000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:40:31,358 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95960000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:40:31,359 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95960000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:40:31,366 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94A50000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:40:31,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94A50000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:40:32,200 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:40:32,201 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE250000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 20:40:32,203 [root] DEBUG: 7496: DLL loaded at 0x00007FFE94A30000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 20:40:32,206 [root] DEBUG: 7496: DLL loaded at 0x00007FFE94A10000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 20:40:32,280 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 13352: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:40:32,281 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 13352
2026-05-28 20:40:32,282 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 13352
2026-05-28 20:40:32,380 [root] DEBUG: 7496: DLL loaded at 0x00007FFE948A0000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 20:40:33,162 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 13328: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:40:33,163 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 13328
2026-05-28 20:40:33,164 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 13328
2026-05-28 20:40:37,476 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 7496 (handle 0x26a0): 0x00007FF60A060000.
2026-05-28 20:40:39,639 [root] DEBUG: 4372: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 20:40:39,734 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95920000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:40:39,736 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95920000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:40:40,113 [lib.api.process] INFO: Monitor config for process 4372: C:\_3mo6uuq\dll\4372.ini
2026-05-28 20:40:40,114 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:40,117 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:40,122 [root] DEBUG: Loader: Injecting process 4372 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:40,125 [root] DEBUG: 4372: caller_dispatch: Added region at 0x0000000008D90000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0000000008D90042, thread 12360).
2026-05-28 20:40:40,125 [root] DEBUG: 4372: DumpPEsInRange: Scanning range 0x0000000008D90000 - 0x0000000008D90133.
2026-05-28 20:40:40,126 [root] DEBUG: 4372: ScanForDisguisedPE: Size too small: 0x133 bytes
2026-05-28 20:40:40,131 [lib.common.results] INFO: Uploading file C:\QJqaJqCEA\CAPE\4372_51254040029552026 to CAPE\0cdb282fd03853a36318ab35f90e0fe2212dbaa0b9f9d2832624a4fbd407aaf6; Size is 307; Max size: 100000000
2026-05-28 20:40:40,137 [root] DEBUG: 4372: DumpMemory: Payload successfully created: C:\QJqaJqCEA\CAPE\4372_51254040029552026 (size 307 bytes)
2026-05-28 20:40:40,137 [root] DEBUG: 4372: DumpRegion: Dumped entire allocation from 0x0000000008D90000, size 4096 bytes.
2026-05-28 20:40:40,138 [root] DEBUG: 4372: ProcessTrackedRegion: Dumped region at 0x0000000008D90000.
2026-05-28 20:40:40,139 [root] DEBUG: 4372: YaraScan: Scanning 0x0000000008D90000, size 0x133
2026-05-28 20:40:40,142 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:40:40,142 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:40,144 [lib.api.process] INFO: Injected into 64-bit <Process 4372 explorer.exe>
2026-05-28 20:40:42,176 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96F90000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 20:40:42,177 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96F90000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 20:40:42,182 [root] DEBUG: 4372: DLL loaded at 0x00007FFE958C0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 20:40:42,183 [root] DEBUG: 4372: DLL loaded at 0x00007FFE958C0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 20:40:42,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 20:40:42,549 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 20:40:42,678 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:40:42,679 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:40:42,693 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94780000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 20:40:42,694 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94780000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 20:40:42,733 [root] DEBUG: 4372: DLL loaded at 0x00007FFED98A0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:40:42,734 [root] DEBUG: 4372: DLL loaded at 0x00007FFED98A0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:40:42,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94390000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 20:40:42,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94390000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 20:40:43,126 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:40:43,127 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:40:43,132 [root] DEBUG: 4372: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:40:43,351 [root] DEBUG: 4372: DLL loaded at 0x00007FFE958A0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 20:40:43,353 [root] DEBUG: 4372: DLL loaded at 0x00007FFE958A0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 20:40:43,460 [root] DEBUG: 4372: api-cap: IsDebuggerPresent hook disabled due to count: 5000
2026-05-28 20:40:43,466 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8180000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 20:40:43,467 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8180000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 20:40:43,609 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 4944: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:40:43,611 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4944
2026-05-28 20:40:43,612 [lib.api.process] INFO: Monitor config for process 4944: C:\_3mo6uuq\dll\4944.ini
2026-05-28 20:40:43,614 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:43,618 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:43,627 [root] DEBUG: Loader: Injecting process 4944 (thread 5732) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:43,629 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:43,629 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:43,634 [root] DEBUG: 4372: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 20:40:43,634 [lib.api.process] INFO: Injected into 64-bit <Process 4944 dllhost.exe>
2026-05-28 20:40:43,636 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4944
2026-05-28 20:40:43,636 [lib.api.process] INFO: Monitor config for process 4944: C:\_3mo6uuq\dll\4944.ini
2026-05-28 20:40:43,637 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:43,639 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:43,646 [root] DEBUG: Loader: Injecting process 4944 (thread 5732) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:43,647 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:43,648 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:43,650 [lib.api.process] INFO: Injected into 64-bit <Process 4944 dllhost.exe>
2026-05-28 20:40:43,657 [root] DEBUG: 4944: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:43,659 [root] DEBUG: 4944: Interactive desktop enabled.
2026-05-28 20:40:43,660 [root] DEBUG: 4944: Dropped file limit defaulting to 100.
2026-05-28 20:40:43,663 [root] DEBUG: 4944: Disabling sleep skipping.
2026-05-28 20:40:43,665 [root] DEBUG: 4944: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:43,677 [root] DEBUG: 4944: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:43,678 [root] DEBUG: 4944: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:40:43,679 [root] DEBUG: 4944: Monitor initialised: 64-bit capemon loaded in process 4944 at 0x00007FFEAF1A0000, thread 5732, image base 0x00007FF6868D0000, stack from 0x0000006DD4104000-0x0000006DD4110000
2026-05-28 20:40:43,680 [root] DEBUG: 4944: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:40:43,691 [root] DEBUG: 4944: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:43,713 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:43,714 [root] DEBUG: 4944: set_hooks: Unable to hook LockResource
2026-05-28 20:40:43,719 [root] DEBUG: 4944: Hooked 627 out of 628 functions
2026-05-28 20:40:43,721 [root] DEBUG: 4944: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:43,727 [root] DEBUG: 4944: RestoreHeaders: Restored original import table.
2026-05-28 20:40:43,728 [root] INFO: Loaded monitor into process with pid 4944
2026-05-28 20:40:43,729 [root] DEBUG: 4944: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 5732).
2026-05-28 20:40:43,731 [root] DEBUG: 4944: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:40:43,733 [root] DEBUG: 4944: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:43,736 [root] DEBUG: 4944: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:40:43,738 [root] DEBUG: 4944: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:40:43,741 [root] DEBUG: 4944: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:40:43,756 [root] DEBUG: 4944: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:40:43,771 [root] DEBUG: 4944: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:40:43,772 [root] DEBUG: 4944: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:40:43,778 [root] DEBUG: 4944: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:40:44,804 [root] DEBUG: 4372: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 20:40:45,298 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 15560: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF6C5DC0000
2026-05-28 20:40:45,299 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 15560
2026-05-28 20:40:45,300 [lib.api.process] INFO: Monitor config for process 15560: C:\_3mo6uuq\dll\15560.ini
2026-05-28 20:40:45,301 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:45,304 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:45,309 [root] DEBUG: Loader: Injecting process 15560 (thread 15564) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:45,310 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:45,311 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:45,312 [lib.api.process] INFO: Injected into 64-bit <Process 15560 rundll32.exe>
2026-05-28 20:40:45,313 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 15560
2026-05-28 20:40:45,314 [lib.api.process] INFO: Monitor config for process 15560: C:\_3mo6uuq\dll\15560.ini
2026-05-28 20:40:45,314 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:45,317 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:40:45,321 [root] DEBUG: Loader: Injecting process 15560 (thread 15564) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:45,322 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:45,322 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:40:45,323 [lib.api.process] INFO: Injected into 64-bit <Process 15560 rundll32.exe>
2026-05-28 20:40:45,330 [root] DEBUG: 15560: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:45,330 [root] DEBUG: 15560: Interactive desktop enabled.
2026-05-28 20:40:45,331 [root] DEBUG: 15560: Dropped file limit defaulting to 100.
2026-05-28 20:40:45,333 [root] DEBUG: 15560: Disabling sleep skipping.
2026-05-28 20:40:45,334 [root] DEBUG: 15560: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:45,346 [root] DEBUG: 15560: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:40:45,346 [root] DEBUG: 15560: YaraScan: Scanning 0x00007FF6C5DC0000, size 0x16100
2026-05-28 20:40:45,348 [root] DEBUG: 15560: Monitor initialised: 64-bit capemon loaded in process 15560 at 0x00007FFEAF1A0000, thread 15564, image base 0x00007FF6C5DC0000, stack from 0x000000E3B05E4000-0x000000E3B05F0000
2026-05-28 20:40:45,348 [root] DEBUG: 15560: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 20:40:45,359 [root] DEBUG: 15560: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:40:45,380 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:40:45,381 [root] DEBUG: 15560: set_hooks: Unable to hook LockResource
2026-05-28 20:40:45,386 [root] DEBUG: 15560: Hooked 627 out of 628 functions
2026-05-28 20:40:45,387 [root] DEBUG: 15560: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:45,392 [root] DEBUG: 15560: RestoreHeaders: Restored original import table.
2026-05-28 20:40:45,392 [root] INFO: Loaded monitor into process with pid 15560
2026-05-28 20:40:45,393 [root] DEBUG: 15560: caller_dispatch: Added region at 0x00007FF6C5DC0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6C5DC6D01, thread 15564).
2026-05-28 20:40:45,394 [root] DEBUG: 15560: YaraScan: Scanning 0x00007FF6C5DC0000, size 0x16100
2026-05-28 20:40:45,395 [root] DEBUG: 15560: ProcessImageBase: Main module image at 0x00007FF6C5DC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:45,400 [root] DEBUG: 15560: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:40:45,401 [root] DEBUG: 15560: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:40:45,404 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 15560, handle 0x2da0: C:\Windows\System32\rundll32.exe
2026-05-28 20:40:45,407 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8690000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 20:40:45,408 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8690000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 20:40:45,415 [root] DEBUG: 15560: NtTerminateProcess hook: Attempting to dump process 15560
2026-05-28 20:40:45,416 [root] DEBUG: 15560: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:40:45,423 [root] INFO: Process with pid 15560 has terminated
2026-05-28 20:40:47,436 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 15832: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe, ImageBase: 0x0000000000C00000
2026-05-28 20:40:47,437 [root] INFO: Announced 32-bit process name: FileCoAuth.exe pid: 15832
2026-05-28 20:40:47,438 [lib.api.process] INFO: Monitor config for process 15832: C:\_3mo6uuq\dll\15832.ini
2026-05-28 20:40:47,439 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:48,435 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-28 20:40:48,472 [lib.api.process] INFO: 32-bit DLL to inject is C:\_3mo6uuq\dll\GOWHeq.dll, loader C:\_3mo6uuq\bin\HBkFsgf.exe
2026-05-28 20:40:48,480 [root] DEBUG: Loader: Injecting process 15832 (thread 15836) with C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:48,483 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:40:48,484 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:48,487 [lib.api.process] INFO: Injected into 32-bit <Process 15832 FileCoAuth.exe>
2026-05-28 20:40:48,488 [root] INFO: Announced 32-bit process name: FileCoAuth.exe pid: 15832
2026-05-28 20:40:48,489 [lib.api.process] INFO: Monitor config for process 15832: C:\_3mo6uuq\dll\15832.ini
2026-05-28 20:40:48,489 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:40:48,874 [root] INFO: Process with pid 4944 has terminated
2026-05-28 20:40:48,874 [root] DEBUG: 4944: NtTerminateProcess hook: Attempting to dump process 4944
2026-05-28 20:40:48,875 [root] DEBUG: 4944: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:40:49,618 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-28 20:40:49,655 [lib.api.process] INFO: 32-bit DLL to inject is C:\_3mo6uuq\dll\GOWHeq.dll, loader C:\_3mo6uuq\bin\HBkFsgf.exe
2026-05-28 20:40:49,661 [root] DEBUG: Loader: Injecting process 15832 (thread 15836) with C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:49,662 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:40:49,663 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\GOWHeq.dll.
2026-05-28 20:40:49,665 [lib.api.process] INFO: Injected into 32-bit <Process 15832 FileCoAuth.exe>
2026-05-28 20:40:49,676 [root] DEBUG: 15832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:40:49,678 [root] DEBUG: 15832: Interactive desktop enabled.
2026-05-28 20:40:49,679 [root] DEBUG: 15832: Dropped file limit defaulting to 100.
2026-05-28 20:40:49,681 [root] DEBUG: 15832: Disabling sleep skipping.
2026-05-28 20:40:49,682 [root] DEBUG: 15832: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:40:49,683 [root] DEBUG: 15832: YaraScan: Scanning 0x00C00000, size 0xa2732
2026-05-28 20:40:49,688 [root] DEBUG: 15832: Monitor initialised: 32-bit capemon loaded in process 15832 at 0x6c5b0000, thread 15836, image base 0xc00000, stack from 0x534000-0x540000
2026-05-28 20:40:49,689 [root] DEBUG: 15832: Commandline: "C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe" -Embedding
2026-05-28 20:40:49,690 [root] DEBUG: 15832: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\LoggingPlatform.DLL
2026-05-28 20:40:49,691 [root] DEBUG: 15832: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\UpdateRingSettings.dll
2026-05-28 20:40:49,692 [root] DEBUG: 15832: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\MSVCP140.dll
2026-05-28 20:40:49,692 [root] DEBUG: 15832: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\VCRUNTIME140.dll
2026-05-28 20:40:49,715 [root] DEBUG: 15832: hook_api: LdrpCallInitRoutine export address 0x776C2B50 obtained via GetFunctionAddress
2026-05-28 20:40:49,729 [root] DEBUG: 15832: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-28 20:40:49,730 [root] DEBUG: 15832: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-28 20:40:49,734 [root] DEBUG: 15832: Hooked 632 out of 632 functions
2026-05-28 20:40:49,738 [root] DEBUG: 15832: Syscall hook installed, syscall logging level 1
2026-05-28 20:40:49,741 [root] DEBUG: 15832: RestoreHeaders: Restored original import table.
