| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-29 04:59:36 | 2026-05-29 05:03:13 | 217s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:55:31,007 [root] INFO: Date set to: 20260529T04:59:42, timeout set to: 600
2026-05-29 04:59:42,009 [root] DEBUG: Starting analyzer from: C:\lpw_albt
2026-05-29 04:59:42,009 [root] DEBUG: Storing results at: C:\zDtLzmEP
2026-05-29 04:59:42,010 [root] DEBUG: Pipe server name: \\.\PIPE\IMxzQK
2026-05-29 04:59:42,010 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-29 04:59:42,010 [root] INFO: analysis running as an admin
2026-05-29 04:59:42,010 [root] INFO: analysis package specified: "edge"
2026-05-29 04:59:42,010 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-29 04:59:42,022 [root] DEBUG: imported analysis package "edge"
2026-05-29 04:59:42,022 [root] DEBUG: initializing analysis package "edge"...
2026-05-29 04:59:42,023 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-29 04:59:42,023 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-29 04:59:42,023 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-29 04:59:42,023 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-29 04:59:42,023 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-29 04:59:42,120 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-29 04:59:42,147 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-29 04:59:42,163 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-29 04:59:42,173 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-29 04:59:42,194 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-29 04:59:42,196 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-29 04:59:42,201 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-29 04:59:42,206 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-29 04:59:42,207 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-29 04:59:42,207 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-29 04:59:42,207 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-29 04:59:42,208 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-29 04:59:42,211 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-29 04:59:42,212 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-29 04:59:42,212 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-29 04:59:42,213 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-29 04:59:42,213 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-29 04:59:42,213 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-29 04:59:42,214 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-29 04:59:42,214 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-29 04:59:42,215 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-29 04:59:42,216 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-29 04:59:42,218 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-29 04:59:42,231 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 8444)
2026-05-29 04:59:42,232 [modules.auxiliary.disguise] INFO: Disguising GUID to bbb2e3fe-8250-4191-b9a0-25fa3f6af8d7
2026-05-29 04:59:42,232 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-29 04:59:42,232 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-29 04:59:42,233 [root] DEBUG: attempting to configure 'Human' from data
2026-05-29 04:59:42,234 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-29 04:59:42,234 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-29 04:59:42,235 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-29 04:59:42,235 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-29 04:59:42,236 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-29 04:59:42,236 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-29 04:59:42,236 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-29 04:59:42,236 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-29 04:59:42,236 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-29 04:59:42,237 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-29 04:59:42,237 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-29 04:59:42,237 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-29 04:59:42,237 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-29 04:59:42,239 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-29 04:59:42,239 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-29 04:59:42,240 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-29 04:59:42,327 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-29 04:59:42,328 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 04:59:42,330 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 04:59:42,398 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:42,569 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 04:59:42,571 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-29 04:59:42,572 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-29 04:59:42,575 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-29 04:59:42,578 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-29 04:59:42,606 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-29 04:59:42,609 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 04:59:42,693 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 04:59:42,695 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-29 04:59:42,779 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF18250000, thread 3724, image base 0x00007FF79BC10000, stack from 0x0000000009001000-0x0000000009010000
2026-05-29 04:59:42,780 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-29 04:59:42,793 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-29 04:59:42,824 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-29 04:59:42,833 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-29 04:59:42,833 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:42,834 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-29 04:59:43,518 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF79BD27BE7, thread 4696).
2026-05-29 04:59:43,519 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-29 04:59:43,552 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-29 04:59:49,938 [root] INFO: Restarting WMI Service
2026-05-29 04:59:49,948 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-29 04:59:49,949 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-29 04:59:49,949 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-29 04:59:49,952 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 7772
2026-05-29 04:59:49,953 [lib.api.process] INFO: Monitor config for process 7772: C:\lpw_albt\dll\7772.ini
2026-05-29 04:59:49,955 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 04:59:49,956 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 04:59:49,960 [root] DEBUG: Loader: Injecting process 7772 (thread 1020) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:49,961 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 04:59:49,961 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:49,962 [lib.api.process] INFO: Injected into 64-bit <Process 7772 msedge.exe>
2026-05-29 04:59:51,965 [lib.api.process] INFO: Successfully resumed process with pid 7772
2026-05-29 04:59:52,091 [root] DEBUG: 7772: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 04:59:52,093 [root] DEBUG: 7772: Disabling sleep skipping.
2026-05-29 04:59:52,094 [root] DEBUG: 7772: Interactive desktop enabled.
2026-05-29 04:59:52,095 [root] DEBUG: 7772: Dropped file limit defaulting to 100.
2026-05-29 04:59:52,105 [root] DEBUG: 7772: Edge-specific hook-set enabled.
2026-05-29 04:59:52,110 [root] DEBUG: 7772: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 04:59:52,125 [root] DEBUG: 7772: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 04:59:52,126 [root] DEBUG: 7772: Monitor initialised: 64-bit capemon loaded in process 7772 at 0x00007FFF18250000, thread 1020, image base 0x00007FF7F5380000, stack from 0x000000885E7F4000-0x000000885E800000
2026-05-29 04:59:52,126 [root] DEBUG: 7772: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-29 04:59:52,143 [root] DEBUG: 7772: Hooked 2 out of 2 functions
2026-05-29 04:59:52,180 [root] DEBUG: 7772: Syscall hook installed, syscall logging level 1
2026-05-29 04:59:52,184 [root] DEBUG: 7772: RestoreHeaders: Restored original import table.
2026-05-29 04:59:52,186 [root] INFO: Loaded monitor into process with pid 7772
2026-05-29 04:59:52,190 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-29 04:59:52,228 [root] DEBUG: 7772: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-29 04:59:52,236 [root] DEBUG: 7772: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 04:59:52,238 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-29 04:59:52,239 [root] DEBUG: 7772: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 04:59:52,241 [root] DEBUG: 7772: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-29 04:59:52,242 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 04:59:52,398 [root] DEBUG: 7772: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-29 04:59:52,408 [root] DEBUG: 7772: DLL loaded at 0x00007FFEFE540000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-29 04:59:52,423 [root] DEBUG: 7772: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-29 04:59:52,426 [root] DEBUG: 7772: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 04:59:52,433 [root] DEBUG: 7772: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 04:59:52,434 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 8488: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:52,434 [root] DEBUG: 7772: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 04:59:52,435 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 8488
2026-05-29 04:59:52,435 [root] DEBUG: 7772: DLL loaded at 0x00007FFF18230000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-29 04:59:52,436 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 8488
2026-05-29 04:59:52,436 [root] DEBUG: 7772: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 04:59:52,437 [root] DEBUG: 7772: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 04:59:52,449 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-29 04:59:52,450 [root] DEBUG: 7772: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-29 04:59:52,451 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-29 04:59:52,452 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-29 04:59:52,454 [root] DEBUG: 7772: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 04:59:52,454 [root] DEBUG: 7772: DLL loaded at 0x00007FFF17EF0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-29 04:59:52,457 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 04:59:52,458 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-29 04:59:52,458 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-29 04:59:52,459 [root] DEBUG: 7772: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 04:59:52,460 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-29 04:59:52,462 [root] DEBUG: 7772: DLL loaded at 0x00007FFF15300000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-29 04:59:52,462 [root] DEBUG: 7772: DLL loaded at 0x00007FFF3E240000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-29 04:59:52,463 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-29 04:59:52,464 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-29 04:59:52,466 [root] DEBUG: 7772: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-29 04:59:52,467 [root] DEBUG: 7772: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 04:59:52,468 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-29 04:59:52,468 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-29 04:59:52,471 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-29 04:59:52,480 [root] DEBUG: 7772: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-29 04:59:52,481 [root] DEBUG: 7772: DLL loaded at 0x00007FFF42BF0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-29 04:59:52,482 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 04:59:52,483 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-29 04:59:52,484 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-29 04:59:52,485 [root] DEBUG: 7772: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-29 04:59:52,488 [root] DEBUG: 7772: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-29 04:59:52,490 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-29 04:59:52,491 [root] DEBUG: 7772: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 04:59:52,493 [root] DEBUG: 7772: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-29 04:59:52,494 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-29 04:59:52,496 [root] DEBUG: 7772: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-29 04:59:52,497 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-29 04:59:52,497 [root] DEBUG: 7772: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-29 04:59:52,498 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-29 04:59:52,499 [root] DEBUG: 7772: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-29 04:59:52,500 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-29 04:59:52,500 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-29 04:59:52,503 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-29 04:59:52,505 [root] DEBUG: 7772: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-29 04:59:52,505 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-29 04:59:52,505 [root] DEBUG: 7772: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-29 04:59:52,506 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-29 04:59:52,509 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-29 04:59:52,510 [root] DEBUG: 7772: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-29 04:59:52,512 [root] DEBUG: 7772: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-29 04:59:52,514 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-29 04:59:52,520 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-29 04:59:52,522 [root] DEBUG: 7772: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-29 04:59:52,526 [root] DEBUG: 7772: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-29 04:59:52,526 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-29 04:59:52,527 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-29 04:59:52,530 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-29 04:59:52,531 [root] DEBUG: 7772: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-29 04:59:52,533 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-29 04:59:52,536 [root] DEBUG: 7772: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-29 04:59:52,537 [root] DEBUG: 7772: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-29 04:59:52,538 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-29 04:59:52,538 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-29 04:59:52,547 [root] DEBUG: 7772: DLL loaded at 0x00007FFF16370000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-29 04:59:52,560 [root] DEBUG: 7772: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-29 04:59:52,562 [root] DEBUG: 7772: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-29 04:59:52,564 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 1120: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:52,565 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 1120
2026-05-29 04:59:52,566 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 1120
2026-05-29 04:59:52,568 [root] DEBUG: 7772: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 3144).
2026-05-29 04:59:52,575 [root] DEBUG: 7772: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-29 04:59:52,587 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 3100: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:52,587 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 6900: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:52,588 [root] DEBUG: 7772: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-29 04:59:52,588 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 3100
2026-05-29 04:59:52,588 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 6900
2026-05-29 04:59:52,591 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 3100
2026-05-29 04:59:52,592 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 6900
2026-05-29 04:59:52,592 [root] DEBUG: 7772: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-29 04:59:52,634 [root] DEBUG: 7772: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-29 04:59:52,635 [root] DEBUG: 7772: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-29 04:59:52,671 [root] DEBUG: 7772: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-29 04:59:52,672 [root] DEBUG: 7772: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-29 04:59:52,673 [root] DEBUG: 7772: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-29 04:59:52,674 [root] DEBUG: 7772: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-29 04:59:52,697 [root] DEBUG: 7772: DLL loaded at 0x00007FFF17EF0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-29 04:59:52,712 [root] DEBUG: 7772: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-29 04:59:52,718 [root] DEBUG: 7772: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-29 04:59:52,719 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 1360: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:52,720 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 3760: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:52,722 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 1360
2026-05-29 04:59:52,722 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 3760
2026-05-29 04:59:52,723 [root] DEBUG: 7772: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-29 04:59:52,723 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 1360
2026-05-29 04:59:52,723 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 3760
2026-05-29 04:59:52,800 [root] DEBUG: 7772: DLL loaded at 0x00007FFF3EFA0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-29 04:59:52,803 [root] DEBUG: 7772: DLL loaded at 0x00007FFF3F6A0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-29 04:59:52,804 [root] DEBUG: 7772: DLL loaded at 0x00007FFF162D0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-29 04:59:52,809 [root] DEBUG: 7772: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-29 04:59:52,815 [root] DEBUG: 7772: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-29 04:59:52,817 [root] DEBUG: 7772: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-29 04:59:52,838 [root] DEBUG: 7772: DLL loaded at 0x00007FFF16070000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-29 04:59:52,851 [root] DEBUG: 7772: DLL loaded at 0x00007FFF15400000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-29 04:59:52,858 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-29 04:59:52,864 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-29 04:59:52,872 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-29 04:59:54,000 [root] DEBUG: 7772: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-29 04:59:54,452 [root] DEBUG: 7772: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 04:59:54,455 [root] DEBUG: 7772: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 04:59:57,737 [root] DEBUG: 7772: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-29 04:59:57,741 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 9564: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:57,743 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 9576: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 04:59:57,743 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 9564
2026-05-29 04:59:57,744 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 9576
2026-05-29 04:59:57,745 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 9564
2026-05-29 04:59:57,746 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 9576
2026-05-29 04:59:57,788 [root] DEBUG: 7772: DLL loaded at 0x00007FFEFB560000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-29 04:59:57,932 [root] DEBUG: 7772: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-29 04:59:57,937 [root] DEBUG: 7772: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-29 04:59:57,957 [root] DEBUG: 7772: DLL loaded at 0x00007FFEFAF00000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-29 04:59:58,017 [root] DEBUG: 7772: DLL loaded at 0x00007FFF15A60000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-29 04:59:58,019 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-29 04:59:58,020 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-29 04:59:58,022 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56250000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-29 04:59:58,023 [root] DEBUG: 7772: DLL loaded at 0x00007FFF561E0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-29 04:59:58,053 [root] DEBUG: 7772: DLL loaded at 0x00007FFF12C60000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-29 04:59:58,097 [root] DEBUG: 7772: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-29 04:59:58,098 [root] DEBUG: 7772: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-29 04:59:58,098 [root] DEBUG: 7772: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-29 04:59:58,431 [root] DEBUG: 7772: DLL loaded at 0x00007FFF13410000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-29 04:59:58,441 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 9748: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF742720000
2026-05-29 04:59:58,442 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9748
2026-05-29 04:59:58,443 [lib.api.process] INFO: Monitor config for process 9748: C:\lpw_albt\dll\9748.ini
2026-05-29 04:59:58,444 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 04:59:59,203 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 04:59:59,203 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 04:59:59,204 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 04:59:59,204 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 04:59:59,205 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 04:59:59,205 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 04:59:59,205 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 04:59:59,205 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 04:59:59,208 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 04:59:59,213 [root] DEBUG: Loader: Injecting process 9748 (thread 9752) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:59,213 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 04:59:59,214 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:59,216 [lib.api.process] INFO: Injected into 64-bit <Process 9748 identity_helper.exe>
2026-05-29 04:59:59,222 [root] DEBUG: 7772: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-29 04:59:59,223 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4CBD0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-29 04:59:59,225 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 9900: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF742720000
2026-05-29 04:59:59,225 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9900
2026-05-29 04:59:59,226 [lib.api.process] INFO: Monitor config for process 9900: C:\lpw_albt\dll\9900.ini
2026-05-29 04:59:59,228 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 04:59:59,306 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 04:59:59,306 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 04:59:59,308 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 04:59:59,308 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 04:59:59,309 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 04:59:59,310 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 04:59:59,310 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 04:59:59,310 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 04:59:59,312 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 04:59:59,316 [root] DEBUG: Loader: Injecting process 9900 (thread 9904) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:59,317 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 04:59:59,317 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:59,318 [lib.api.process] INFO: Injected into 64-bit <Process 9900 identity_helper.exe>
2026-05-29 04:59:59,321 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9900
2026-05-29 04:59:59,321 [lib.api.process] INFO: Monitor config for process 9900: C:\lpw_albt\dll\9900.ini
2026-05-29 04:59:59,321 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 04:59:59,391 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 04:59:59,392 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 04:59:59,392 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 04:59:59,393 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 04:59:59,393 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 04:59:59,393 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 04:59:59,393 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 04:59:59,393 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 04:59:59,395 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 04:59:59,398 [root] DEBUG: Loader: Injecting process 9900 (thread 9904) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:59,399 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 04:59:59,399 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 04:59:59,401 [lib.api.process] INFO: Injected into 64-bit <Process 9900 identity_helper.exe>
2026-05-29 04:59:59,410 [root] DEBUG: 9900: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 04:59:59,410 [root] DEBUG: 9900: Interactive desktop enabled.
2026-05-29 04:59:59,410 [root] DEBUG: 9900: Dropped file limit defaulting to 100.
2026-05-29 04:59:59,426 [root] DEBUG: 9900: Disabling sleep skipping.
2026-05-29 04:59:59,427 [root] DEBUG: 9900: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 04:59:59,439 [root] DEBUG: 9900: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 04:59:59,440 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,471 [root] DEBUG: 9900: Monitor initialised: 64-bit capemon loaded in process 9900 at 0x00007FFF18250000, thread 9904, image base 0x00007FF742720000, stack from 0x000000F3B40F4000-0x000000F3B4100000
2026-05-29 04:59:59,472 [root] DEBUG: 9900: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5920,i,6459358960151492041,10382894102935569465,524288 --field-trial-handle=2328,i,194968896967151411,7716814595926539180,262144 --variations-seed-version --pseudonymization-salt-handle=2364,i,3288981485989055659,1644457982178689346
2026-05-29 04:59:59,472 [root] DEBUG: 9900: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-29 04:59:59,483 [root] DEBUG: 9900: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 04:59:59,506 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 04:59:59,507 [root] DEBUG: 9900: set_hooks: Unable to hook LockResource
2026-05-29 04:59:59,511 [root] DEBUG: 9900: Hooked 627 out of 628 functions
2026-05-29 04:59:59,525 [root] DEBUG: 9900: Syscall hook installed, syscall logging level 1
2026-05-29 04:59:59,530 [root] DEBUG: 9900: RestoreHeaders: Restored original import table.