2026-05-28 20:40:49,742 [root] INFO: Loaded monitor into process with pid 15832
2026-05-28 20:40:49,742 [root] DEBUG: 15832: YaraScan: Scanning 0x740B0000, size 0x13ac6
2026-05-28 20:40:49,744 [root] DEBUG: 15832: caller_dispatch: Added region at 0x740B0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x740B7916, thread 15836).
2026-05-28 20:40:49,746 [root] DEBUG: 15832: caller_dispatch: Scanning calling region at 0x740B0000...
2026-05-28 20:40:49,746 [root] DEBUG: 15832: ProcessTrackedRegion: Region at 0x740B0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\vcruntime140.dll appears unmodified, skipping
2026-05-28 20:40:49,747 [root] DEBUG: 15832: YaraScan: Scanning 0x740D0000, size 0x6c6de
2026-05-28 20:40:49,750 [root] DEBUG: 15832: caller_dispatch: Added region at 0x740D0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x740FE9DC, thread 15836).
2026-05-28 20:40:49,751 [root] DEBUG: 15832: caller_dispatch: Scanning calling region at 0x740D0000...
2026-05-28 20:40:49,752 [root] DEBUG: 15832: ProcessTrackedRegion: Region at 0x740D0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\msvcp140.dll appears unmodified, skipping
2026-05-28 20:40:49,754 [root] DEBUG: 15832: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:40:49,757 [root] DEBUG: 15832: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:40:49,760 [root] DEBUG: 15832: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:40:49,764 [root] DEBUG: 15832: caller_dispatch: Added region at 0x74140000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x7418AF34, thread 15836).
2026-05-28 20:40:49,765 [root] DEBUG: 15832: caller_dispatch: Scanning calling region at 0x74140000...
2026-05-28 20:40:49,766 [root] DEBUG: 15832: ProcessTrackedRegion: Region at 0x74140000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\LoggingPlatform.dll appears unmodified, skipping
2026-05-28 20:40:49,768 [root] DEBUG: 15832: DLL loaded at 0x76970000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-28 20:40:49,770 [root] DEBUG: 15832: YaraScan: Scanning 0x737B0000, size 0x6ce84
2026-05-28 20:40:49,773 [root] DEBUG: 15832: caller_dispatch: Added region at 0x737B0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x737F0864, thread 15836).
2026-05-28 20:40:49,774 [root] DEBUG: 15832: caller_dispatch: Scanning calling region at 0x737B0000...
2026-05-28 20:40:49,775 [root] DEBUG: 15832: ProcessTrackedRegion: Region at 0x737B0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\UpdateRingSettings.dll appears unmodified, skipping
2026-05-28 20:40:49,776 [root] DEBUG: 15832: caller_dispatch: Added region at 0x00C00000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00C52D18, thread 15836).
2026-05-28 20:40:49,777 [root] DEBUG: 15832: YaraScan: Scanning 0x00C00000, size 0xa2732
2026-05-28 20:40:49,782 [root] DEBUG: 15832: ProcessImageBase: Main module image at 0x00C00000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:40:49,790 [root] DEBUG: 15832: DLL loaded at 0x74080000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-28 20:40:49,791 [root] DEBUG: 15832: DLL loaded at 0x74050000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-05-28 20:40:49,795 [root] DEBUG: 15832: DLL loaded at 0x748E0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-28 20:40:49,796 [root] DEBUG: 15832: DLL loaded at 0x74910000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-28 20:40:49,798 [root] DEBUG: 15832: DLL loaded at 0x77250000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-28 20:40:49,800 [root] DEBUG: 15832: DLL loaded at 0x74030000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-28 20:40:49,816 [root] DEBUG: 15832: DLL loaded at 0x73E50000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-05-28 20:40:49,817 [root] DEBUG: 15832: DLL loaded at 0x73E90000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\OneDriveTelemetryStable (0x19a000 bytes).
2026-05-28 20:40:49,819 [root] DEBUG: 15832: DLL loaded at 0x74880000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncTelemetryExtensions (0x10000 bytes).
2026-05-28 20:40:49,823 [root] DEBUG: 15832: DLL loaded at 0x74800000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-28 20:40:49,826 [root] DEBUG: 15832: DLL loaded at 0x74F60000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-05-28 20:40:49,828 [root] DEBUG: 15832: DLL loaded at 0x75550000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-28 20:40:49,851 [root] DEBUG: 15832: DLL loaded at 0x74860000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuthLib (0x2a000 bytes).
2026-05-28 20:40:49,857 [root] DEBUG: 10752: DLL loaded at 0x00007FFE95860000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\amd64\FileCoAuthLib64 (0x31000 bytes).
2026-05-28 20:40:55,913 [root] INFO: Added new file to list with pid 15832 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-29.0040.15832.1.aodl
2026-05-28 20:40:55,915 [root] DEBUG: 15832: NtTerminateProcess hook: Attempting to dump process 15832
2026-05-28 20:40:55,916 [root] DEBUG: 15832: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:40:55,921 [root] INFO: Process with pid 15832 has terminated
2026-05-28 20:41:23,528 [root] DEBUG: 7496: DLL loaded at 0x00007FFED8650000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 20:41:23,670 [root] DEBUG: 7496: DLL loaded at 0x00007FFED02B0000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 20:41:23,683 [root] DEBUG: 7496: DLL loaded at 0x00007FFEF06C0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 20:41:23,695 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 15652: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:41:23,696 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 12088: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:41:23,697 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 15652
2026-05-28 20:41:23,698 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 12088
2026-05-28 20:41:23,705 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 15652
2026-05-28 20:41:23,708 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 12088
2026-05-28 20:41:23,717 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 15872: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:41:23,726 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE9310000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 20:41:23,731 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 15872
2026-05-28 20:41:23,735 [root] DEBUG: 7496: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:41:23,743 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 15872
2026-05-28 20:41:23,746 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:23,756 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:23,894 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 9792: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:41:23,898 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 9792
2026-05-28 20:41:23,901 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 9792
2026-05-28 20:41:24,415 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDA3B0000: C:\Windows\system32\zipfldr (0x4a000 bytes).
2026-05-28 20:41:24,416 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDA3B0000: C:\Windows\system32\zipfldr (0x4a000 bytes).
2026-05-28 20:41:24,420 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 15944: C:\Windows\system32\taskhostw.exe, ImageBase: 0x00007FF753750000
2026-05-28 20:41:24,421 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 15972: C:\Windows\system32\wermgr.exe, ImageBase: 0x00007FF6845A0000
2026-05-28 20:41:24,423 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 15944
2026-05-28 20:41:24,423 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 15972
2026-05-28 20:41:24,423 [lib.api.process] INFO: Monitor config for process 15944: C:\_3mo6uuq\dll\15944.ini
2026-05-28 20:41:24,424 [lib.api.process] INFO: Monitor config for process 15972: C:\_3mo6uuq\dll\15972.ini
2026-05-28 20:41:24,424 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:24,425 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:24,428 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:24,430 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:24,437 [root] DEBUG: Loader: Injecting process 15944 (thread 15940) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,437 [root] DEBUG: Loader: Injecting process 15972 (thread 15980) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,438 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:41:24,439 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:41:24,439 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,440 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,442 [lib.api.process] INFO: Injected into 64-bit <Process 15944 taskhostw.exe>
2026-05-28 20:41:24,442 [lib.api.process] INFO: Injected into 64-bit <Process 15972 wermgr.exe>
2026-05-28 20:41:24,444 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 15944
2026-05-28 20:41:24,444 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 15972
2026-05-28 20:41:24,445 [lib.api.process] INFO: Monitor config for process 15944: C:\_3mo6uuq\dll\15944.ini
2026-05-28 20:41:24,445 [lib.api.process] INFO: Monitor config for process 15972: C:\_3mo6uuq\dll\15972.ini
2026-05-28 20:41:24,450 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:24,451 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:24,455 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:24,456 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:24,460 [root] DEBUG: Loader: Injecting process 15944 (thread 15940) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,461 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:41:24,462 [root] DEBUG: Loader: Injecting process 15972 (thread 15980) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,464 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,465 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:41:24,466 [lib.api.process] INFO: Injected into 64-bit <Process 15944 taskhostw.exe>
2026-05-28 20:41:24,466 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,467 [lib.api.process] INFO: Injected into 64-bit <Process 15972 wermgr.exe>
2026-05-28 20:41:24,468 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 15944
2026-05-28 20:41:24,469 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 15972
2026-05-28 20:41:24,470 [lib.api.process] INFO: Monitor config for process 15944: C:\_3mo6uuq\dll\15944.ini
2026-05-28 20:41:24,470 [lib.api.process] INFO: Monitor config for process 15972: C:\_3mo6uuq\dll\15972.ini
2026-05-28 20:41:24,471 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:24,471 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:24,475 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:24,477 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:24,480 [root] DEBUG: Loader: Injecting process 15944 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,481 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15940, handle 0x94
2026-05-28 20:41:24,482 [root] DEBUG: Loader: Injecting process 15972 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,483 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:41:24,484 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15980, handle 0x128
2026-05-28 20:41:24,485 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,485 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:41:24,486 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:24,487 [lib.api.process] INFO: Injected into 64-bit <Process 15944 taskhostw.exe>
2026-05-28 20:41:24,487 [lib.api.process] INFO: Injected into 64-bit <Process 15972 wermgr.exe>
2026-05-28 20:41:24,494 [root] DEBUG: 15972: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:41:24,496 [root] DEBUG: 15972: Interactive desktop enabled.
2026-05-28 20:41:24,497 [root] DEBUG: 15972: Dropped file limit defaulting to 100.
2026-05-28 20:41:24,503 [root] DEBUG: 15944: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:41:24,504 [root] DEBUG: 15944: Interactive desktop enabled.
2026-05-28 20:41:24,505 [root] DEBUG: 15944: Dropped file limit defaulting to 100.
2026-05-28 20:41:24,508 [root] DEBUG: 15944: Disabling sleep skipping.
2026-05-28 20:41:24,509 [root] DEBUG: 15944: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:41:24,515 [root] DEBUG: 15972: Disabling sleep skipping.
2026-05-28 20:41:24,517 [root] DEBUG: 15972: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:41:24,526 [root] DEBUG: 15944: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:41:24,527 [root] DEBUG: 15944: YaraScan: Scanning 0x00007FF753750000, size 0x192fc
2026-05-28 20:41:24,529 [root] DEBUG: 4372: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 20:41:24,531 [root] DEBUG: 15944: Monitor initialised: 64-bit capemon loaded in process 15944 at 0x00007FFEAF1A0000, thread 15940, image base 0x00007FF753750000, stack from 0x000000758E184000-0x000000758E190000
2026-05-28 20:41:24,532 [root] DEBUG: 15944: Commandline: taskhostw.exe
2026-05-28 20:41:24,536 [root] DEBUG: 15972: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:41:24,538 [root] DEBUG: 15972: YaraScan: Scanning 0x00007FF6845A0000, size 0x3f17e
2026-05-28 20:41:24,543 [root] DEBUG: 15972: Monitor initialised: 64-bit capemon loaded in process 15972 at 0x00007FFEAF1A0000, thread 15980, image base 0x00007FF6845A0000, stack from 0x000000E8D4474000-0x000000E8D4480000
2026-05-28 20:41:24,544 [root] DEBUG: 15972: Commandline: "C:\Windows\system32\wermgr.exe" -upload
2026-05-28 20:41:24,547 [root] DEBUG: 15944: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:41:24,569 [root] DEBUG: 15972: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:41:24,585 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:41:24,586 [root] DEBUG: 15944: set_hooks: Unable to hook LockResource
2026-05-28 20:41:24,592 [root] DEBUG: 15944: Hooked 627 out of 628 functions
2026-05-28 20:41:24,594 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:41:24,594 [root] DEBUG: 15944: Syscall hook installed, syscall logging level 1
2026-05-28 20:41:24,595 [root] DEBUG: 15972: set_hooks: Unable to hook LockResource
2026-05-28 20:41:24,599 [root] DEBUG: 15944: RestoreHeaders: Restored original import table.
2026-05-28 20:41:24,600 [root] INFO: Loaded monitor into process with pid 15944
2026-05-28 20:41:24,601 [root] DEBUG: 15972: Hooked 627 out of 628 functions
2026-05-28 20:41:24,602 [root] DEBUG: 15944: caller_dispatch: Added region at 0x00007FF753750000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF753755CA1, thread 15940).
2026-05-28 20:41:24,603 [root] DEBUG: 15944: YaraScan: Scanning 0x00007FF753750000, size 0x192fc
2026-05-28 20:41:24,603 [root] DEBUG: 15972: Syscall hook installed, syscall logging level 1
2026-05-28 20:41:24,604 [root] DEBUG: 15944: ProcessImageBase: Main module image at 0x00007FF753750000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:41:24,607 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF1540000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:41:24,609 [root] DEBUG: 15972: RestoreHeaders: Restored original import table.
2026-05-28 20:41:24,610 [root] DEBUG: 15944: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:41:24,611 [root] INFO: Loaded monitor into process with pid 15972
2026-05-28 20:41:24,612 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:41:24,613 [root] DEBUG: 15972: caller_dispatch: Added region at 0x00007FF6845A0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6845B9181, thread 15980).
2026-05-28 20:41:24,614 [root] DEBUG: 15972: YaraScan: Scanning 0x00007FF6845A0000, size 0x3f17e
2026-05-28 20:41:24,617 [root] DEBUG: 15972: ProcessImageBase: Main module image at 0x00007FF6845A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:41:24,618 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:41:24,623 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:41:24,624 [root] DEBUG: 15972: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 20:41:24,625 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDA360000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-05-28 20:41:24,628 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9980000: C:\Windows\System32\InstallServiceTasks (0x3e000 bytes).