2026-05-29 04:59:59,531 [root] INFO: Loaded monitor into process with pid 9900
2026-05-29 04:59:59,532 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,578 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,593 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4F950000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-29 04:59:59,606 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,617 [root] DEBUG: 7772: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-29 04:59:59,618 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-29 04:59:59,633 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,662 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,688 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,700 [root] DEBUG: 7772: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-29 04:59:59,702 [root] DEBUG: 7772: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-29 04:59:59,703 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-29 04:59:59,704 [root] DEBUG: 7772: DLL loaded at 0x00007FFF50370000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-29 04:59:59,705 [root] DEBUG: 7772: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 04:59:59,705 [root] DEBUG: 7772: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-29 04:59:59,706 [root] DEBUG: 7772: DLL loaded at 0x00007FFF45050000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-29 04:59:59,711 [root] DEBUG: 7772: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-29 04:59:59,713 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FFF16940000, size 0x4b9994
2026-05-29 04:59:59,741 [root] DEBUG: 9900: caller_dispatch: Added region at 0x00007FFF16940000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF16B3F156, thread 9904).
2026-05-29 04:59:59,742 [root] DEBUG: 9900: caller_dispatch: Scanning calling region at 0x00007FFF16940000...
2026-05-29 04:59:59,747 [root] DEBUG: 9900: ProcessTrackedRegion: Region at 0x00007FFF16940000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-29 04:59:59,750 [root] DEBUG: 9900: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-29 04:59:59,772 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,787 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,804 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,822 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,838 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,853 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,871 [root] DEBUG: 9900: caller_dispatch: Added region at 0x00007FF742720000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF742814096, thread 9904).
2026-05-29 04:59:59,873 [root] DEBUG: 9900: YaraScan: Scanning 0x00007FF742720000, size 0x28b4d8
2026-05-29 04:59:59,889 [root] DEBUG: 9900: ProcessImageBase: Main module image at 0x00007FF742720000 unmodified (entropy change 0.000000e+00)
2026-05-29 04:59:59,893 [root] DEBUG: 9900: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 04:59:59,920 [root] DEBUG: 9900: DLL loaded at 0x000002B24A000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-29 04:59:59,927 [root] DEBUG: 9900: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 04:59:59,929 [root] DEBUG: 9900: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-29 04:59:59,958 [root] DEBUG: 9900: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 04:59:59,963 [root] DEBUG: 9900: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 04:59:59,967 [root] DEBUG: 9900: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 04:59:59,968 [root] DEBUG: 9900: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-29 04:59:59,968 [root] DEBUG: 9900: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-29 04:59:59,969 [root] DEBUG: 9900: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-29 04:59:59,979 [root] DEBUG: 9900: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-29 04:59:59,981 [root] DEBUG: 9900: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-29 04:59:59,981 [root] DEBUG: 9900: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-29 04:59:59,982 [root] DEBUG: 9900: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-29 04:59:59,982 [root] DEBUG: 9900: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-29 04:59:59,988 [root] DEBUG: 9900: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-29 04:59:59,995 [root] DEBUG: 9900: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-29 05:00:00,002 [root] DEBUG: 9900: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:00,002 [root] DEBUG: 9900: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:00,004 [root] DEBUG: 9900: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-29 05:00:00,013 [root] DEBUG: 9900: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 05:00:00,017 [root] DEBUG: 9900: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-29 05:00:00,026 [root] DEBUG: 9900: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-29 05:00:00,027 [root] DEBUG: 9900: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-29 05:00:00,030 [root] DEBUG: 9900: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-29 05:00:00,036 [root] DEBUG: 9900: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-29 05:00:00,042 [root] DEBUG: 9900: DLL loaded at 0x000002B248ED0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-29 05:00:00,049 [lib.api.process] INFO: Monitor config for process 832: C:\lpw_albt\dll\832.ini
2026-05-29 05:00:00,050 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:00,051 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:00,055 [root] DEBUG: Loader: Injecting process 832 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:00,057 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:00,057 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-29 05:00:00,058 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-29 05:00:00,058 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-29 05:00:00,059 [root] DEBUG: 832: Services hook set enabled
2026-05-29 05:00:00,061 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:00,072 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:00,072 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF18250000, thread 3924, image base 0x00007FF7BF220000, stack from 0x000000CCA7AF5000-0x000000CCA7B00000
2026-05-29 05:00:00,073 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-29 05:00:00,086 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-29 05:00:00,087 [root] INFO: Loaded monitor into process with pid 832
2026-05-29 05:00:00,088 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-29 05:00:00,088 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:00,090 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-29 05:00:02,128 [root] DEBUG: 9900: DLL loaded at 0x00007FFF4B780000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-29 05:00:02,131 [root] DEBUG: 9900: DLL loaded at 0x00007FFF4B840000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-29 05:00:02,132 [root] DEBUG: 9900: DLL loaded at 0x00007FFF43150000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-29 05:00:02,134 [root] DEBUG: 9900: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-29 05:00:02,143 [root] DEBUG: 9900: DLL loaded at 0x00007FFF4F6E0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-29 05:00:02,164 [root] DEBUG: 9900: DLL loaded at 0x00007FFF55EF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-29 05:00:02,165 [root] DEBUG: 9900: DLL loaded at 0x00007FFF53070000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-29 05:00:02,170 [root] DEBUG: 9900: DLL loaded at 0x00007FFF48B40000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-29 05:00:02,171 [root] DEBUG: 9900: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-29 05:00:02,184 [root] DEBUG: 9900: DLL loaded at 0x00007FFF43060000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-29 05:00:02,204 [root] DEBUG: 9900: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-29 05:00:02,205 [root] DEBUG: 9900: DLL loaded at 0x00007FFF56FA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-29 05:00:02,205 [root] DEBUG: 9900: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 05:00:02,206 [root] DEBUG: 9900: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-29 05:00:02,206 [root] DEBUG: 9900: DLL loaded at 0x00007FFF43DD0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-29 05:00:02,223 [root] DEBUG: 9900: DLL loaded at 0x00007FFF3D810000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-29 05:00:02,242 [root] DEBUG: 9900: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-29 05:00:02,269 [root] DEBUG: 9900: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-29 05:00:10,115 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5228: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:00:10,117 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 5228
2026-05-29 05:00:10,117 [lib.api.process] INFO: Monitor config for process 5228: C:\lpw_albt\dll\5228.ini
2026-05-29 05:00:10,118 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,118 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,123 [root] DEBUG: Loader: Injecting process 5228 (thread 9500) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,123 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:10,124 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,125 [lib.api.process] INFO: Injected into 64-bit <Process 5228 backgroundTaskHost.exe>
2026-05-29 05:00:10,126 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 5228
2026-05-29 05:00:10,126 [lib.api.process] INFO: Monitor config for process 5228: C:\lpw_albt\dll\5228.ini
2026-05-29 05:00:10,126 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,127 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,131 [root] DEBUG: Loader: Injecting process 5228 (thread 9500) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,131 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:10,132 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,133 [lib.api.process] INFO: Injected into 64-bit <Process 5228 backgroundTaskHost.exe>
2026-05-29 05:00:10,133 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 5228
2026-05-29 05:00:10,134 [lib.api.process] INFO: Monitor config for process 5228: C:\lpw_albt\dll\5228.ini
2026-05-29 05:00:10,134 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,135 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,140 [root] DEBUG: Loader: Injecting process 5228 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,141 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9500, handle 0x120
2026-05-29 05:00:10,141 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:10,141 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,143 [lib.api.process] INFO: Injected into 64-bit <Process 5228 backgroundTaskHost.exe>
2026-05-29 05:00:10,148 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8884: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:00:10,148 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8884
2026-05-29 05:00:10,149 [lib.api.process] INFO: Monitor config for process 8884: C:\lpw_albt\dll\8884.ini