2026-05-28 20:41:24,632 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEACF0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:41:24,636 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,637 [root] DEBUG: 15944: DLL loaded at 0x00007FFED8B50000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:41:24,638 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,640 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:41:24,642 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:41:24,643 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:41:24,645 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,646 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,652 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,653 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,654 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,655 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,660 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:41:24,661 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:41:24,670 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEB550000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:41:24,672 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:41:24,673 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:41:24,676 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:41:24,678 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:41:24,681 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDD9D0000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-28 20:41:24,683 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,684 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,685 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF640000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:41:24,686 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE4FE0000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-05-28 20:41:24,688 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:41:24,689 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,690 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:41:24,691 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,691 [root] DEBUG: 15944: DLL loaded at 0x00007FFED49C0000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-05-28 20:41:24,693 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF210000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:41:24,695 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,696 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,698 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:41:24,698 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:41:24,713 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,715 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,719 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,721 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,725 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,726 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,731 [root] DEBUG: 15972: DLL loaded at 0x00007FFEF1540000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:41:24,731 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:41:24,732 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9960000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:41:24,735 [root] DEBUG: 15972: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:41:24,736 [root] DEBUG: 15972: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:41:24,739 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:41:24,745 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:41:24,746 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:41:24,747 [root] DEBUG: 15972: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:41:24,749 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:41:24,749 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:41:24,753 [root] DEBUG: 15944: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:41:24,754 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:41:24,757 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,759 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDAF20000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-28 20:41:24,760 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,762 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE5AA0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 20:41:24,764 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,765 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,768 [root] DEBUG: 15944: DLL loaded at 0x00007FFED5BD0000: C:\Windows\system32\fcon (0x45000 bytes).
2026-05-28 20:41:24,768 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,769 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,776 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:41:24,776 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,778 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,782 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,782 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,786 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,788 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,798 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,799 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,800 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:41:24,801 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9960000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:41:24,803 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,804 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,808 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,810 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,810 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:41:24,811 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:41:24,813 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:41:24,815 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:41:24,815 [root] DEBUG: 15944: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:41:24,816 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:41:24,820 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDAF20000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-28 20:41:24,820 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,821 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,826 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,827 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,831 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,833 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,851 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,851 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,855 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,856 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,859 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:41:24,859 [root] DEBUG: 15972: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:41:24,864 [root] DEBUG: 15972: NtTerminateProcess hook: Attempting to dump process 15972
2026-05-28 20:41:24,865 [root] DEBUG: 15972: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:41:24,870 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:41:24,872 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9960000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:41:24,874 [root] INFO: Process with pid 15972 has terminated
2026-05-28 20:41:24,875 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:41:24,877 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:41:24,878 [root] INFO: Process with pid 15972 has terminated
2026-05-28 20:41:24,878 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:41:24,880 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:41:24,881 [root] DEBUG: 15944: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:41:24,882 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:41:24,890 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:41:24,892 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-28 20:41:24,894 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 20:41:24,901 [root] DEBUG: 15944: DLL loaded at 0x00007FFED4780000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:24,902 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 20:41:24,904 [root] DEBUG: 15944: DLL loaded at 0x00007FFEB6C10000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-28 20:41:24,906 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-28 20:41:24,906 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9040000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-28 20:41:24,907 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE0D0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-28 20:41:24,908 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:41:24,909 [root] DEBUG: 15944: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 20:41:24,910 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE6180000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-28 20:41:24,911 [root] DEBUG: 15944: DLL loaded at 0x00007FFED50A0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-28 20:41:24,929 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 20:41:24,930 [root] DEBUG: 15944: DLL loaded at 0x00007FFED0400000: C:\Windows\System32\OneSettingsClient (0x32000 bytes).
2026-05-28 20:41:24,937 [root] DEBUG: 15944: DLL loaded at 0x00007FFED5E30000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-05-28 20:41:24,940 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEDE0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:41:24,942 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE8E20000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 20:41:24,946 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE8E40000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:41:24,947 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE8D30000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:41:24,951 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDB3D0000: C:\Windows\System32\webio (0x98000 bytes).
2026-05-28 20:41:24,962 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEB10000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:41:24,964 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE4F10000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-05-28 20:41:24,992 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE6D00000: C:\Windows\System32\fwpuclnt (0x80000 bytes).
2026-05-28 20:41:25,191 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE620000: C:\Windows\system32\schannel (0x97000 bytes).
2026-05-28 20:41:25,575 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9520000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-05-28 20:41:25,577 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:41:25,580 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\system32\ncrypt (0x27000 bytes).
2026-05-28 20:41:25,582 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9570000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-05-28 20:41:25,601 [root] DEBUG: 15944: DLL loaded at 0x00007FFED94B0000: C:\Windows\system32\cryptnet (0x31000 bytes).
2026-05-28 20:41:25,611 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF430000: C:\Windows\system32\DPAPI (0xa000 bytes).
2026-05-28 20:41:25,775 [root] INFO: Added new file to list with pid 10812 and path C:\ProgramData\USOPrivate\UpdateStore\store.db
2026-05-28 20:41:25,776 [root] INFO: Added new file to list with pid 10812 and path C:\ProgramData\USOShared\Logs\System\WuProvider.66c45947-6c78-4452-9c65-bebfe7903b50.1.etl
2026-05-28 20:41:25,777 [root] INFO: Added new file to list with pid 10812 and path C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.56a529bd-084b-44db-b3c8-67bf99008ac1.1.etl
2026-05-28 20:41:25,778 [root] DEBUG: 10812: NtTerminateProcess hook: Attempting to dump process 10812
2026-05-28 20:41:25,780 [root] DEBUG: 10812: CAPEExceptionFilter: Exception 0xc0000005 accessing 0xd051d004 caught at RVA 0x75419 in capemon (expected in memory scans), passing to next handler.
2026-05-28 20:41:25,781 [root] DEBUG: 10812: VerifyCodeSection: Exception rebasing image from 0x00007FF6D0370000 to 0x0000000140000000.
2026-05-28 20:41:25,782 [root] DEBUG: 10812: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:41:25,791 [root] INFO: Process with pid 10812 has terminated
2026-05-28 20:41:26,048 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:41:26,050 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9960000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:41:26,101 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:41:26,103 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:41:26,104 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:41:26,105 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:41:26,106 [root] DEBUG: 15944: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:41:26,108 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:41:26,110 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9960000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:41:26,142 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:41:26,143 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE250000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-05-28 20:41:26,513 [root] DEBUG: 15944: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:41:26,514 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 20:41:26,522 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:41:26,523 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:41:26,526 [root] DEBUG: 15944: DLL loaded at 0x00007FFED4EC0000: C:\Windows\SYSTEM32\dmEnrollEngine (0xdf000 bytes).
2026-05-28 20:41:26,527 [root] DEBUG: 15944: DLL loaded at 0x00007FFED4FA0000: C:\Windows\SYSTEM32\enrollmentapi (0x11000 bytes).
2026-05-28 20:41:26,551 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:41:26,553 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:41:26,555 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:41:26,557 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:41:26,558 [root] DEBUG: 15944: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:41:26,559 [root] DEBUG: 15944: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:41:26,561 [root] DEBUG: 15944: DLL loaded at 0x00007FFED9960000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:41:26,581 [root] DEBUG: 15944: DLL loaded at 0x00007FFEE59B0000: C:\Windows\SYSTEM32\dmiso8601utils (0x9000 bytes).
2026-05-28 20:41:26,605 [root] DEBUG: 15944: NtTerminateProcess hook: Attempting to dump process 15944
2026-05-28 20:41:26,606 [root] DEBUG: 15944: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:41:26,616 [root] INFO: Process with pid 15944 has terminated
2026-05-28 20:41:26,620 [root] INFO: Process with pid 15944 has terminated
2026-05-28 20:41:32,216 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 17140: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:41:32,217 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 17140
2026-05-28 20:41:32,219 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 17140
2026-05-28 20:41:32,270 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDA370000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:41:32,272 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDA370000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:41:32,321 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9990000: C:\Windows\System32\shacct (0x29000 bytes).
2026-05-28 20:41:32,322 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9990000: C:\Windows\System32\shacct (0x29000 bytes).
2026-05-28 20:41:32,365 [root] DEBUG: 4372: api-cap: NtQueryKey hook disabled due to count: 5000
2026-05-28 20:41:32,383 [root] DEBUG: 4372: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 20:41:32,402 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5320000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 20:41:32,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5320000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 20:41:32,512 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9960000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 20:41:32,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9960000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 20:41:32,547 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDA350000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 20:41:32,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDA350000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 20:41:32,565 [root] DEBUG: 4372: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 20:41:32,642 [root] DEBUG: 4372: api-cap: NtWaitForSingleObject hook disabled due to count: 5000
2026-05-28 20:41:32,647 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8A00000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:41:32,649 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8A00000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:41:32,652 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE59B0000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 20:41:32,654 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE59B0000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 20:41:32,665 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5C00000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 20:41:32,667 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5C00000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 20:41:32,682 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE5850000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 20:41:32,684 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE5850000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 20:41:32,684 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5BE0000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 20:41:32,686 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5BE0000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 20:41:32,731 [root] DEBUG: 4372: DLL loaded at 0x00007FFED52C0000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 20:41:32,732 [root] DEBUG: 4372: DLL loaded at 0x00007FFED52C0000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 20:41:32,736 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4F50000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 20:41:32,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4F50000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 20:41:32,747 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4EA0000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 20:41:32,748 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4EA0000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 20:41:32,757 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4E70000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 20:41:32,758 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4E70000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 20:41:33,914 [root] DEBUG: 4372: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-28 20:41:34,026 [root] DEBUG: 4372: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 20:41:36,448 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9960000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-28 20:41:36,450 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9960000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-28 20:41:36,584 [root] DEBUG: 4372: DLL loaded at 0x00007FFEF0A50000: C:\Windows\System32\comdlg32 (0xda000 bytes).
2026-05-28 20:41:36,585 [root] DEBUG: 4372: DLL loaded at 0x00007FFEF0A50000: C:\Windows\System32\comdlg32 (0xda000 bytes).