2026-05-29 05:00:10,149 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,150 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,155 [root] DEBUG: Loader: Injecting process 8884 (thread 8700) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,156 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:10,156 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,157 [lib.api.process] INFO: Injected into 64-bit <Process 8884 backgroundTaskHost.exe>
2026-05-29 05:00:10,158 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8884
2026-05-29 05:00:10,158 [lib.api.process] INFO: Monitor config for process 8884: C:\lpw_albt\dll\8884.ini
2026-05-29 05:00:10,159 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,159 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,163 [root] DEBUG: Loader: Injecting process 8884 (thread 8700) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,163 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:10,164 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,165 [lib.api.process] INFO: Injected into 64-bit <Process 8884 backgroundTaskHost.exe>
2026-05-29 05:00:10,167 [root] INFO: Process with pid 8884 has terminated
2026-05-29 05:00:10,171 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 4056: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:00:10,172 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 4056
2026-05-29 05:00:10,172 [lib.api.process] INFO: Monitor config for process 4056: C:\lpw_albt\dll\4056.ini
2026-05-29 05:00:10,173 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,174 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,178 [root] DEBUG: Loader: Injecting process 4056 (thread 6492) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,178 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:10,179 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,180 [lib.api.process] INFO: Injected into 64-bit <Process 4056 backgroundTaskHost.exe>
2026-05-29 05:00:10,181 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 4056
2026-05-29 05:00:10,181 [lib.api.process] INFO: Monitor config for process 4056: C:\lpw_albt\dll\4056.ini
2026-05-29 05:00:10,181 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,182 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,186 [root] DEBUG: Loader: Injecting process 4056 (thread 6492) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,187 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:10,189 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,190 [lib.api.process] INFO: Injected into 64-bit <Process 4056 backgroundTaskHost.exe>
2026-05-29 05:00:10,192 [root] INFO: Process with pid 4056 has terminated
2026-05-29 05:00:10,195 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9496: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:00:10,195 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9496
2026-05-29 05:00:10,196 [lib.api.process] INFO: Monitor config for process 9496: C:\lpw_albt\dll\9496.ini
2026-05-29 05:00:10,196 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,197 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,202 [root] DEBUG: Loader: Injecting process 9496 (thread 1676) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,202 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:10,203 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,205 [lib.api.process] INFO: Injected into 64-bit <Process 9496 backgroundTaskHost.exe>
2026-05-29 05:00:10,205 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9496
2026-05-29 05:00:10,206 [lib.api.process] INFO: Monitor config for process 9496: C:\lpw_albt\dll\9496.ini
2026-05-29 05:00:10,206 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:10,207 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:10,210 [root] DEBUG: Loader: Injecting process 9496 (thread 1676) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,211 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:10,211 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:10,213 [lib.api.process] INFO: Injected into 64-bit <Process 9496 backgroundTaskHost.exe>
2026-05-29 05:00:10,213 [root] INFO: Process with pid 9496 has terminated
2026-05-29 05:00:12,345 [root] INFO: Process with pid 9900 has terminated
2026-05-29 05:00:12,346 [root] DEBUG: 9900: NtTerminateProcess hook: Attempting to dump process 9900
2026-05-29 05:00:12,347 [root] DEBUG: 9900: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:00:20,890 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 3888: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 05:00:20,891 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 3888
2026-05-29 05:00:20,892 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 3888
2026-05-29 05:00:21,904 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 10040: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 05:00:21,905 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 10040
2026-05-29 05:00:21,906 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 10040
2026-05-29 05:00:22,430 [root] DEBUG: 7772: DLL loaded at 0x00007FFF18A30000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-29 05:00:22,543 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 1796: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 05:00:22,544 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 1796
2026-05-29 05:00:22,544 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 1796
2026-05-29 05:00:32,006 [root] INFO: Announced starting service "b'edgeupdate'"
2026-05-29 05:00:32,007 [lib.api.process] INFO: Monitor config for process 676: C:\lpw_albt\dll\676.ini
2026-05-29 05:00:32,007 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:32,008 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:32,012 [root] DEBUG: Loader: Injecting process 676 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:32,014 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\676.ini to system path C:\676.ini
2026-05-29 05:00:32,016 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:00:32,016 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:32,017 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-29 05:00:33,147 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:33,156 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-29 05:00:33,157 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-29 05:00:33,157 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-29 05:00:33,159 [root] DEBUG: 676: Services hook set enabled
2026-05-29 05:00:33,193 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:33,194 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFF17340000, thread 2340, image base 0x00007FF7839A0000, stack from 0x000000F2F00F2000-0x000000F2F0100000
2026-05-29 05:00:33,194 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-29 05:00:33,217 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-29 05:00:33,220 [root] INFO: Loaded monitor into process with pid 676
2026-05-29 05:00:35,040 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-29 05:00:35,041 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 05:00:35,043 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-29 05:00:35,044 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 8268: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x0000000000150000
2026-05-29 05:00:35,045 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 8268
2026-05-29 05:00:35,046 [lib.api.process] INFO: Monitor config for process 8268: C:\lpw_albt\dll\8268.ini
2026-05-29 05:00:35,048 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:35,050 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\ujJJun.dll, loader C:\lpw_albt\bin\IJlvWFq.exe
2026-05-29 05:00:35,099 [root] DEBUG: Loader: Injecting process 8268 (thread 7024) with C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:35,100 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:35,101 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:35,104 [lib.api.process] INFO: Injected into 32-bit <Process 8268 MicrosoftEdgeUpdate.exe>
2026-05-29 05:00:35,106 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 8268
2026-05-29 05:00:35,106 [lib.api.process] INFO: Monitor config for process 8268: C:\lpw_albt\dll\8268.ini
2026-05-29 05:00:35,107 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:35,108 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\ujJJun.dll, loader C:\lpw_albt\bin\IJlvWFq.exe
2026-05-29 05:00:35,115 [root] DEBUG: Loader: Injecting process 8268 (thread 7024) with C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:35,116 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:35,116 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:35,118 [lib.api.process] INFO: Injected into 32-bit <Process 8268 MicrosoftEdgeUpdate.exe>
2026-05-29 05:00:35,118 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 8268
2026-05-29 05:00:35,118 [lib.api.process] INFO: Monitor config for process 8268: C:\lpw_albt\dll\8268.ini
2026-05-29 05:00:35,119 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:35,120 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\ujJJun.dll, loader C:\lpw_albt\bin\IJlvWFq.exe
2026-05-29 05:00:35,126 [root] DEBUG: Loader: Injecting process 8268 with C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:35,126 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2026-05-29 05:00:35,153 [root] DEBUG: 8268: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:35,154 [root] DEBUG: 8268: Interactive desktop enabled.
2026-05-29 05:00:35,154 [root] DEBUG: 8268: Dropped file limit defaulting to 100.
2026-05-29 05:00:35,158 [root] DEBUG: 8268: Disabling sleep skipping.
2026-05-29 05:00:35,160 [root] DEBUG: 8268: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:35,160 [root] DEBUG: 8268: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 05:00:35,162 [root] DEBUG: 8268: Monitor initialised: 32-bit capemon loaded in process 8268 at 0x6abe0000, thread 3536, image base 0x150000, stack from 0x2694000-0x26a0000
2026-05-29 05:00:35,162 [root] DEBUG: 8268: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
2026-05-29 05:00:35,186 [root] DEBUG: 8268: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-29 05:00:35,201 [root] DEBUG: 8268: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-29 05:00:35,201 [root] DEBUG: 8268: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-29 05:00:35,205 [root] DEBUG: 8268: Hooked 632 out of 632 functions
2026-05-29 05:00:35,207 [root] DEBUG: 8268: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:35,213 [root] DEBUG: 8268: RestoreHeaders: Restored original import table.
2026-05-29 05:00:35,214 [root] INFO: Loaded monitor into process with pid 8268
2026-05-29 05:00:35,214 [root] DEBUG: 8268: caller_dispatch: Added region at 0x02550000 to tracked regions list (ntdll::LdrLoadDll returns to 0x02550035, thread 3536).
2026-05-29 05:00:35,216 [root] DEBUG: 8268: DumpPEsInRange: Scanning range 0x02550000 - 0x02550127.
2026-05-29 05:00:35,216 [root] DEBUG: 8268: ScanForDisguisedPE: Size too small: 0x127 bytes
2026-05-29 05:00:35,220 [lib.common.results] INFO: Uploading file C:\zDtLzmEP\CAPE\8268_4434612350929552026 to CAPE\2be761dbccfdf79599c74ee94d70981e02e33e2bd02e20125c50811d484d28e6; Size is 295; Max size: 100000000
2026-05-29 05:00:35,223 [root] DEBUG: 8268: DumpMemory: Payload successfully created: C:\zDtLzmEP\CAPE\8268_4434612350929552026 (size 295 bytes)
2026-05-29 05:00:35,223 [root] DEBUG: 8268: DumpRegion: Dumped entire allocation from 0x02550000, size 4096 bytes.