2026-05-28 20:41:42,095 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9050000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:41:42,098 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9050000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:41:42,103 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,106 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,117 [root] DEBUG: 4372: DLL loaded at 0x00007FFEEDFA0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:41:42,119 [root] DEBUG: 4372: DLL loaded at 0x00007FFEEDFA0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:41:42,179 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,180 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,181 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,182 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,194 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,196 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,239 [root] DEBUG: 4372: api-cap: NtOpenProcessToken hook disabled due to count: 5000
2026-05-28 20:41:42,264 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,266 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,341 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,342 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,401 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,416 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,417 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,470 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,472 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,474 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,476 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,488 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,489 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,533 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,534 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,535 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,536 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,549 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,601 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,602 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,603 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,604 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,615 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,616 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,636 [root] DEBUG: 4372: api-cap: RegEnumKeyExW hook disabled due to count: 5000
2026-05-28 20:41:42,676 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,678 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,681 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,681 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,692 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,693 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,744 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,745 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,747 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,747 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,759 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,760 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,807 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,808 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,810 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,811 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,822 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,823 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,871 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,872 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,873 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,875 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,884 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,885 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,933 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,935 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,936 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,937 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,946 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,946 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:42,954 [root] DEBUG: 4372: api-cap: GetSystemTimeAsFileTime hook disabled due to count: 5000
2026-05-28 20:41:42,993 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:42,996 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:42,997 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,006 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,007 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,066 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,068 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,069 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,072 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,082 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,084 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,135 [root] DEBUG: 4372: api-cap: NtQueryValueKey hook disabled due to count: 5000
2026-05-28 20:41:43,155 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,158 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,225 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,227 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,271 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,272 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,273 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,276 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,285 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,337 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,339 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,340 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,342 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,352 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,353 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,421 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,422 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,423 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,424 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,436 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,437 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,484 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,485 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,487 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,489 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,498 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,500 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,572 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,573 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,622 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,624 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,625 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,626 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,638 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,638 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,684 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,686 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,690 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,700 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,703 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,746 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,749 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,752 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,753 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,771 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,773 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,819 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,820 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,821 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,822 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,833 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,835 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,876 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,877 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,878 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,879 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,888 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,889 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,936 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,938 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,938 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,939 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,949 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,950 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:43,991 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,993 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:43,994 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:43,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,004 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,005 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,047 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,050 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,052 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,053 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,062 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,067 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,109 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,109 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,111 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,112 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,122 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,123 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,179 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,180 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,183 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,186 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,203 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,205 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,257 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,258 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,259 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,260 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,270 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,273 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,333 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,401 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,447 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,448 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,449 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,450 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,460 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,461 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,508 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,510 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,511 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,522 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,523 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,575 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,576 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,577 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,578 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,587 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,588 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,639 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,641 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,643 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,645 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,655 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,656 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,723 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,724 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,726 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,727 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,736 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,737 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,783 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,785 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,786 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,796 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,797 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,846 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,849 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,850 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,851 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,863 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,864 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,922 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,924 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,925 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,926 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,936 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,937 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,979 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,980 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:44,981 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,982 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:44,991 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:44,993 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,036 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,037 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,038 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,040 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,050 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,051 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,093 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,094 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,096 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,099 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,109 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,110 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,152 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,153 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,154 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,155 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,165 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,165 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,218 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,220 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,222 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,233 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,235 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,277 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,278 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,279 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,281 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,291 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,293 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,334 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,335 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,336 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,337 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,348 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,348 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,390 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,391 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,392 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,393 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,449 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,450 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,451 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,453 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,463 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,465 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,512 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,514 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,515 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,525 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,527 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,568 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,569 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,570 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,571 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,581 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,581 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,627 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,628 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,630 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,631 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,641 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,642 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,690 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,692 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,695 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,704 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,705 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,747 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,748 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,750 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,752 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,761 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,762 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,804 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,806 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,807 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,809 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,818 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,819 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,861 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,862 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,865 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,866 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,875 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,878 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,929 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,930 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,931 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,933 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,942 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,944 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:45,986 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,988 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:45,990 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:45,991 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,000 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,002 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,044 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,045 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,047 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,047 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,057 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,058 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,104 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,106 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,107 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,108 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,119 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,121 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,165 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,166 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,167 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,168 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,179 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,180 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,221 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,222 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,224 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,226 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,237 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,238 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,280 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,281 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,282 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,283 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,294 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,295 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,338 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,339 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,340 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,341 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,350 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,352 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,393 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,395 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,397 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,399 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,411 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,412 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,459 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,461 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,463 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,464 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,473 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,474 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,515 [root] DEBUG: 4372: api-cap: NtSetInformationThread hook disabled due to count: 5000
2026-05-28 20:41:46,516 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,517 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,519 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,520 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,530 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,531 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,572 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,574 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,575 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,577 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,587 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,588 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,629 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,630 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,632 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,633 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,643 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,644 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,685 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,687 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,690 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,700 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,702 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,750 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,751 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,753 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,754 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,763 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,765 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,807 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,809 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,810 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,811 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,821 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,822 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,861 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,863 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,865 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,866 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,875 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,876 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,916 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,917 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,919 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,920 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,931 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,932 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,981 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,983 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:46,984 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,986 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:46,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:46,996 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,039 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,042 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,046 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,047 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,058 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,060 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,099 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,101 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,102 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,103 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,114 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,116 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,158 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,159 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,160 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,162 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,171 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,172 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,220 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,222 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,265 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,266 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,267 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,268 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,277 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,279 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,346 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,347 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,348 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,351 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,363 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,364 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,378 [root] DEBUG: 4372: api-cap: FindResourceExW hook disabled due to count: 5000
2026-05-28 20:41:47,380 [root] DEBUG: 4372: api-cap: LoadResource hook disabled due to count: 5000
2026-05-28 20:41:47,412 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,414 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,415 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,416 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,426 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,427 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,478 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,479 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,481 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,482 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,492 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,494 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,549 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,550 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,551 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,562 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,564 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,619 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,620 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,621 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,623 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,633 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,635 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,676 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,678 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,678 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,680 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,690 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,692 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,731 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,733 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,734 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,735 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,746 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,747 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,787 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,788 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,790 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,791 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,796 [root] DEBUG: 4372: api-cap: NtCreateFile hook disabled due to count: 5000
2026-05-28 20:41:47,801 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,803 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,815 [root] DEBUG: 4372: api-cap: SizeofResource hook disabled due to count: 5000
2026-05-28 20:41:47,838 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,840 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,843 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,844 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,853 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,854 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,886 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,887 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,889 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,891 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,900 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,901 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,932 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,933 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,934 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,934 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,944 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,982 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,983 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:47,984 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,985 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:47,994 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:47,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,027 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,029 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,031 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,032 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,040 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,040 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,075 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,077 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,079 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,080 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,087 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,088 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,121 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,122 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,124 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,124 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,132 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,134 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,167 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,168 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,170 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,171 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,179 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,180 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,212 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,215 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,217 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,224 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,226 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,258 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,259 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,261 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,262 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,270 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,271 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,310 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,312 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,314 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,315 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,322 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,324 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,356 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,357 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,357 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,358 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,368 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,400 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,401 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,412 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,413 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,447 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,448 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,449 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,450 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,458 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,459 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,490 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,492 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,493 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,494 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,502 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,504 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,534 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,535 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,537 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,538 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,546 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,547 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,580 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,581 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,582 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,583 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,592 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,597 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,632 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,633 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,635 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,636 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,643 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,645 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,678 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,679 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,680 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,681 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,692 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,725 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,727 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,727 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,728 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,741 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,786 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,787 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,789 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,790 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,797 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,798 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,834 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,835 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,836 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,838 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,846 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,848 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,880 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,882 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,884 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,884 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,892 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,894 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,926 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,927 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,928 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,929 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,937 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,938 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,969 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,970 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:48,971 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,974 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:48,982 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:48,983 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,013 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,014 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,014 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,016 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,023 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,024 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,057 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,058 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,060 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,062 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,069 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,070 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,076 [root] DEBUG: 4372: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 20:41:49,103 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,105 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,107 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,107 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,115 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,116 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,147 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,148 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,150 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,150 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,158 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,159 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,190 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,192 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,193 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,194 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,201 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,203 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,235 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,237 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,238 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,240 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,248 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,251 [root] DEBUG: 4372: api-cap: LdrGetProcedureAddressForCaller hook disabled due to count: 5000
2026-05-28 20:41:49,282 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,283 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,285 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,293 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,295 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,306 [root] DEBUG: 4372: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 20:41:49,328 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,329 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,329 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,330 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,337 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,338 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,369 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,371 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,372 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,373 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,381 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,382 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,414 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,415 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,417 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,418 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,426 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,427 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,459 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,460 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,461 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,463 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,470 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,472 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,502 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,503 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,504 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,505 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,514 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,516 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,544 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,546 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,549 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,557 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,558 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,592 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,594 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,627 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,628 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,629 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,631 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,636 [root] DEBUG: 4372: api-cap: DeviceIoControl hook disabled due to count: 5000
2026-05-28 20:41:49,640 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,642 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,681 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,683 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,685 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,688 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,696 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,698 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,731 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,732 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,735 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,737 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,746 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,747 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,782 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,783 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,792 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,795 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,824 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,825 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,826 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,828 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,836 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,837 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,870 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,871 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,872 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,873 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,882 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,883 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,913 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,914 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,917 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,920 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,927 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,929 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,961 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,962 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:49,963 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,964 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:49,973 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:49,974 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,011 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,012 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,013 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,015 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,023 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,024 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,075 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,076 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,077 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,078 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,086 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,086 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,116 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,118 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,120 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,122 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,131 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,132 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,161 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,162 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,163 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,164 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,173 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,175 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,204 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,205 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,207 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,208 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,218 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,251 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,253 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,254 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,265 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,268 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,307 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,334 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,337 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,347 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,349 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,387 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,389 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,390 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,392 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,401 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,437 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,438 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,441 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,443 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,451 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,452 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,486 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,488 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,490 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,492 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,501 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,502 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,542 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,544 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,550 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,560 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,564 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,588 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 21548: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:41:50,592 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21548
2026-05-28 20:41:50,593 [lib.api.process] INFO: Monitor config for process 21548: C:\_3mo6uuq\dll\21548.ini
2026-05-28 20:41:50,596 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:50,598 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,599 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,600 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,602 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:50,603 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,611 [root] DEBUG: Loader: Injecting process 21548 (thread 21552) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:50,612 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:41:50,613 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,614 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:50,616 [lib.api.process] INFO: Injected into 64-bit <Process 21548 dllhost.exe>
2026-05-28 20:41:50,617 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,618 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21548
2026-05-28 20:41:50,620 [lib.api.process] INFO: Monitor config for process 21548: C:\_3mo6uuq\dll\21548.ini
2026-05-28 20:41:50,622 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:41:50,626 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:41:50,632 [root] DEBUG: 4372: api-cap: CoCreateInstance hook disabled due to count: 5000
2026-05-28 20:41:50,636 [root] DEBUG: Loader: Injecting process 21548 (thread 21552) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:50,636 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:41:50,641 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:41:50,646 [lib.api.process] INFO: Injected into 64-bit <Process 21548 dllhost.exe>
2026-05-28 20:41:50,649 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,650 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,651 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,652 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,653 [root] DEBUG: 21548: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:41:50,654 [root] DEBUG: 21548: Interactive desktop enabled.
2026-05-28 20:41:50,655 [root] DEBUG: 21548: Dropped file limit defaulting to 100.
2026-05-28 20:41:50,659 [root] DEBUG: 21548: Disabling sleep skipping.
2026-05-28 20:41:50,661 [root] DEBUG: 21548: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:41:50,662 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,663 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,673 [root] DEBUG: 21548: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:41:50,674 [root] DEBUG: 21548: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:41:50,676 [root] DEBUG: 21548: Monitor initialised: 64-bit capemon loaded in process 21548 at 0x00007FFEAF1A0000, thread 21552, image base 0x00007FF6868D0000, stack from 0x00000088DECF4000-0x00000088DED00000
2026-05-28 20:41:50,677 [root] DEBUG: 21548: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:41:50,688 [root] DEBUG: 21548: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:41:50,694 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,695 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,696 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,698 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,704 [root] DEBUG: 4372: api-cap: NtOpenFile hook disabled due to count: 5000
2026-05-28 20:41:50,706 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,707 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,709 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:41:50,710 [root] DEBUG: 21548: set_hooks: Unable to hook LockResource
2026-05-28 20:41:50,716 [root] DEBUG: 21548: Hooked 627 out of 628 functions
2026-05-28 20:41:50,717 [root] DEBUG: 21548: Syscall hook installed, syscall logging level 1
2026-05-28 20:41:50,722 [root] DEBUG: 21548: RestoreHeaders: Restored original import table.
2026-05-28 20:41:50,723 [root] INFO: Loaded monitor into process with pid 21548
2026-05-28 20:41:50,727 [root] DEBUG: 21548: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 21552).
2026-05-28 20:41:50,729 [root] DEBUG: 21548: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:41:50,731 [root] DEBUG: 21548: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:41:50,735 [root] DEBUG: 21548: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:41:50,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,739 [root] DEBUG: 21548: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:41:50,739 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,743 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,744 [root] DEBUG: 21548: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:41:50,746 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,752 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,752 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,762 [root] DEBUG: 21548: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:41:50,776 [root] DEBUG: 21548: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:41:50,778 [root] DEBUG: 21548: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:41:50,783 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,783 [root] DEBUG: 21548: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:41:50,785 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,786 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,787 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,792 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,795 [root] DEBUG: 4372: api-cap: NtReleaseMutant hook disabled due to count: 5000
2026-05-28 20:41:50,795 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,824 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,825 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,825 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,827 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,832 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,833 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,859 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,861 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,862 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,864 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,868 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,870 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,894 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,896 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,898 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,899 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,904 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,906 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,940 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,941 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,945 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,950 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,952 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,981 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,982 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:50,984 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,985 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:50,990 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:50,992 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,019 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,020 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,021 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,021 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,026 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,027 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,044 [root] DEBUG: 4372: api-cap: NtReadFile hook disabled due to count: 5000
2026-05-28 20:41:51,067 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,068 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,069 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,070 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,075 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,076 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,102 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,104 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,105 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,106 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,112 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,112 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,138 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,139 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,140 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,141 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,146 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,147 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,174 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,175 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,176 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,178 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,182 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,183 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,211 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,212 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,214 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,215 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,219 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,220 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,246 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,247 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,248 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,249 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,255 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,257 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,283 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,284 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,287 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,293 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,294 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,321 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,323 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,323 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,325 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,331 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,344 [root] DEBUG: 4372: api-cap: NtQueryInformationFile hook disabled due to count: 5000
2026-05-28 20:41:51,357 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,359 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,360 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,361 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,365 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,366 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,389 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,390 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,391 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,393 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,398 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,401 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,428 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,430 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,431 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,432 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,436 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,438 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,460 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,462 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,463 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,465 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,470 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,471 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,495 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,496 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,498 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,498 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,502 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,503 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,526 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,528 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,529 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,531 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,536 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,537 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,561 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,563 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,569 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,570 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,578 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,579 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,602 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,605 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,607 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,609 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,614 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,615 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,650 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,652 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,653 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,654 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,658 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,659 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,691 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,693 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,694 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,695 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,700 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,702 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,707 [root] DEBUG: 4372: api-cap: NtCreateMutant hook disabled due to count: 5000
2026-05-28 20:41:51,735 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,736 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,737 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,742 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,744 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,775 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,776 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,778 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,779 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,783 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,815 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,815 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,816 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,818 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,822 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,823 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,854 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,855 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,857 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,859 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,863 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,864 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,895 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,897 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,899 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,900 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,906 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,907 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,949 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,951 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,952 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,953 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,959 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,960 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:51,989 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,992 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:51,993 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:51,994 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,000 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,001 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,030 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,032 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,033 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,035 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,040 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,042 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,071 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,073 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,074 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,075 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,081 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,082 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,088 [root] DEBUG: 4372: api-cap: SetErrorMode hook disabled due to count: 5000
2026-05-28 20:41:52,090 [root] DEBUG: 4372: api-cap: LdrUnloadDll hook disabled due to count: 5000
2026-05-28 20:41:52,117 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,117 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,119 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,122 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,126 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,128 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,159 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,160 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,162 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,163 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,168 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,169 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,199 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,200 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,201 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,204 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,208 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,209 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,240 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,242 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,242 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,243 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,249 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,281 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,283 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,294 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,294 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,325 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,326 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,328 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,333 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,335 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,369 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,369 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,371 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,376 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,378 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,409 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,411 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,412 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,413 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,418 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,422 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,452 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,454 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,454 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,456 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,460 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,461 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,490 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,492 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,494 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,497 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,502 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,502 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,533 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,534 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,535 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,537 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,541 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,543 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,572 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,574 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,576 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,577 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,582 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,585 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,616 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,618 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,619 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,621 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,625 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,626 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,656 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,657 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,659 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,661 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,665 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,667 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,698 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,700 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,700 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,703 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,707 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,708 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,715 [root] DEBUG: 4372: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 20:41:52,740 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,742 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,743 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,744 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,750 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,751 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,779 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,781 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,782 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,788 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,791 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,820 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,822 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,823 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,824 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,829 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,833 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,862 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,863 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,864 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,865 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,869 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,870 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,901 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,902 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,903 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,905 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,909 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,910 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,944 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,946 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,947 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,951 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,954 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,985 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,987 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:52,989 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,990 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:52,994 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:52,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,024 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,026 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,026 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,028 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,033 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,035 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,045 [root] DEBUG: 4372: api-cap: NtQueryAttributesFile hook disabled due to count: 5000
2026-05-28 20:41:53,064 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,065 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,066 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,067 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,071 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,072 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,104 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,105 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,106 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,108 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,114 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,115 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,144 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,145 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,146 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,147 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,151 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,152 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,180 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,182 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,183 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,185 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,189 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,190 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,222 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,224 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,225 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,227 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,231 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,232 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,260 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,261 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,262 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,265 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,269 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,271 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,302 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,304 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,306 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,306 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,312 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,313 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,353 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,356 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,359 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,361 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,369 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,371 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,407 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,408 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,412 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,413 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,436 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,439 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,440 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,444 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,453 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,454 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,485 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,487 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,488 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,490 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,494 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,495 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,529 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,531 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,533 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,535 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,539 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,540 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,568 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,569 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,570 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,571 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,575 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,576 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,612 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,614 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,616 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,616 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,621 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,622 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,649 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,650 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,652 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,654 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,658 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,660 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,691 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,693 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,693 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,697 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,699 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,726 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,728 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,729 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,731 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,735 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,737 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,765 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,766 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,767 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,768 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,772 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,773 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,802 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,803 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,804 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,805 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,810 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,811 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,841 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,842 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,844 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,845 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,849 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,851 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,878 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,879 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,881 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,883 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,887 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,888 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,917 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,920 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,921 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,923 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,927 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,929 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,962 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,963 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:53,965 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,966 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:53,971 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:53,971 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,000 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,001 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,003 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,004 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,008 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,009 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,037 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,038 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,042 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,043 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,048 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,051 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,079 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,080 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,081 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,083 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,087 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,088 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,117 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,118 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,120 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,121 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,126 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,128 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,161 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,162 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,164 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,166 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,171 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,172 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,206 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,208 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,209 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,211 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,218 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,248 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,249 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,249 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,252 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,257 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,258 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,284 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,285 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,287 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,291 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,292 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,322 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,323 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,326 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,331 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,360 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,361 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,362 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,363 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,368 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,396 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,397 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,398 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,399 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,432 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,434 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,435 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,436 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,440 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,442 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,471 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,472 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,473 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,474 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,483 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,485 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,515 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,518 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,519 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,519 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,524 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,525 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,554 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,555 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,556 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,557 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,562 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,563 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,594 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,595 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,596 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,596 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,600 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,602 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,630 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,631 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,632 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,634 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,639 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,640 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,666 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,668 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,670 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,671 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,675 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,676 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,709 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,710 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,711 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,712 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,717 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,718 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,759 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,761 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,765 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,767 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,772 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,774 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,808 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,810 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,811 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,813 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,817 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,819 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,847 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,850 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,855 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,856 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,861 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,863 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,894 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,896 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,897 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,898 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,903 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,903 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,936 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,936 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,938 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,939 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,944 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,944 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,972 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,974 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:54,974 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,976 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:54,980 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:54,981 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,009 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,010 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,012 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,013 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,017 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,018 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,047 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,049 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,051 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,053 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,057 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,059 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,088 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,089 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,092 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,094 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,098 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,099 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,129 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,131 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,132 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,134 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,138 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,139 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,170 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,172 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,173 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,174 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,178 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,180 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,208 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,209 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,212 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,217 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,218 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,244 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,245 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,247 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,248 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,252 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,254 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,280 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,282 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,284 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,289 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,290 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,318 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,319 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,320 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,322 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,326 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,355 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,357 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,359 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,360 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,365 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,366 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,396 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,397 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,398 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,399 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,463 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,466 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,467 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,469 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,472 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,473 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,496 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,497 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,498 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,501 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,505 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,506 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,534 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,537 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,537 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,538 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,543 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,544 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,582 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,583 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,585 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,586 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,592 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,592 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,619 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,620 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,622 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,623 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,627 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,629 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,650 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,650 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,651 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,653 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,657 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,659 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,686 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,687 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,688 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,695 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,696 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,733 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,734 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,736 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,742 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,743 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,770 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,772 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,774 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,776 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,780 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,781 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,811 [root] DEBUG: 13208: NtTerminateProcess hook: Attempting to dump process 13208
2026-05-28 20:41:55,812 [root] DEBUG: 13208: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:41:55,814 [root] INFO: Process with pid 13208 has terminated
2026-05-28 20:41:55,824 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,825 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,826 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,827 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,829 [root] INFO: Process with pid 21548 has terminated
2026-05-28 20:41:55,830 [root] DEBUG: 21548: NtTerminateProcess hook: Attempting to dump process 21548
2026-05-28 20:41:55,833 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,833 [root] DEBUG: 21548: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:41:55,833 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,924 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,928 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,929 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,931 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,935 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,936 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,965 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,966 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:55,968 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,969 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:55,973 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:55,974 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,002 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,003 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,004 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,006 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,011 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,012 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,040 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,041 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,043 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,045 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,050 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,051 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,078 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,080 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,082 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,084 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,088 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,091 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,118 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,120 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,122 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,124 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,127 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,130 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,159 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,160 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,162 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,164 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,168 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,170 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,197 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,198 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,200 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,201 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,204 [root] DEBUG: 4372: api-cap: LoadLibraryExW hook disabled due to count: 5000
2026-05-28 20:41:56,206 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,208 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,236 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,237 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,238 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,239 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,243 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,244 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,283 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,285 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,288 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,291 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,294 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,321 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,324 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,326 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,331 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,361 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,362 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,364 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,365 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,370 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,372 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,402 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,406 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,413 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,413 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,442 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,443 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,444 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,445 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,449 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,451 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,479 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,481 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,482 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,484 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,490 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,491 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,520 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,522 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,523 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,524 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,530 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,531 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,559 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,560 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,561 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,562 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,568 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,569 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,632 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,634 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,636 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,637 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,642 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,643 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,672 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,673 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,676 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,677 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,681 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,683 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,711 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,711 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,713 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,714 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,719 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,720 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,750 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,750 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,752 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,754 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,758 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,759 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,789 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,790 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,792 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,793 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,798 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,799 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,827 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,828 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,829 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,831 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,835 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,837 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,866 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,868 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,870 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,871 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,878 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,880 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,908 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,909 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,911 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,913 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,917 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,919 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,946 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,947 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,949 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,950 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,957 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,958 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,986 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,987 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:56,988 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,989 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:56,994 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:56,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,024 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,027 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,028 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,029 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,034 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,036 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,064 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,067 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,068 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,072 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,081 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,083 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,111 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,112 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,115 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,118 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,123 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,126 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,158 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,160 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,163 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,164 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,172 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,174 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,217 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,218 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,221 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,226 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,229 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,258 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,259 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,261 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,263 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,267 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,269 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,310 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,312 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,313 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,314 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,318 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,319 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,349 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,350 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,352 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,353 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,358 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,361 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,397 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,397 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,399 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,400 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,407 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,447 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,448 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,451 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,452 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,457 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,459 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,487 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,488 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,489 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,491 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,497 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,498 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,560 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,561 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,563 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,564 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,569 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,570 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,644 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,647 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,648 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,650 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,654 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,655 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,684 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,686 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,688 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,690 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,694 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,695 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,780 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,782 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,786 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,790 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,792 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,822 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,823 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,826 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,827 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,832 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,836 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,906 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,907 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,909 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,910 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,914 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,916 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,945 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,947 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,948 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,952 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,954 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,981 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,982 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:57,984 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,985 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:57,988 [root] DEBUG: 4372: api-cap: NtQueryInformationThread hook disabled due to count: 5000
2026-05-28 20:41:57,990 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:57,992 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,060 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,062 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,063 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,065 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,069 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,070 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,120 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,128 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,129 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,131 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,139 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,142 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,171 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,173 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,176 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,177 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,182 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,185 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,215 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,217 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,221 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,223 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,251 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,253 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,253 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,257 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,259 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,288 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,289 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,290 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,295 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,296 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,323 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,325 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,328 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,335 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,363 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,364 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,365 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,371 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,372 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,400 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,402 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,404 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,406 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,411 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,412 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,434 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,436 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,438 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,439 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,443 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,444 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,471 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,472 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,473 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,476 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,481 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,482 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,512 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,514 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,515 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,519 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,521 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,555 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,556 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,558 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,560 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,564 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,565 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,593 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,594 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,595 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,597 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,601 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,603 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,632 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,634 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,636 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,636 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,643 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,645 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,681 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,683 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,684 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,685 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,689 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,691 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,720 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,721 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,722 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,724 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,728 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,730 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,757 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,759 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,760 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,761 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,766 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,767 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,794 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,795 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,797 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,797 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,802 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,804 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,833 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,835 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,837 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,839 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,842 [root] DEBUG: 4372: api-cap: NtDeviceIoControlFile hook disabled due to count: 5000
2026-05-28 20:41:58,844 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,845 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,875 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,877 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,879 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,880 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,883 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,885 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,914 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,916 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,917 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,919 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,922 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,923 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,949 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,951 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,952 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,953 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,956 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,957 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,985 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,986 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:58,988 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,989 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:58,992 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:58,994 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,020 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,021 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,023 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,024 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,028 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,029 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,056 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,058 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,059 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,060 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,064 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,066 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,092 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,093 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,094 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,097 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,101 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,102 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,135 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,137 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,138 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,139 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,144 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,145 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,173 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,175 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,176 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,178 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,182 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,184 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,215 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,220 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,224 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,251 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,252 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,253 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,257 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,258 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,285 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,286 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,287 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,288 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,292 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,293 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,321 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,322 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,324 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,326 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,330 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,360 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,361 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,363 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,364 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,369 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,396 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,397 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,399 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,400 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,405 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,407 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,435 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,436 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,440 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,441 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,445 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,448 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,475 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,477 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,478 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,479 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,483 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,484 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,511 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,515 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,519 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,520 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,547 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,550 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,550 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,552 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,555 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,557 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,583 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,585 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,586 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,588 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,592 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,595 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,622 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,623 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,625 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,626 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,630 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,631 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,659 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,660 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,662 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,662 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,667 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,667 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,670 [root] DEBUG: 4372: api-cap: LdrLoadDll hook disabled due to count: 5000
2026-05-28 20:41:59,697 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,699 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,701 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,702 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,706 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,708 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,735 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,737 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,739 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,741 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,746 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,748 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,775 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,777 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,778 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,780 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,784 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,785 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,811 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,812 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,814 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,815 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,818 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,820 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,848 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,850 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,852 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,853 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,857 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,859 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,895 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,896 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,897 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,898 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,902 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,903 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,939 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,941 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,947 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,950 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,977 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,978 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:41:59,979 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,981 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:41:59,985 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:41:59,986 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,017 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,019 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,020 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,021 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,025 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,027 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,053 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,055 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,057 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,058 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,062 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,063 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,091 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,093 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,095 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,096 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,099 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,100 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,127 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,128 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,130 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,131 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,135 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,137 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,164 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,166 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,167 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,170 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,173 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,175 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,186 [root] DEBUG: 4372: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5000
2026-05-28 20:42:00,202 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,205 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,206 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,208 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,211 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,212 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,239 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,241 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,242 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,243 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,249 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,277 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,280 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,282 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,284 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,288 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,289 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,327 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,329 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,330 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,332 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,335 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,336 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,363 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,364 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,365 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,367 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,370 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,371 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,399 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,400 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,401 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,403 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,407 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,408 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,434 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,435 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,437 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,439 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,443 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,445 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,474 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,475 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,476 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,477 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,482 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,483 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,509 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,511 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,513 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,514 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,517 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,519 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,547 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,548 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,551 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,553 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,557 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,558 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,569 [root] DEBUG: 4372: api-cap: NtSetInformationProcess hook disabled due to count: 5000
2026-05-28 20:42:00,586 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,587 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,588 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,589 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,593 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,594 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,621 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,624 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,625 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,627 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,630 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,631 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,658 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,659 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,660 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,662 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,665 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,666 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,695 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,697 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,699 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,701 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,704 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,706 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,733 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,735 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,736 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,742 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,743 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,770 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,772 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,773 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,775 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,778 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,780 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,807 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,809 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,810 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,813 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,816 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,817 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,844 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,845 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,847 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,848 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,851 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,852 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,867 [root] DEBUG: 4372: api-cap: NtSetInformationFile hook disabled due to count: 5000
2026-05-28 20:42:00,880 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,881 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,883 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,884 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,887 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,889 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,916 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,918 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,920 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,920 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,923 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,925 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,951 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,952 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:00,992 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,995 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4780000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:42:00,996 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:00,998 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:42:01,001 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:01,003 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:01,031 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:01,032 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:42:01,121 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 27788: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:42:01,124 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 27788
2026-05-28 20:42:01,127 [lib.api.process] INFO: Monitor config for process 27788: C:\_3mo6uuq\dll\27788.ini
2026-05-28 20:42:01,134 [root] DEBUG: 4372: api-cap: NtOpenProcess hook disabled due to count: 5000
2026-05-28 20:42:01,138 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:01,139 [root] DEBUG: 4372: api-cap: NtOpenProcess hook disabled due to count: 5001
2026-05-28 20:42:01,154 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:01,154 [root] DEBUG: 4372: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5000
2026-05-28 20:42:01,157 [root] DEBUG: 4372: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5001
2026-05-28 20:42:01,162 [root] DEBUG: 4372: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5002
2026-05-28 20:42:01,163 [root] DEBUG: 4372: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5004
2026-05-28 20:42:01,169 [root] DEBUG: 4372: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5005
2026-05-28 20:42:01,171 [root] DEBUG: 4372: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5003
2026-05-28 20:42:01,182 [root] DEBUG: Loader: Injecting process 27788 (thread 27792) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:01,183 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:01,184 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:01,186 [lib.api.process] INFO: Injected into 64-bit <Process 27788 dllhost.exe>
2026-05-28 20:42:01,191 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 27788
2026-05-28 20:42:01,192 [lib.api.process] INFO: Monitor config for process 27788: C:\_3mo6uuq\dll\27788.ini
2026-05-28 20:42:01,193 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:01,201 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:01,216 [root] DEBUG: Loader: Injecting process 27788 (thread 27792) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:01,217 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:01,219 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:01,225 [lib.api.process] INFO: Injected into 64-bit <Process 27788 dllhost.exe>
2026-05-28 20:42:01,233 [root] DEBUG: 27788: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:42:01,234 [root] DEBUG: 27788: Interactive desktop enabled.
2026-05-28 20:42:01,238 [root] DEBUG: 27788: Dropped file limit defaulting to 100.
2026-05-28 20:42:01,243 [root] DEBUG: 27788: Disabling sleep skipping.