2026-05-29 05:00:35,223 [root] DEBUG: 8268: ProcessTrackedRegion: Dumped region at 0x02550000.
2026-05-29 05:00:35,224 [root] DEBUG: 8268: YaraScan: Scanning 0x02550000, size 0x127
2026-05-29 05:00:35,225 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-29 05:00:35,225 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:35,227 [lib.api.process] INFO: Injected into 32-bit <Process 8268 MicrosoftEdgeUpdate.exe>
2026-05-29 05:00:35,228 [root] DEBUG: 8268: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 7024).
2026-05-29 05:00:35,228 [root] DEBUG: 8268: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 05:00:35,230 [root] DEBUG: 8268: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:35,235 [root] DEBUG: 8268: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-29 05:00:35,236 [root] DEBUG: 8268: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-29 05:00:35,240 [root] DEBUG: 8268: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-29 05:00:35,247 [root] DEBUG: 8268: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-29 05:00:35,248 [root] DEBUG: 8268: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-29 05:00:35,248 [root] DEBUG: 8268: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-29 05:00:35,249 [root] DEBUG: 8268: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-29 05:00:35,250 [root] DEBUG: 8268: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-29 05:00:35,250 [root] DEBUG: 8268: DLL loaded at 0x6AEB0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-29 05:00:35,268 [root] DEBUG: 8268: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 05:00:35,268 [root] DEBUG: 8268: DLL loaded at 0x75590000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-29 05:00:35,282 [root] DEBUG: 8268: DLL loaded at 0x6F2A0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-29 05:00:35,283 [root] DEBUG: 8268: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-29 05:00:35,284 [root] DEBUG: 8268: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 05:00:35,284 [root] DEBUG: 8268: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-29 05:00:35,285 [root] DEBUG: 8268: DLL loaded at 0x754D0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-29 05:00:35,286 [root] DEBUG: 8268: DLL loaded at 0x754F0000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-29 05:00:35,286 [root] DEBUG: 8268: DLL loaded at 0x75560000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-29 05:00:35,289 [root] DEBUG: 8268: DLL loaded at 0x6F290000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-29 05:00:35,292 [root] DEBUG: 8268: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 05:00:35,297 [root] DEBUG: 8268: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 05:00:35,298 [root] DEBUG: 8268: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-29 05:00:35,299 [root] DEBUG: 8268: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-29 05:00:35,307 [root] DEBUG: 8268: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-29 05:00:35,339 [root] DEBUG: 8268: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-29 05:00:35,341 [root] DEBUG: 8268: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-29 05:00:35,347 [root] DEBUG: 8268: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-29 05:00:35,362 [root] DEBUG: 8268: DLL loaded at 0x75590000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\psmachine (0x58000 bytes).
2026-05-29 05:00:35,428 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 05:00:35,429 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1116, handle 0x3b8: Error obtaining target process name
2026-05-29 05:00:35,550 [root] DEBUG: 8268: DLL loaded at 0x75530000: C:\Windows\System32\SystemSettings.DataModel (0x57000 bytes).
2026-05-29 05:00:35,552 [root] DEBUG: 8268: caller_dispatch: Added region at 0x75530000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x7555B711, thread 9552).
2026-05-29 05:00:35,553 [root] DEBUG: 8268: ProcessTrackedRegion: Region at 0x75530000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\SystemSettings.DataModel.dll is in known range, skipping
2026-05-29 05:00:35,560 [root] DEBUG: 8268: DLL loaded at 0x75410000: C:\Windows\SYSTEM32\USERENV (0x25000 bytes).
2026-05-29 05:00:35,572 [root] DEBUG: 8268: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 05:00:35,574 [root] DEBUG: 8268: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 05:00:35,581 [root] DEBUG: 8268: DLL loaded at 0x6FCF0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x3ba000 bytes).
2026-05-29 05:00:35,603 [root] DEBUG: 8268: DLL loaded at 0x77270000: C:\Windows\System32\CFGMGR32 (0x3b000 bytes).
2026-05-29 05:00:35,611 [root] DEBUG: 8268: DLL loaded at 0x754A0000: C:\Windows\System32\StructuredQuery (0x81000 bytes).
2026-05-29 05:00:35,615 [root] DEBUG: 8268: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2026-05-29 05:00:35,618 [root] DEBUG: 8268: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-29 05:00:35,623 [root] DEBUG: 8268: DLL loaded at 0x70910000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2026-05-29 05:00:35,637 [root] DEBUG: 8268: DLL loaded at 0x6AB40000: C:\Windows\System32\Windows.StateRepositoryPS (0x93000 bytes).
2026-05-29 05:00:35,655 [root] DEBUG: 8268: DLL loaded at 0x6AAA0000: C:\Windows\system32\Windows.Storage.Search (0x9d000 bytes).
2026-05-29 05:00:35,685 [root] DEBUG: 8268: DLL loaded at 0x6AA90000: C:\Windows\SYSTEM32\LINKINFO (0xb000 bytes).
2026-05-29 05:00:35,723 [root] DEBUG: 8268: DLL loaded at 0x6F0B0000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-29 05:00:35,732 [root] DEBUG: 8268: DLL loaded at 0x755F0000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-29 05:00:35,750 [root] DEBUG: 8268: DLL loaded at 0x75340000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-29 05:00:35,754 [root] DEBUG: 8268: DLL loaded at 0x6E3B0000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-29 05:00:35,757 [root] DEBUG: 8268: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-05-29 05:00:35,758 [root] DEBUG: 8268: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-29 05:00:35,759 [root] DEBUG: 8268: DLL loaded at 0x6BC10000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-29 05:00:35,761 [root] DEBUG: 8268: DLL loaded at 0x73F80000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-29 05:00:35,773 [root] DEBUG: 8268: DLL loaded at 0x6AA10000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-29 05:00:35,776 [root] DEBUG: 8268: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-29 05:00:35,777 [root] DEBUG: 8268: DLL loaded at 0x6E2F0000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-29 05:00:35,783 [root] DEBUG: 8268: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-29 05:00:35,786 [root] DEBUG: 8268: DLL loaded at 0x6D030000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-29 05:00:35,811 [root] DEBUG: 8268: DLL loaded at 0x6CFD0000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-29 05:00:36,095 [root] DEBUG: 8268: DLL loaded at 0x6CF50000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-29 05:00:36,656 [root] DEBUG: 8268: DLL loaded at 0x6CF40000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-29 05:00:36,657 [root] DEBUG: 8268: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 05:00:36,659 [root] DEBUG: 8268: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 05:00:36,660 [root] DEBUG: 8268: DLL loaded at 0x6CEF0000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-29 05:00:36,662 [root] DEBUG: 8268: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-29 05:00:36,953 [root] DEBUG: Error 87 (0x57) - OpenProcessHandler: Error obtaining target process name: The parameter is incorrect.
2026-05-29 05:00:36,954 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4, handle 0x73c: Error obtaining target process name
2026-05-29 05:00:36,955 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 124, handle 0x73c:
2026-05-29 05:00:36,955 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 384, handle 0x73c: C:\Windows\System32\smss.exe
2026-05-29 05:00:36,956 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 480, handle 0x73c: C:\Windows\System32\csrss.exe
2026-05-29 05:00:36,956 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 556, handle 0x73c: C:\Windows\System32\wininit.exe
2026-05-29 05:00:36,956 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 576, handle 0x73c: C:\Windows\System32\csrss.exe
2026-05-29 05:00:36,957 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 656, handle 0x73c: C:\Windows\System32\winlogon.exe
2026-05-29 05:00:36,958 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 676, handle 0x73c: C:\Windows\System32\services.exe
2026-05-29 05:00:36,958 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 724, handle 0x73c: C:\Windows\System32\lsass.exe
2026-05-29 05:00:36,958 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 832, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,959 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 860, handle 0x73c: C:\Windows\System32\fontdrvhost.exe
2026-05-29 05:00:36,959 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 868, handle 0x73c: C:\Windows\System32\fontdrvhost.exe
2026-05-29 05:00:36,960 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 948, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,960 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1004, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,961 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 472, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,961 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 772, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,961 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1048, handle 0x73c: C:\Windows\System32\dwm.exe
2026-05-29 05:00:36,962 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1096, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,962 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1136, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,963 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1164, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,963 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1268, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,963 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1284, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,965 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1292, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,965 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1308, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,966 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1352, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,966 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1444, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,967 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1596, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,967 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1632, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,967 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1644, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,968 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1664, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,968 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1828, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,969 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1852, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,969 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1860, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,969 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1868, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,970 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1992, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,970 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2020, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,971 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2036, handle 0x73c:
2026-05-29 05:00:36,971 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2124, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,971 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2224, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,972 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2240, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,972 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2296, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,973 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2344, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,973 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2456, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,973 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2472, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,974 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2520, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,974 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2696, handle 0x73c: C:\Windows\System32\spoolsv.exe
2026-05-29 05:00:36,974 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2724, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,975 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2772, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,975 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2876, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,976 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2896, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,976 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3012, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,977 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3020, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,977 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3040, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,977 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3048, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,978 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3056, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,978 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2292, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,978 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2820, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,979 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3396, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,980 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3892, handle 0x73c: C:\Windows\System32\SearchIndexer.exe
2026-05-29 05:00:36,981 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3992, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,981 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3500, handle 0x73c: C:\Windows\System32\sihost.exe
2026-05-29 05:00:36,982 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3416, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,982 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4148, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,983 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4240, handle 0x73c: C:\Windows\System32\taskhostw.exe
2026-05-29 05:00:36,983 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4300, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,984 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4380, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,984 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4484, handle 0x73c: C:\Windows\explorer.exe
2026-05-29 05:00:36,985 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4524, handle 0x73c: C:\Windows\System32\ctfmon.exe
2026-05-29 05:00:36,985 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4592, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,986 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4788, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,986 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 4916, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,987 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5200, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,987 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5260, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,988 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5544, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,992 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5624, handle 0x73c: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-29 05:00:36,992 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5688, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 05:00:36,993 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5800, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,993 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5892, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,994 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6008, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:36,994 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6136, handle 0x73c: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-29 05:00:36,996 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5948, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 05:00:36,997 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6436, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 05:00:36,998 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6616, handle 0x73c: C:\Windows\System32\taskhostw.exe
2026-05-29 05:00:36,998 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6996, handle 0x73c: C:\Windows\System32\smartscreen.exe
2026-05-29 05:00:36,999 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 7052, handle 0x73c: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-29 05:00:37,000 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 7088, handle 0x73c: C:\Windows\System32\SecurityHealthService.exe
2026-05-29 05:00:37,000 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6284, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,000 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3976, handle 0x73c: C:\Windows\System32\conhost.exe
2026-05-29 05:00:37,001 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1104, handle 0x73c: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-29 05:00:37,001 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5128, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 05:00:37,002 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6768, handle 0x73c: C:\Program Files (x86)\Steam\steam.exe
2026-05-29 05:00:37,002 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6400, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,003 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6356, handle 0x73c: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-29 05:00:37,003 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6360, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 05:00:37,004 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6392, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,004 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2160, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 05:00:37,005 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6512, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,005 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6504, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 05:00:37,006 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 7444, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,006 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 7544, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,007 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 7844, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 05:00:37,007 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8100, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,008 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8340, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 05:00:37,008 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8108, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,008 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3820, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 05:00:37,009 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8044, handle 0x73c: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-29 05:00:37,009 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1740, handle 0x73c: C:\Windows\System32\dllhost.exe
2026-05-29 05:00:37,010 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1316, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,010 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3404, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,011 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5364, handle 0x73c: C:\Windows\System32\SgrmBroker.exe
2026-05-29 05:00:37,011 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6640, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,013 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2580, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,013 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6028, handle 0x73c: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-29 05:00:37,013 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6188, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,014 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8484, handle 0x73c: C:\Windows\System32\backgroundTaskHost.exe
2026-05-29 05:00:37,015 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2992, handle 0x73c: C:\Windows\System32\CompatTelRunner.exe
2026-05-29 05:00:37,015 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6280, handle 0x73c: C:\Windows\servicing\TrustedInstaller.exe
2026-05-29 05:00:37,015 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8444, handle 0x73c: C:\Windows\System32\notepad.exe
2026-05-29 05:00:37,016 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8904, handle 0x73c: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-29 05:00:37,016 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 2092, handle 0x73c: C:\Windows\System32\conhost.exe
2026-05-29 05:00:37,017 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5232, handle 0x73c: C:\Windows\System32\CompatTelRunner.exe
2026-05-29 05:00:37,017 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5632, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,018 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6748, handle 0x73c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-29 05:00:37,018 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 7772, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,018 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 8488, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,019 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1120, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,020 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3100, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,020 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 6900, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,021 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 1360, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,021 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 5360, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,022 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 9360, handle 0x73c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-29 05:00:37,022 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 9400, handle 0x73c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-29 05:00:37,022 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 9776, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,023 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 9800, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 05:00:37,023 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 3888, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,024 [root] DEBUG: 8268: OpenProcessHandler: Injection info created for process 10040, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 05:00:37,033 [root] DEBUG: 8268: CreateProcessHandler: Injection info set for new process 10788: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-29 05:00:37,033 [root] DEBUG: 8268: CreateProcessHandler: Injection info set for new process 10788: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-29 05:00:37,034 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 10788
2026-05-29 05:00:37,034 [lib.api.process] INFO: Monitor config for process 10788: C:\lpw_albt\dll\10788.ini
2026-05-29 05:00:38,042 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:38,043 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\ujJJun.dll, loader C:\lpw_albt\bin\IJlvWFq.exe
2026-05-29 05:00:38,049 [root] DEBUG: Loader: Injecting process 10788 (thread 10792) with C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:38,049 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:38,050 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\ujJJun.dll.
2026-05-29 05:00:38,051 [lib.api.process] INFO: Injected into 32-bit <Process 10788 MicrosoftEdgeUpdate.exe>
2026-05-29 05:00:38,052 [root] DEBUG: 8268: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-29 05:00:38,061 [root] DEBUG: 10788: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:38,061 [root] DEBUG: 10788: Interactive desktop enabled.
2026-05-29 05:00:38,062 [root] DEBUG: 10788: Dropped file limit defaulting to 100.
2026-05-29 05:00:38,063 [root] DEBUG: 10788: Disabling sleep skipping.
2026-05-29 05:00:38,065 [root] DEBUG: 10788: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:38,065 [root] DEBUG: 10788: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 05:00:38,067 [root] DEBUG: 10788: Monitor initialised: 32-bit capemon loaded in process 10788 at 0x6abe0000, thread 10792, image base 0x150000, stack from 0x25d4000-0x25e0000
2026-05-29 05:00:38,067 [root] DEBUG: 10788: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4yMzMuMyIgc2hlbGxfdmVyc2lvbj0iMS4zLjIzMy4zIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0E5QUI0QjlBLTAwRDEtNEZDRi05RkQxLUNEOEY2NURCRTk4Rn0iIHVzZXJpZD0iezU4MTY0NzY3LUVFREItNDcwOS04OTFBLUQ3OUUwMkM2QUNCRH0iIGluc3RhbGxzb3VyY2U9InNjaGVkdWxlciIgcmVxdWVzdGlkPSJ7MTQzMUREQ0YtQzY5Ny00QUZELTk1NEEtMjQ5QjgzN
2026-05-29 05:00:38,088 [root] DEBUG: 10788: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-29 05:00:38,102 [root] DEBUG: 10788: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-29 05:00:38,103 [root] DEBUG: 10788: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-29 05:00:38,106 [root] DEBUG: 10788: Hooked 632 out of 632 functions
2026-05-29 05:00:38,107 [root] DEBUG: 10788: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:38,110 [root] DEBUG: 10788: RestoreHeaders: Restored original import table.
2026-05-29 05:00:38,111 [root] INFO: Loaded monitor into process with pid 10788
2026-05-29 05:00:38,111 [root] DEBUG: 10788: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 10792).