2026-05-28 20:42:01,245 [root] DEBUG: 27788: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:42:01,259 [root] DEBUG: 27788: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:42:01,260 [root] DEBUG: 27788: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:42:01,261 [root] DEBUG: 27788: Monitor initialised: 64-bit capemon loaded in process 27788 at 0x00007FFEAF1A0000, thread 27792, image base 0x00007FF6868D0000, stack from 0x000000071BB64000-0x000000071BB70000
2026-05-28 20:42:01,263 [root] DEBUG: 27788: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:42:01,279 [root] DEBUG: 27788: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:42:01,306 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:42:01,308 [root] DEBUG: 27788: set_hooks: Unable to hook LockResource
2026-05-28 20:42:01,314 [root] DEBUG: 27788: Hooked 627 out of 628 functions
2026-05-28 20:42:01,316 [root] DEBUG: 27788: Syscall hook installed, syscall logging level 1
2026-05-28 20:42:01,321 [root] DEBUG: 27788: RestoreHeaders: Restored original import table.
2026-05-28 20:42:01,322 [root] INFO: Loaded monitor into process with pid 27788
2026-05-28 20:42:01,323 [root] DEBUG: 27788: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6868D1349, thread 27792).
2026-05-28 20:42:01,326 [root] DEBUG: 27788: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:42:01,335 [root] DEBUG: 27788: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:42:01,339 [root] DEBUG: 27788: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:42:01,341 [root] DEBUG: 27788: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:42:01,346 [root] DEBUG: 27788: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:42:01,370 [root] DEBUG: 27788: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:42:01,389 [root] DEBUG: 27788: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:42:01,390 [root] DEBUG: 27788: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:42:01,400 [root] DEBUG: 27788: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:42:06,517 [root] INFO: Process with pid 27788 has terminated
2026-05-28 20:42:06,519 [root] DEBUG: 27788: NtTerminateProcess hook: Attempting to dump process 27788
2026-05-28 20:42:06,520 [root] DEBUG: 27788: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:08,987 [root] DEBUG: 9668: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:42:13,007 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 28192: C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe, ImageBase: 0x00007FF7E27A0000
2026-05-28 20:42:13,011 [root] INFO: Announced 64-bit process name: platform_experience_helper.exe pid: 28192
2026-05-28 20:42:13,012 [lib.api.process] INFO: Monitor config for process 28192: C:\_3mo6uuq\dll\28192.ini
2026-05-28 20:42:13,015 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:13,022 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:13,026 [root] DEBUG: Loader: Injecting process 28192 (thread 28196) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,027 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:13,029 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,030 [lib.api.process] INFO: Injected into 64-bit <Process 28192 platform_experience_helper.exe>
2026-05-28 20:42:13,036 [root] INFO: Announced 64-bit process name: platform_experience_helper.exe pid: 28192
2026-05-28 20:42:13,037 [lib.api.process] INFO: Monitor config for process 28192: C:\_3mo6uuq\dll\28192.ini
2026-05-28 20:42:13,039 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:13,046 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:13,051 [root] DEBUG: Loader: Injecting process 28192 (thread 28196) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,052 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:13,053 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,055 [lib.api.process] INFO: Injected into 64-bit <Process 28192 platform_experience_helper.exe>
2026-05-28 20:42:13,057 [root] INFO: Announced 64-bit process name: platform_experience_helper.exe pid: 28192
2026-05-28 20:42:13,058 [lib.api.process] INFO: Monitor config for process 28192: C:\_3mo6uuq\dll\28192.ini
2026-05-28 20:42:13,059 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:13,067 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:13,073 [root] DEBUG: Loader: Injecting process 28192 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,075 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 28196, handle 0x120
2026-05-28 20:42:13,077 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:13,079 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,080 [lib.api.process] INFO: Injected into 64-bit <Process 28192 platform_experience_helper.exe>
2026-05-28 20:42:13,090 [root] DEBUG: 28192: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:42:13,091 [root] DEBUG: 28192: Interactive desktop enabled.
2026-05-28 20:42:13,092 [root] DEBUG: 28192: Dropped file limit defaulting to 100.
2026-05-28 20:42:13,106 [root] DEBUG: 28192: Disabling sleep skipping.
2026-05-28 20:42:13,107 [root] DEBUG: 28192: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:42:13,120 [root] DEBUG: 28192: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:42:13,121 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,161 [root] DEBUG: 28192: Monitor initialised: 64-bit capemon loaded in process 28192 at 0x00007FFEAF1A0000, thread 28196, image base 0x00007FF7E27A0000, stack from 0x000000FBFD1A4000-0x000000FBFD1B0000
2026-05-28 20:42:13,163 [root] DEBUG: 28192: Commandline: "C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe"
2026-05-28 20:42:13,172 [root] DEBUG: 28192: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:42:13,195 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:42:13,197 [root] DEBUG: 28192: set_hooks: Unable to hook LockResource
2026-05-28 20:42:13,203 [root] DEBUG: 28192: Hooked 627 out of 628 functions
2026-05-28 20:42:13,225 [root] DEBUG: 28192: Syscall hook installed, syscall logging level 1
2026-05-28 20:42:13,230 [root] DEBUG: 28192: RestoreHeaders: Restored original import table.
2026-05-28 20:42:13,231 [root] INFO: Loaded monitor into process with pid 28192
2026-05-28 20:42:13,234 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,255 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,277 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,300 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,322 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,345 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,370 [root] DEBUG: 28192: caller_dispatch: Added region at 0x00007FF7E27A0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7E2942156, thread 28196).
2026-05-28 20:42:13,371 [root] DEBUG: 28192: YaraScan: Scanning 0x00007FF7E27A0000, size 0x3f6a5c
2026-05-28 20:42:13,396 [root] DEBUG: 28192: ProcessImageBase: Main module image at 0x00007FF7E27A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:42:13,399 [root] DEBUG: 28192: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:42:13,405 [root] DEBUG: 28192: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:42:13,410 [root] DEBUG: 28192: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:42:13,413 [root] DEBUG: 28192: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:42:13,417 [root] DEBUG: 28192: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:42:13,419 [root] DEBUG: 28192: DLL loaded at 0x00007FFEEACF0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:42:13,427 [root] DEBUG: 28192: DLL loaded at 0x00007FFEEE830000: C:\Windows\system32\ntmarta (0x33000 bytes).
2026-05-28 20:42:13,435 [root] DEBUG: 28192: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:42:13,437 [root] DEBUG: 28192: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:42:13,439 [root] DEBUG: 28192: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:42:13,442 [root] DEBUG: 28192: CreateProcessHandler: Injection info set for new process 28484: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF7E0640000
2026-05-28 20:42:13,444 [root] INFO: Announced 64-bit process name: chrome.exe pid: 28484
2026-05-28 20:42:13,445 [lib.api.process] INFO: Monitor config for process 28484: C:\_3mo6uuq\dll\28484.ini
2026-05-28 20:42:13,449 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:13,458 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:13,464 [root] DEBUG: Loader: Injecting process 28484 (thread 28488) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,464 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:13,465 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,467 [lib.api.process] INFO: Injected into 64-bit <Process 28484 chrome.exe>
2026-05-28 20:42:13,469 [root] DEBUG: 28192: DLL loaded at 0x00007FFEECF30000: C:\Windows\system32\apphelp (0x90000 bytes).
2026-05-28 20:42:13,472 [root] INFO: Announced 64-bit process name: chrome.exe pid: 28484
2026-05-28 20:42:13,472 [lib.api.process] INFO: Monitor config for process 28484: C:\_3mo6uuq\dll\28484.ini
2026-05-28 20:42:13,473 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:13,484 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:13,488 [root] DEBUG: Loader: Injecting process 28484 (thread 28488) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,490 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:13,492 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:13,494 [lib.api.process] INFO: Injected into 64-bit <Process 28484 chrome.exe>
2026-05-28 20:42:13,512 [root] DEBUG: 28484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:42:13,513 [root] DEBUG: 28484: Interactive desktop enabled.
2026-05-28 20:42:13,514 [root] DEBUG: 28484: Dropped file limit defaulting to 100.
2026-05-28 20:42:13,521 [root] DEBUG: 28484: Chrome-specific hook-set enabled.
2026-05-28 20:42:13,524 [root] DEBUG: 28484: Disabling sleep skipping.
2026-05-28 20:42:13,526 [root] DEBUG: 28484: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:42:13,538 [root] DEBUG: 28484: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:42:13,540 [root] DEBUG: 28484: Monitor initialised: 64-bit capemon loaded in process 28484 at 0x00007FFEAF1A0000, thread 28488, image base 0x00007FF7E0640000, stack from 0x0000001036DF4000-0x0000001036E00000
2026-05-28 20:42:13,542 [root] DEBUG: 28484: Commandline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=150.0
2026-05-28 20:42:13,552 [root] DEBUG: 28484: Hooked 2 out of 2 functions
2026-05-28 20:42:13,583 [root] DEBUG: 28484: Syscall hook installed, syscall logging level 1
2026-05-28 20:42:13,588 [root] DEBUG: 28484: RestoreHeaders: Restored original import table.
2026-05-28 20:42:13,590 [root] INFO: Loaded monitor into process with pid 28484
2026-05-28 20:42:13,593 [root] DEBUG: 28484: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:42:13,600 [root] DEBUG: 28484: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:42:13,601 [root] DEBUG: 28484: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:42:13,604 [root] DEBUG: 28484: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:42:13,610 [root] INFO: Added new file to list with pid 28192 and path C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
2026-05-28 20:42:13,620 [root] DEBUG: 28192: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:42:13,662 [root] DEBUG: 28192: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:42:13,674 [root] INFO: Added new file to list with pid 28192 and path C:\Users\admin\AppData\Local\Google\Chrome\User Data\PlatformExperienceHelperMetrics\a634adb3-12c4-49bb-b1ea-3f66c508cdb3.tmp
2026-05-28 20:42:13,678 [root] INFO: Error dumping file from path "C:\Users\admin\AppData\Local\Google\Chrome\User Data\PlatformExperienceHelperMetrics\81f036d9-cd3f-4b69-a33f-443a6f3434e6.tmp": [Errno 13] Permission denied: 'C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\PlatformExperienceHelperMetrics\\81f036d9-cd3f-4b69-a33f-443a6f3434e6.tmp'
2026-05-28 20:42:13,680 [root] INFO: Error dumping file from path "C:\Users\admin\AppData\Local\Google\Chrome\User Data\PlatformExperienceHelperMetrics\81f036d9-cd3f-4b69-a33f-443a6f3434e6.tmp": [Errno 13] Permission denied: 'C:\\Users\\admin\\AppData\\Local\\Google\\Chrome\\User Data\\PlatformExperienceHelperMetrics\\81f036d9-cd3f-4b69-a33f-443a6f3434e6.tmp'
2026-05-28 20:42:13,690 [root] DEBUG: 28192: NtTerminateProcess hook: Attempting to dump process 28192
2026-05-28 20:42:13,692 [root] DEBUG: 28192: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:13,703 [root] INFO: Process with pid 28192 has terminated
2026-05-28 20:42:13,708 [root] INFO: Process with pid 28192 has terminated
2026-05-28 20:42:13,709 [root] DEBUG: 28484: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:42:14,070 [root] INFO: Process with pid 28484 appears to have terminated
2026-05-28 20:42:25,899 [root] DEBUG: 4372: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:42:25,900 [root] DEBUG: 4372: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:42:25,905 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 27956: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF668B30000
2026-05-28 20:42:25,907 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 27956
2026-05-28 20:42:25,910 [lib.api.process] INFO: Monitor config for process 27956: C:\_3mo6uuq\dll\27956.ini
2026-05-28 20:42:25,912 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:25,922 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:25,927 [root] DEBUG: Loader: Injecting process 27956 (thread 28048) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:25,929 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:25,933 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:25,935 [lib.api.process] INFO: Injected into 64-bit <Process 27956 SecurityHealthHost.exe>
2026-05-28 20:42:25,941 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 27956
2026-05-28 20:42:25,943 [lib.api.process] INFO: Monitor config for process 27956: C:\_3mo6uuq\dll\27956.ini
2026-05-28 20:42:25,944 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:25,959 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:25,963 [root] DEBUG: Loader: Injecting process 27956 (thread 28048) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:25,964 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:25,966 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:25,968 [lib.api.process] INFO: Injected into 64-bit <Process 27956 SecurityHealthHost.exe>
2026-05-28 20:42:25,976 [root] DEBUG: 27956: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:42:25,978 [root] DEBUG: 27956: Interactive desktop enabled.
2026-05-28 20:42:25,980 [root] DEBUG: 27956: Dropped file limit defaulting to 100.
2026-05-28 20:42:25,986 [root] DEBUG: 27956: Disabling sleep skipping.
2026-05-28 20:42:25,988 [root] DEBUG: 27956: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:42:26,000 [root] DEBUG: 27956: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:42:26,002 [root] DEBUG: 27956: YaraScan: Scanning 0x00007FF668B30000, size 0x19174
2026-05-28 20:42:26,005 [root] DEBUG: 27956: Monitor initialised: 64-bit capemon loaded in process 27956 at 0x00007FFEAF1A0000, thread 28048, image base 0x00007FF668B30000, stack from 0x000000209FC84000-0x000000209FC90000
2026-05-28 20:42:26,007 [root] DEBUG: 27956: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 20:42:26,018 [root] DEBUG: 27956: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:42:26,038 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:42:26,042 [root] DEBUG: 27956: set_hooks: Unable to hook LockResource
2026-05-28 20:42:26,047 [root] DEBUG: 27956: Hooked 627 out of 628 functions
2026-05-28 20:42:26,050 [root] DEBUG: 27956: Syscall hook installed, syscall logging level 1
2026-05-28 20:42:26,058 [root] DEBUG: 27956: RestoreHeaders: Restored original import table.
2026-05-28 20:42:26,058 [root] INFO: Loaded monitor into process with pid 27956
2026-05-28 20:42:26,061 [root] DEBUG: 27956: caller_dispatch: Added region at 0x00007FF668B30000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF668B3D3B2, thread 28048).
2026-05-28 20:42:26,062 [root] DEBUG: 27956: YaraScan: Scanning 0x00007FF668B30000, size 0x19174
2026-05-28 20:42:26,064 [root] DEBUG: 27956: ProcessImageBase: Main module image at 0x00007FF668B30000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:42:26,068 [root] DEBUG: 27956: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:42:26,071 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:42:26,075 [root] DEBUG: 27956: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:42:26,091 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEF080000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 20:42:26,093 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:42:26,095 [root] DEBUG: 27956: DLL loaded at 0x00007FFED5250000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 20:42:26,109 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:42:26,113 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEAA90000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 20:42:26,121 [root] DEBUG: 27956: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:42:26,122 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:42:26,123 [root] DEBUG: 27956: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:42:26,127 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:42:26,128 [root] DEBUG: 27956: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:42:26,130 [root] DEBUG: 27956: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:42:26,134 [root] DEBUG: 27956: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:42:26,143 [root] DEBUG: 27956: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:42:26,151 [root] DEBUG: 27956: DLL loaded at 0x00007FFED5C90000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 20:42:26,178 [root] DEBUG: 27956: NtTerminateProcess hook: Attempting to dump process 27956
2026-05-28 20:42:26,180 [root] DEBUG: 27956: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:26,190 [root] INFO: Process with pid 27956 has terminated
2026-05-28 20:42:26,213 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 3332: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF648C80000
2026-05-28 20:42:26,216 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 3332
2026-05-28 20:42:26,218 [lib.api.process] INFO: Monitor config for process 3332: C:\_3mo6uuq\dll\3332.ini
2026-05-28 20:42:26,220 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:27,846 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:27,851 [root] DEBUG: Loader: Injecting process 3332 (thread 17068) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:27,853 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:27,855 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:27,857 [lib.api.process] INFO: Injected into 64-bit <Process 3332 ShellExperienceHost.exe>
2026-05-28 20:42:27,861 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 3332
2026-05-28 20:42:27,863 [lib.api.process] INFO: Monitor config for process 3332: C:\_3mo6uuq\dll\3332.ini
2026-05-28 20:42:27,864 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:28,031 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 28048: C:\Windows\system32\wermgr.exe, ImageBase: 0x00007FF6845A0000
2026-05-28 20:42:28,040 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 28048
2026-05-28 20:42:28,042 [lib.api.process] INFO: Monitor config for process 28048: C:\_3mo6uuq\dll\28048.ini
2026-05-28 20:42:28,048 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:28,056 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:28,062 [root] DEBUG: Loader: Injecting process 28048 (thread 9084) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:28,066 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:28,067 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:28,068 [lib.api.process] INFO: Injected into 64-bit <Process 28048 wermgr.exe>
2026-05-28 20:42:28,071 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 28048
2026-05-28 20:42:28,072 [lib.api.process] INFO: Monitor config for process 28048: C:\_3mo6uuq\dll\28048.ini
2026-05-28 20:42:28,074 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:28,088 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:28,096 [root] DEBUG: Loader: Injecting process 28048 (thread 9084) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:28,097 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:28,099 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:28,102 [lib.api.process] INFO: Injected into 64-bit <Process 28048 wermgr.exe>
2026-05-28 20:42:28,104 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 28048
2026-05-28 20:42:28,108 [lib.api.process] INFO: Monitor config for process 28048: C:\_3mo6uuq\dll\28048.ini
2026-05-28 20:42:28,110 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:28,120 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:28,126 [root] DEBUG: Loader: Injecting process 28048 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:28,128 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9084, handle 0x120
2026-05-28 20:42:28,130 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:28,132 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:28,133 [lib.api.process] INFO: Injected into 64-bit <Process 28048 wermgr.exe>
2026-05-28 20:42:28,143 [root] DEBUG: 28048: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:42:28,145 [root] DEBUG: 28048: Interactive desktop enabled.
2026-05-28 20:42:28,147 [root] DEBUG: 28048: Dropped file limit defaulting to 100.
2026-05-28 20:42:28,152 [root] DEBUG: 28048: Disabling sleep skipping.
2026-05-28 20:42:28,155 [root] DEBUG: 28048: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 20:42:28,172 [root] DEBUG: 28048: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:42:28,174 [root] DEBUG: 28048: YaraScan: Scanning 0x00007FF6845A0000, size 0x3f17e
2026-05-28 20:42:28,177 [root] DEBUG: 28048: Monitor initialised: 64-bit capemon loaded in process 28048 at 0x00007FFEAF1A0000, thread 9084, image base 0x00007FF6845A0000, stack from 0x000000D0BD4A4000-0x000000D0BD4B0000
2026-05-28 20:42:28,180 [root] DEBUG: 28048: Commandline: "C:\Windows\system32\wermgr.exe" -upload
2026-05-28 20:42:28,191 [root] DEBUG: 28048: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:42:28,214 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:42:28,217 [root] DEBUG: 28048: set_hooks: Unable to hook LockResource
2026-05-28 20:42:28,222 [root] DEBUG: 28048: Hooked 627 out of 628 functions
2026-05-28 20:42:28,225 [root] DEBUG: 28048: Syscall hook installed, syscall logging level 1
2026-05-28 20:42:28,232 [root] DEBUG: 28048: RestoreHeaders: Restored original import table.
2026-05-28 20:42:28,234 [root] INFO: Loaded monitor into process with pid 28048
2026-05-28 20:42:28,236 [root] DEBUG: 28048: caller_dispatch: Added region at 0x00007FF6845A0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6845B9181, thread 9084).
2026-05-28 20:42:28,238 [root] DEBUG: 28048: YaraScan: Scanning 0x00007FF6845A0000, size 0x3f17e
2026-05-28 20:42:28,240 [root] DEBUG: 28048: ProcessImageBase: Main module image at 0x00007FF6845A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:42:28,244 [root] DEBUG: 28048: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 20:42:28,251 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,254 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,258 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,259 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,264 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,265 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,275 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:42:28,284 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,285 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,290 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,291 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,299 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,302 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,318 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,322 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,327 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,329 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,333 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,335 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,340 [root] DEBUG: 28048: DLL loaded at 0x00007FFEF1540000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:42:28,344 [root] DEBUG: 28048: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:42:28,346 [root] DEBUG: 28048: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:42:28,349 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:42:28,358 [root] DEBUG: 28048: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:42:28,366 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,368 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,372 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,374 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,379 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,381 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,390 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,391 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,394 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,396 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,400 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,403 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,416 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,418 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,423 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,425 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,431 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,433 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,443 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,445 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,449 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,451 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,459 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,461 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,484 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,486 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,492 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,494 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,498 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:42:28,502 [root] DEBUG: 28048: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:42:28,508 [root] DEBUG: 28048: NtTerminateProcess hook: Attempting to dump process 28048
2026-05-28 20:42:28,510 [root] DEBUG: 28048: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:28,520 [root] INFO: Process with pid 28048 has terminated
2026-05-28 20:42:28,525 [root] INFO: Process with pid 28048 has terminated
2026-05-28 20:42:30,082 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:30,090 [root] DEBUG: Loader: Injecting process 3332 (thread 17068) with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:30,092 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:42:30,093 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:30,096 [lib.api.process] INFO: Injected into 64-bit <Process 3332 ShellExperienceHost.exe>
2026-05-28 20:42:30,119 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 3332
2026-05-28 20:42:30,123 [lib.api.process] INFO: Monitor config for process 3332: C:\_3mo6uuq\dll\3332.ini
2026-05-28 20:42:30,124 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:42:32,196 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 29208: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:42:32,198 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\injector.vcxproj.user
2026-05-28 20:42:32,207 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 29208
2026-05-28 20:42:32,212 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 29232: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:42:32,216 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 29208
2026-05-28 20:42:32,220 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 29232
2026-05-28 20:42:32,223 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 29232
2026-05-28 20:42:32,258 [root] DEBUG: 7496: CreateProcessHandler: Injection info set for new process 29304: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:42:32,260 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 29304
2026-05-28 20:42:32,262 [root] DEBUG: 7496: ProcessMessage: Skipping monitoring process 29304
2026-05-28 20:42:32,774 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\lbpkzk.dll, loader C:\_3mo6uuq\bin\VkwUsjmY.exe
2026-05-28 20:42:32,780 [root] DEBUG: Loader: Injecting process 3332 with C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:32,780 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17068, handle 0x124
2026-05-28 20:42:32,782 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:42:32,783 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\lbpkzk.dll.
2026-05-28 20:42:32,785 [lib.api.process] INFO: Injected into 64-bit <Process 3332 ShellExperienceHost.exe>
2026-05-28 20:42:35,744 [root] DEBUG: 7496: DLL loaded at 0x00007FFED5170000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes).
2026-05-28 20:42:35,754 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE61A0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 20:42:35,755 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE5430000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 20:42:35,759 [root] DEBUG: 7496: DLL loaded at 0x00007FFEDE9E0000: C:\Windows\SYSTEM32\FLTLIB (0xb000 bytes).
2026-05-28 20:42:35,761 [root] DEBUG: 7496: DLL loaded at 0x00007FFEEC8E0000: C:\Windows\SYSTEM32\virtdisk (0x13000 bytes).
2026-05-28 20:42:35,764 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE40A0000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 20:42:35,766 [root] DEBUG: 7496: DLL loaded at 0x00007FFED0380000: C:\Windows\SYSTEM32\shdocvw (0x41000 bytes).
2026-05-28 20:42:35,768 [root] DEBUG: 7496: DLL loaded at 0x00007FFEECF30000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 20:42:35,777 [root] DEBUG: 7496: DLL loaded at 0x00007FFEE88C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 20:42:35,907 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDCD80000: C:\Windows\System32\Windows.System.Launcher (0xbd000 bytes).
2026-05-28 20:42:35,908 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDCD80000: C:\Windows\System32\Windows.System.Launcher (0xbd000 bytes).
2026-05-28 20:42:51,164 [root] DEBUG: 4372: api-cap: PostMessageW hook disabled due to count: 5001
2026-05-28 20:42:51,164 [root] DEBUG: 4372: api-cap: PostMessageW hook disabled due to count: 5000
2026-05-28 20:42:52,655 [root] INFO: Analysis timeout hit, terminating analysis
2026-05-28 20:42:52,656 [lib.api.process] INFO: Terminate event set for process 7496
2026-05-28 20:42:52,657 [root] DEBUG: 7496: Terminate Event: Attempting to dump process 7496
2026-05-28 20:42:52,660 [root] DEBUG: 7496: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,674 [lib.api.process] INFO: Termination confirmed for process 7496
2026-05-28 20:42:52,674 [root] DEBUG: 7496: Terminate Event: monitor shutdown complete for process 7496
2026-05-28 20:42:52,676 [root] INFO: Terminate event set for process 7496
2026-05-28 20:42:52,678 [lib.api.process] INFO: Terminate event set for process 848
2026-05-28 20:42:52,678 [root] DEBUG: 848: Terminate Event: Attempting to dump process 848
2026-05-28 20:42:52,680 [root] DEBUG: 848: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,681 [lib.api.process] INFO: Termination confirmed for process 848
2026-05-28 20:42:52,682 [root] DEBUG: 848: Terminate Event: monitor shutdown complete for process 848
2026-05-28 20:42:52,683 [root] INFO: Terminate event set for process 848
2026-05-28 20:42:52,686 [root] DEBUG: 9668: Terminate Event: Attempting to dump process 9668
2026-05-28 20:42:52,686 [lib.api.process] INFO: Terminate event set for process 9668
2026-05-28 20:42:52,687 [root] DEBUG: 9668: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,695 [root] DEBUG: 9668: DumpPEsInRange: Scanning range 0x00007DF49E260000 - 0x00007DF49E2614E0.
2026-05-28 20:42:52,696 [root] DEBUG: 9668: ScanForDisguisedPE: No PE image located in range 0x00007DF49E260000-0x00007DF49E2614E0.
2026-05-28 20:42:52,708 [lib.common.results] INFO: Uploading file C:\QJqaJqCEA\CAPE\9668_280855242029552026 to CAPE\388f8d731de1c3ddcafe8694620a427294f7446cfa4e4f5c79e32c0efc34b793; Size is 5344; Max size: 100000000
2026-05-28 20:42:52,715 [root] DEBUG: 9668: DumpMemory: Payload successfully created: C:\QJqaJqCEA\CAPE\9668_280855242029552026 (size 5344 bytes)
2026-05-28 20:42:52,717 [root] DEBUG: 9668: DumpRegion: Dumped entire allocation from 0x00007DF49E260000, size 8192 bytes.
2026-05-28 20:42:52,719 [root] DEBUG: 9668: ProcessTrackedRegion: Dumped region at 0x00007DF49E260000.
2026-05-28 20:42:52,721 [root] DEBUG: 9668: YaraScan: Scanning 0x00007DF49E260000, size 0x14e0
2026-05-28 20:42:52,722 [lib.api.process] INFO: Termination confirmed for process 9668
2026-05-28 20:42:52,722 [root] DEBUG: 9668: Terminate Event: monitor shutdown complete for process 9668
2026-05-28 20:42:52,723 [root] INFO: Terminate event set for process 9668
2026-05-28 20:42:52,726 [lib.api.process] INFO: Terminate event set for process 9596
2026-05-28 20:42:52,727 [lib.api.process] INFO: Termination confirmed for process 9596
2026-05-28 20:42:52,727 [root] INFO: Terminate event set for process 9596
2026-05-28 20:42:52,728 [lib.api.process] INFO: Terminate event set for process 4372
2026-05-28 20:42:52,730 [root] DEBUG: 4372: Terminate Event: Attempting to dump process 4372
2026-05-28 20:42:52,739 [root] DEBUG: 4372: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,782 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\injector.vcxproj.filters:Zone.Identifier
2026-05-28 20:42:52,785 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\grum\msobj80.dll
2026-05-28 20:42:52,793 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\grum\resources\func_createthread.h:Zone.Identifier
2026-05-28 20:42:52,795 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\grum\ntdll.h:Zone.Identifier
2026-05-28 20:42:52,808 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\ntdll.h
2026-05-28 20:42:52,819 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\msobj80.dll:Zone.Identifier
2026-05-28 20:42:52,836 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\Downloads\Grum\grum\grum\main.cpp:Zone.Identifier
2026-05-28 20:42:52,846 [root] DEBUG: 4372: Dropped file limit reached.