2026-05-29 05:00:38,112 [root] DEBUG: 10788: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 05:00:38,114 [root] DEBUG: 10788: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:38,117 [root] DEBUG: 10788: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-29 05:00:38,117 [root] DEBUG: 10788: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-29 05:00:38,118 [root] DEBUG: 10788: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-29 05:00:38,121 [root] DEBUG: 10788: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-29 05:00:38,122 [root] DEBUG: 10788: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-29 05:00:38,122 [root] DEBUG: 10788: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-29 05:00:38,123 [root] DEBUG: 10788: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-29 05:00:38,123 [root] DEBUG: 10788: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-29 05:00:38,123 [root] DEBUG: 10788: DLL loaded at 0x6AEB0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-29 05:00:38,128 [root] DEBUG: 10788: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 05:00:38,128 [root] DEBUG: 10788: DLL loaded at 0x6A9B0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-29 05:00:38,133 [root] DEBUG: 10788: DLL loaded at 0x6F2A0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-29 05:00:38,134 [root] DEBUG: 10788: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-29 05:00:38,135 [root] DEBUG: 10788: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 05:00:38,135 [root] DEBUG: 10788: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-29 05:00:38,137 [root] DEBUG: 10788: DLL loaded at 0x6A8F0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-29 05:00:38,137 [root] DEBUG: 10788: DLL loaded at 0x6A910000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-29 05:00:38,138 [root] DEBUG: 10788: DLL loaded at 0x6A980000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-29 05:00:38,139 [root] DEBUG: 10788: DLL loaded at 0x6F290000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-29 05:00:38,140 [root] DEBUG: 10788: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 05:00:38,143 [root] DEBUG: 10788: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 05:00:38,143 [root] DEBUG: 10788: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-29 05:00:38,144 [root] DEBUG: 10788: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-29 05:00:38,148 [root] DEBUG: 10788: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-29 05:00:38,165 [root] DEBUG: 10788: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-29 05:00:38,166 [root] DEBUG: 10788: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-29 05:00:38,169 [root] DEBUG: 10788: DLL loaded at 0x755F0000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-29 05:00:38,177 [root] DEBUG: 10788: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\Iphlpapi (0x32000 bytes).
2026-05-29 05:00:38,177 [root] DEBUG: 10788: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-29 05:00:38,178 [root] DEBUG: 10788: DLL loaded at 0x73F80000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-29 05:00:38,179 [root] DEBUG: 10788: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 05:00:38,180 [root] DEBUG: 10788: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 05:00:38,182 [root] DEBUG: 10788: DLL loaded at 0x73E90000: C:\Windows\SYSTEM32\diagnosticdataquery (0xc000 bytes).
2026-05-29 05:00:38,183 [root] DEBUG: 10788: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-29 05:00:38,184 [root] DEBUG: 10788: DLL loaded at 0x6F0B0000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-29 05:00:38,189 [root] DEBUG: 10788: DLL loaded at 0x73EB0000: C:\Windows\System32\netprofm (0x32000 bytes).
2026-05-29 05:00:38,200 [root] DEBUG: 10788: DLL loaded at 0x73EA0000: C:\Windows\System32\npmproxy (0xa000 bytes).
2026-05-29 05:00:38,215 [root] DEBUG: 10788: DLL loaded at 0x75340000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-29 05:00:38,217 [root] DEBUG: 10788: DLL loaded at 0x6E3B0000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-29 05:00:38,220 [root] DEBUG: 10788: DLL loaded at 0x6BC10000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-29 05:00:38,231 [root] DEBUG: 10788: DLL loaded at 0x6AA10000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-29 05:00:38,232 [root] DEBUG: 10788: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-29 05:00:38,233 [root] DEBUG: 10788: DLL loaded at 0x6E2F0000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-29 05:00:38,236 [root] DEBUG: 10788: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-29 05:00:38,237 [root] DEBUG: 10788: DLL loaded at 0x6D030000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-29 05:00:38,263 [root] DEBUG: 10788: DLL loaded at 0x6CFD0000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-29 05:00:38,279 [root] DEBUG: 10788: DLL loaded at 0x6CF50000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-29 05:00:38,302 [root] DEBUG: 10788: DLL loaded at 0x6CF40000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-29 05:00:38,302 [root] DEBUG: 10788: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 05:00:38,304 [root] DEBUG: 10788: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 05:00:38,305 [root] DEBUG: 10788: DLL loaded at 0x6CEF0000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-29 05:00:38,307 [root] DEBUG: 10788: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-29 05:00:38,606 [root] DEBUG: 10788: DLL loaded at 0x6E2E0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-05-29 05:00:38,611 [root] INFO: Added new file to list with pid 10788 and path C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log
2026-05-29 05:00:38,613 [root] DEBUG: 10788: NtTerminateProcess hook: Attempting to dump process 10788
2026-05-29 05:00:38,613 [root] DEBUG: 10788: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:00:38,618 [root] INFO: Process with pid 10788 has terminated
2026-05-29 05:00:38,629 [root] DEBUG: 8268: NtTerminateProcess hook: Attempting to dump process 8268
2026-05-29 05:00:38,630 [root] DEBUG: 8268: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:00:38,636 [root] INFO: Process with pid 8268 has terminated
2026-05-29 05:00:45,012 [root] DEBUG: 7772: CreateProcessHandler: Injection info set for new process 2692: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 05:00:45,014 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 2692
2026-05-29 05:00:45,015 [root] DEBUG: 7772: ProcessMessage: Skipping monitoring process 2692
2026-05-29 05:00:45,365 [root] INFO: Process with pid 7772 appears to have terminated
2026-05-29 05:00:45,369 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-29 05:00:46,387 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 2548: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF71E220000
2026-05-29 05:00:46,388 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 2548
2026-05-29 05:00:46,389 [lib.api.process] INFO: Monitor config for process 2548: C:\lpw_albt\dll\2548.ini
2026-05-29 05:00:46,390 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:46,925 [root] DEBUG: 4484: DLL loaded at 0x00007FFF17280000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-29 05:00:46,993 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-29 05:00:46,994 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:46,998 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:47,008 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:47,010 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00000000031C0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00000000031C0042, thread 8536).
2026-05-29 05:00:47,010 [root] DEBUG: 4484: DumpPEsInRange: Scanning range 0x00000000031C0000 - 0x00000000031C0133.
2026-05-29 05:00:47,011 [root] DEBUG: 4484: ScanForDisguisedPE: Size too small: 0x133 bytes
2026-05-29 05:00:47,013 [lib.common.results] INFO: Uploading file C:\zDtLzmEP\CAPE\4484_451470929552026 to CAPE\cb93ebd16a61eff38a9b0d97dfb01d7b39f83cd3477037bb33ca65198936e644; Size is 307; Max size: 100000000
2026-05-29 05:00:47,017 [root] DEBUG: 4484: DumpMemory: Payload successfully created: C:\zDtLzmEP\CAPE\4484_451470929552026 (size 307 bytes)
2026-05-29 05:00:47,018 [root] DEBUG: 4484: DumpRegion: Dumped entire allocation from 0x00000000031C0000, size 4096 bytes.
2026-05-29 05:00:47,019 [root] DEBUG: 4484: ProcessTrackedRegion: Dumped region at 0x00000000031C0000.
2026-05-29 05:00:47,020 [root] DEBUG: 4484: YaraScan: Scanning 0x00000000031C0000, size 0x133
2026-05-29 05:00:47,022 [root] DEBUG: 4484: Monitor config - unrecognised key host-ip.
2026-05-29 05:00:47,022 [root] DEBUG: 4484: Monitor config - unrecognised key host-port.
2026-05-29 05:00:47,023 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:47,024 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-29 05:00:47,043 [root] DEBUG: 4484: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:00:47,070 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 05:00:47,070 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 05:00:47,071 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 05:00:47,071 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 05:00:47,071 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 05:00:47,071 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 05:00:47,071 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 05:00:47,072 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 05:00:47,081 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:47,086 [root] DEBUG: Loader: Injecting process 2548 (thread 8932) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:47,087 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:47,087 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:00:47,088 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:47,088 [root] DEBUG: 4484: set_hooks: Unable to hook LockResource
2026-05-29 05:00:47,089 [lib.api.process] INFO: Injected into 64-bit <Process 2548 elevation_service.exe>
2026-05-29 05:00:47,090 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 2548
2026-05-29 05:00:47,092 [lib.api.process] INFO: Monitor config for process 2548: C:\lpw_albt\dll\2548.ini
2026-05-29 05:00:47,093 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:47,118 [root] DEBUG: 4484: Hooked 627 out of 628 functions
2026-05-29 05:00:47,169 [root] INFO: Loaded monitor into process with pid 4484
2026-05-29 05:00:47,173 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-29 05:00:47,174 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:47,692 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 05:00:47,692 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 05:00:47,693 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 05:00:47,693 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 05:00:47,693 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 05:00:47,694 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 05:00:47,694 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 05:00:47,694 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 05:00:47,703 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:47,707 [root] DEBUG: Loader: Injecting process 2548 (thread 8932) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:47,708 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:47,708 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:47,710 [lib.api.process] INFO: Injected into 64-bit <Process 2548 elevation_service.exe>
2026-05-29 05:00:47,711 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 2548
2026-05-29 05:00:47,711 [lib.api.process] INFO: Monitor config for process 2548: C:\lpw_albt\dll\2548.ini
2026-05-29 05:00:47,712 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:48,312 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 05:00:48,312 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 05:00:48,313 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 05:00:48,313 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 05:00:48,314 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 05:00:48,314 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 05:00:48,314 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 05:00:48,314 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 05:00:48,323 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:48,328 [root] DEBUG: Loader: Injecting process 2548 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:48,329 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8932, handle 0x80
2026-05-29 05:00:48,330 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:48,331 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:48,332 [lib.api.process] INFO: Injected into 64-bit <Process 2548 elevation_service.exe>
2026-05-29 05:00:48,339 [root] DEBUG: 2548: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:48,341 [root] DEBUG: 2548: Interactive desktop enabled.