2026-05-28 20:42:52,849 [lib.api.process] INFO: Termination confirmed for process 4372
2026-05-28 20:42:52,850 [root] DEBUG: 4372: Terminate Event: monitor shutdown complete for process 4372
2026-05-28 20:42:52,850 [root] INFO: Terminate event set for process 4372
2026-05-28 20:42:52,853 [lib.api.process] INFO: Terminate event set for process 10752
2026-05-28 20:42:52,855 [root] DEBUG: 10752: Terminate Event: Attempting to dump process 10752
2026-05-28 20:42:52,857 [root] DEBUG: 10752: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,862 [lib.api.process] INFO: Termination confirmed for process 10752
2026-05-28 20:42:52,863 [root] INFO: Terminate event set for process 10752
2026-05-28 20:42:52,864 [root] DEBUG: 10752: Terminate Event: monitor shutdown complete for process 10752
2026-05-28 20:42:52,868 [lib.api.process] INFO: Terminate event set for process 1212
2026-05-28 20:42:52,870 [root] DEBUG: 1212: Terminate Event: Attempting to dump process 1212
2026-05-28 20:42:52,873 [root] DEBUG: 1212: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,875 [root] INFO: Added new file to list with pid 1212 and path C:\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache
2026-05-28 20:42:52,880 [root] INFO: Added new file to list with pid 1212 and path C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
2026-05-28 20:42:52,900 [root] INFO: Added new file to list with pid 1212 and path C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work
2026-05-28 20:42:52,919 [root] INFO: Added new file to list with pid 1212 and path C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work
2026-05-28 20:42:52,929 [root] INFO: Added new file to list with pid 1212 and path C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work
2026-05-28 20:42:52,943 [lib.api.process] INFO: Termination confirmed for process 1212
2026-05-28 20:42:52,944 [root] INFO: Terminate event set for process 1212
2026-05-28 20:42:52,945 [root] DEBUG: 1212: Terminate Event: monitor shutdown complete for process 1212
2026-05-28 20:42:52,946 [lib.api.process] INFO: Terminate event set for process 1128
2026-05-28 20:42:52,947 [root] DEBUG: 1128: Terminate Event: Attempting to dump process 1128
2026-05-28 20:42:52,949 [root] DEBUG: 1128: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:42:52,951 [lib.api.process] INFO: Termination confirmed for process 1128
2026-05-28 20:42:52,952 [root] DEBUG: 1128: Terminate Event: monitor shutdown complete for process 1128
2026-05-28 20:42:52,953 [root] INFO: Terminate event set for process 1128
2026-05-28 20:42:52,955 [root] INFO: Created shutdown mutex
2026-05-28 20:42:53,964 [root] INFO: Shutting down package
2026-05-28 20:42:53,965 [root] INFO: Stopping auxiliary modules
2026-05-28 20:42:53,965 [root] INFO: Stopping auxiliary module: Browser
2026-05-28 20:42:53,966 [root] INFO: Stopping auxiliary module: Human
2026-05-28 20:42:53,967 [root] INFO: Stopping auxiliary module: Screenshots
2026-05-28 20:42:53,968 [root] INFO: Finishing auxiliary modules
2026-05-28 20:42:53,969 [root] INFO: Shutting down pipe server and dumping dropped files
2026-05-28 20:42:53,970 [root] WARNING: File at path c:\users\admin\appdata\roaming\microsoft\windows\recent\customdestinations\36v4gaxvf4p4eyj30m8g.temp does not exist, skipping
2026-05-28 20:42:53,973 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f18460fded109990.customDestinations-ms to files\90bf6baa6f968a285f88620fbf91e1f5aa3e66e2bad50fd16f37913280ad8228; Size is 24; Max size: 100000000
2026-05-28 20:42:53,980 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db to files\232bae7ac25c78f64250ec50a9cab979b287fdbe6f897445500fb362fe76191b; Size is 58320; Max size: 100000000
2026-05-28 20:42:53,988 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db to files\b749a7ef60d7fee33f9f2676a005e79db40441224499494fc75558a89d1d1cea; Size is 1048576; Max size: 100000000
2026-05-28 20:42:53,997 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db to files\63f81b84e4d17d06edfd162290a835080e3f962f0558b4b965d395f160c49fae; Size is 14688; Max size: 100000000
2026-05-28 20:42:54,006 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db to files\c6644555c4e579451f74d4843be40d2df30e9937bafb122dafa9ced8fc306100; Size is 1048576; Max size: 100000000
2026-05-28 20:42:54,015 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db to files\9779e67fd4db6b6fabab9e92a936108f52c59a3f9c06fe70595b3c1f2e0f088e; Size is 1048576; Max size: 100000000
2026-05-28 20:42:54,024 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Discord\app.ico to files\dfcea1bea8a924252d507d0316d8cf38efc61cf1314e47dca3eb723f47d5fe43; Size is 285478; Max size: 100000000
2026-05-28 20:42:54,030 [lib.common.results] INFO: Uploading file c:\users\admin\appdata\local\microsoft\onedrive\logs\common\filecoauth-2026-05-29.0040.15832.1.odl to files\22ffb0c3346e15ad0e9e5cb8229ac9317e603670522a812b4b3c2310688f6400; Size is 2671; Max size: 100000000
2026-05-28 20:42:54,054 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db to files\9c6201ce7a89cd19e607d9e43db09c2fdfc81e7a54576baf775cb0e91ed24fe9; Size is 8138752; Max size: 100000000
2026-05-28 20:42:54,070 [lib.common.results] INFO: Uploading file C:\ProgramData\USOShared\Logs\System\WuProvider.66c45947-6c78-4452-9c65-bebfe7903b50.1.etl to files\58c190cb786ddb6f26c6e61451f6d19b530040eb6fa80600d87425a175203d10; Size is 4096; Max size: 100000000
2026-05-28 20:42:54,080 [lib.common.results] INFO: Uploading file C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.56a529bd-084b-44db-b3c8-67bf99008ac1.1.etl to files\7c064bfcc11f333595a5cf1c8d2b0aa6d16168205676b2eea2a5cb223a88f710; Size is 53248; Max size: 100000000
2026-05-28 20:42:54,088 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat to files\1779bbd33b0c88c0a1172a2d48609b1806b80160262ce9d0db46b8cfd882b993; Size is 40; Max size: 100000000
2026-05-28 20:42:54,095 [lib.common.results] INFO: Uploading file c:\users\admin\appdata\local\google\chrome\user data\platformexperiencehelpermetrics\28192_13424488933668819.pma to files\316a47ec7b46ea55015bea97dcaa1f233494b20289ed72f1a216e921ef912150; Size is 1104; Max size: 100000000
2026-05-28 20:42:54,102 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\injector.vcxproj.user to files\f2f2e1ebb09bb88b3bc3f57677a31e0ae1b50cad9d5826e00d6b2fcff887974f; Size is 143; Max size: 100000000
2026-05-28 20:42:54,110 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\injector.vcxproj.filters:Zone.Identifier to files\5cbca1a8b5ee174d1f0004e9f84d091a009f3391bbd61acb256595fbbd9e5867; Size is 73; Max size: 100000000
2026-05-28 20:42:54,119 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\grum\msobj80.dll to files\803d06c37d7296bf9f2a9c34eb7bebae218b5f12c18d1dd110eaaa5d323c8268; Size is 57856; Max size: 100000000
2026-05-28 20:42:54,127 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\grum\resources\func_createthread.h:Zone.Identifier to files\5cbca1a8b5ee174d1f0004e9f84d091a009f3391bbd61acb256595fbbd9e5867; Size is 73; Max size: 100000000
2026-05-28 20:42:54,132 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\grum\ntdll.h:Zone.Identifier to files\5cbca1a8b5ee174d1f0004e9f84d091a009f3391bbd61acb256595fbbd9e5867; Size is 73; Max size: 100000000
2026-05-28 20:42:54,138 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\ntdll.h to files\eeb4456682cc3a8eff37021b84d8de7b0fb1a2aa69c9aebcdb4332c289eb2860; Size is 24802; Max size: 100000000
2026-05-28 20:42:54,146 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\msobj80.dll:Zone.Identifier to files\5cbca1a8b5ee174d1f0004e9f84d091a009f3391bbd61acb256595fbbd9e5867; Size is 73; Max size: 100000000
2026-05-28 20:42:54,150 [lib.common.results] INFO: Uploading file C:\Users\admin\Downloads\Grum\grum\grum\main.cpp:Zone.Identifier to files\5cbca1a8b5ee174d1f0004e9f84d091a009f3391bbd61acb256595fbbd9e5867; Size is 73; Max size: 100000000
2026-05-28 20:42:54,154 [lib.common.results] INFO: Uploading file C:\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache to files\5ee5780910ce91d45aa4498ec298f20fd603fa70374943c7c18dadb53d41d346; Size is 4482; Max size: 100000000
2026-05-28 20:42:54,164 [lib.common.results] INFO: Uploading file C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask to files\481a725999c0091e9e68f83518e1f6530ca92e25e57fa40a0831717ba92e5447; Size is 4680; Max size: 100000000
2026-05-28 20:42:54,168 [lib.common.results] INFO: Uploading file C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work to files\dff8902430dcae2fba05fc7f54157c4bc8a7445ed488c1d5727947a0c07075d6; Size is 3116; Max size: 100000000
2026-05-28 20:42:54,175 [lib.common.results] INFO: Uploading file C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work to files\acade97e8a1d30477d0dc3fdfea70c2c617c369b56115ec708ed8a2cfdbc3692; Size is 3086; Max size: 100000000
2026-05-28 20:42:54,184 [lib.common.results] INFO: Uploading file C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work to files\c520ceb2ab34497fba412471877cc761d160eecc642e17c378e6ce6412ce8532; Size is 3358; Max size: 100000000
2026-05-28 20:42:54,190 [root] WARNING: Folder at path "C:\QJqaJqCEA\debugger" does not exist, skipping
2026-05-28 20:42:54,190 [root] WARNING: Folder at path "C:\QJqaJqCEA\tlsdump" does not exist, skipping
2026-05-28 20:42:55,529 [root] WARNING: Monitor injection attempted but failed for process 1180
2026-05-28 20:42:55,530 [root] WARNING: Monitor injection attempted but failed for process 9712
2026-05-28 20:42:55,531 [root] WARNING: Monitor injection attempted but failed for process 8972
2026-05-28 20:42:55,533 [root] WARNING: Monitor injection attempted but failed for process 3332
2026-05-28 20:42:55,536 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 20:39:13 | 2026-05-28 20:42:57 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 185.199.110.133 [VT] | unknown | - |
| N | 185.199.111.215 [VT] | unknown | - |
| N | 23.211.116.176 [VT] | unknown | - |
| Y | 13.107.213.31 [VT] | unknown | - |
| Y | 150.171.28.12 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 150.171.109.24 [VT] | unknown | - |
| Y | 172.172.255.216 [VT] | unknown | - |
| Y | 162.159.128.235 [VT] | unknown | - |
| Y | 23.209.40.114 [VT] | unknown | - |
| Y | 140.82.114.21 [VT] | unknown | - |
| Y | 162.159.128.233 [VT] | unknown | - |
| N | 162.159.136.234 [VT] | unknown | - |
| N | 162.159.130.234 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 23.202.165.41 [VT] | unknown | - |
| N | 4.237.22.34 [VT] | unknown | - |
| N | 140.82.113.22 [VT] | unknown | - |
| Y | 162.159.61.3 [VT] | unknown | - |
| Y | 162.159.130.233 [VT] | unknown | - |
| N | 185.199.109.133 [VT] | unknown | - |
| N | 185.199.108.133 [VT] | unknown | - |
| N | 185.199.110.215 [VT] | unknown | - |
| N | 4.237.22.38 [VT] | unknown | - |
| Y | 162.159.134.233 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 20.190.167.20 [VT] | unknown | - |
| Y | 162.254.194.57 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.155
[VT]
A 149.135.84.160 [VT] |
23.62.157.110 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| github.com [VT] | A 4.237.22.38 [VT] | 4.237.22.38 [VT] |
| github.githubassets.com [VT] |
A 185.199.108.215
[VT]
A 185.199.111.215 [VT] A 185.199.110.215 [VT] A 185.199.109.215 [VT] |
185.199.108.215 [VT] |
| camo.githubusercontent.com [VT] |
A 185.199.109.133
[VT]
A 185.199.110.133 [VT] A 185.199.111.133 [VT] A 185.199.108.133 [VT] |
185.199.111.133 [VT] |
| avatars.githubusercontent.com [VT] | 185.199.110.133 [VT] | |
| user-images.githubusercontent.com [VT] | 185.199.109.133 [VT] | |
| github-cloud.s3.amazonaws.com [VT] |
A 52.217.142.161
[VT]
A 54.231.164.217 [VT] A 52.217.171.25 [VT] A 16.15.229.151 [VT] A 54.231.232.225 [VT] A 52.216.49.105 [VT] A 16.15.229.14 [VT] CNAME s3-1-w.amazonaws.com [VT] A 52.216.218.41 [VT] CNAME s3-w.us-east-1.amazonaws.com [VT] |
16.15.229.131 [VT] |
| raw.githubusercontent.com [VT] | 185.199.109.133 [VT] | |
| collector.github.com [VT] |
CNAME glb-db52c2cf8be544.github.com
[VT]
A 140.82.113.22 [VT] |
140.82.112.21 [VT] |
| api.github.com [VT] | A 4.237.22.34 [VT] | 4.237.22.34 [VT] |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| gateway-us-east1-d.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.134.234 [VT] |
| client-update.akamai.steamstatic.com [VT] |
A 23.211.116.162
[VT]
CNAME client-update.akamai.steamstatic.com.akamaized.net [VT] CNAME a78.dscw27.akamai.net [VT] A 23.211.116.176 [VT] |
23.45.168.193 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.