2026-05-29 05:00:48,342 [root] DEBUG: 2548: Dropped file limit defaulting to 100.
2026-05-29 05:00:48,348 [root] DEBUG: 2548: Disabling sleep skipping.
2026-05-29 05:00:48,350 [root] DEBUG: 2548: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:48,361 [root] DEBUG: 2548: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:48,362 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,387 [root] DEBUG: 2548: Monitor initialised: 64-bit capemon loaded in process 2548 at 0x00007FFF18250000, thread 8932, image base 0x00007FF71E220000, stack from 0x000000A9BDAF4000-0x000000A9BDB00000
2026-05-29 05:00:48,387 [root] DEBUG: 2548: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-29 05:00:48,397 [root] DEBUG: 2548: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:00:48,418 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:00:48,419 [root] DEBUG: 2548: set_hooks: Unable to hook LockResource
2026-05-29 05:00:48,424 [root] DEBUG: 2548: Hooked 627 out of 628 functions
2026-05-29 05:00:48,444 [root] DEBUG: 2548: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:48,457 [root] DEBUG: 2548: RestoreHeaders: Restored original import table.
2026-05-29 05:00:48,458 [root] INFO: Loaded monitor into process with pid 2548
2026-05-29 05:00:48,461 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,482 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,504 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,531 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,554 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,577 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,598 [root] DEBUG: 2548: caller_dispatch: Scanning calling region at 0x00007FF71E220000...
2026-05-29 05:00:48,599 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,600 [root] DEBUG: 2548: caller_dispatch: Added region at 0x00007FF71E220000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF71E35B9D6, thread 8932).
2026-05-29 05:00:48,601 [root] DEBUG: 2548: YaraScan: Scanning 0x00007FF71E220000, size 0x3bf4c0
2026-05-29 05:00:48,622 [root] DEBUG: 2548: ProcessImageBase: Main module image at 0x00007FF71E220000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:48,624 [root] DEBUG: 2548: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-29 05:00:48,634 [root] DEBUG: 2548: ProcessImageBase: Main module image at 0x00007FF71E220000 unmodified (entropy change 8.278925e-06)
2026-05-29 05:00:48,639 [root] DEBUG: 2548: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:00:48,646 [root] DEBUG: 2548: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:00:48,656 [root] DEBUG: 2548: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:00:48,675 [root] DEBUG: 2548: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-29 05:00:48,714 [root] DEBUG: 2548: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-29 05:00:48,722 [root] DEBUG: 2548: NtTerminateProcess hook: Attempting to dump process 2548
2026-05-29 05:00:48,725 [root] DEBUG: 2548: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:00:48,732 [root] DEBUG: 2548: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 8932).
2026-05-29 05:00:48,733 [root] DEBUG: 2548: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-29 05:00:48,739 [root] INFO: Process with pid 2548 has terminated
2026-05-29 05:00:49,253 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-29 05:00:49,254 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-29 05:00:49,277 [root] DEBUG: 4484: DLL loaded at 0x00007FFF16E40000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-29 05:00:49,279 [root] DEBUG: 4484: DLL loaded at 0x00007FFF16E40000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-29 05:00:49,323 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFB0F0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-29 05:00:49,325 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFB0F0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-29 05:00:49,403 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 05:00:49,405 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 8044, handle 0x1f28: Error obtaining target process name
2026-05-29 05:00:49,407 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 05:00:49,408 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6136, handle 0x26ac: Error obtaining target process name
2026-05-29 05:00:49,408 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 05:00:49,409 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5128, handle 0x2854: Error obtaining target process name
2026-05-29 05:00:49,409 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 05:00:49,410 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6400, handle 0x2850: Error obtaining target process name
2026-05-29 05:00:49,938 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-29 05:00:49,947 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-29 05:00:49,954 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11880: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-29 05:00:49,955 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11880
2026-05-29 05:00:49,956 [lib.api.process] INFO: Monitor config for process 11880: C:\lpw_albt\dll\11880.ini
2026-05-29 05:00:49,957 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:49,961 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:49,969 [root] DEBUG: Loader: Injecting process 11880 (thread 11884) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:49,971 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:49,972 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:49,976 [lib.api.process] INFO: Injected into 64-bit <Process 11880 dllhost.exe>
2026-05-29 05:00:49,978 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11880
2026-05-29 05:00:49,978 [lib.api.process] INFO: Monitor config for process 11880: C:\lpw_albt\dll\11880.ini
2026-05-29 05:00:49,981 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:49,986 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:49,990 [root] DEBUG: Loader: Injecting process 11880 (thread 11884) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:49,991 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:49,993 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:49,997 [lib.api.process] INFO: Injected into 64-bit <Process 11880 dllhost.exe>
2026-05-29 05:00:50,009 [root] DEBUG: 11880: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:50,011 [root] DEBUG: 11880: Interactive desktop enabled.
2026-05-29 05:00:50,012 [root] DEBUG: 11880: Dropped file limit defaulting to 100.
2026-05-29 05:00:50,031 [root] DEBUG: 11880: Disabling sleep skipping.
2026-05-29 05:00:50,033 [root] DEBUG: 11880: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:50,046 [root] DEBUG: 11880: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:50,047 [root] DEBUG: 11880: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:00:50,048 [root] DEBUG: 11880: Monitor initialised: 64-bit capemon loaded in process 11880 at 0x00007FFF18250000, thread 11884, image base 0x00007FF6706B0000, stack from 0x000000140D6F4000-0x000000140D700000
2026-05-29 05:00:50,049 [root] DEBUG: 11880: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-29 05:00:50,063 [root] DEBUG: 11880: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:00:50,090 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:00:50,092 [root] DEBUG: 11880: set_hooks: Unable to hook LockResource
2026-05-29 05:00:50,097 [root] DEBUG: 11880: Hooked 627 out of 628 functions
2026-05-29 05:00:50,099 [root] DEBUG: 11880: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:50,105 [root] DEBUG: 11880: RestoreHeaders: Restored original import table.
2026-05-29 05:00:50,107 [root] INFO: Loaded monitor into process with pid 11880
2026-05-29 05:00:50,110 [root] DEBUG: 11880: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 11884).
2026-05-29 05:00:50,111 [root] DEBUG: 11880: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:00:50,113 [root] DEBUG: 11880: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:50,118 [root] DEBUG: 11880: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:00:50,120 [root] DEBUG: 11880: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:00:50,123 [root] DEBUG: 11880: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:00:50,137 [root] DEBUG: 11880: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 05:00:50,153 [root] DEBUG: 11880: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:00:50,154 [root] DEBUG: 11880: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-29 05:00:50,161 [root] DEBUG: 11880: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-29 05:00:50,185 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-29 05:00:51,065 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-29 05:00:51,066 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-29 05:00:51,072 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13052: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF627A60000
2026-05-29 05:00:51,073 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 13052
2026-05-29 05:00:51,073 [lib.api.process] INFO: Monitor config for process 13052: C:\lpw_albt\dll\13052.ini
2026-05-29 05:00:51,075 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:51,077 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:51,082 [root] DEBUG: Loader: Injecting process 13052 (thread 13056) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:51,083 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:51,084 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:51,085 [lib.api.process] INFO: Injected into 64-bit <Process 13052 SecurityHealthHost.exe>
2026-05-29 05:00:51,087 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 13052
2026-05-29 05:00:51,088 [lib.api.process] INFO: Monitor config for process 13052: C:\lpw_albt\dll\13052.ini
2026-05-29 05:00:51,089 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:51,094 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:51,100 [root] DEBUG: Loader: Injecting process 13052 (thread 13056) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:51,102 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:51,103 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:51,105 [lib.api.process] INFO: Injected into 64-bit <Process 13052 SecurityHealthHost.exe>
2026-05-29 05:00:51,114 [root] DEBUG: 13052: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:51,114 [root] DEBUG: 13052: Interactive desktop enabled.
2026-05-29 05:00:51,115 [root] DEBUG: 13052: Dropped file limit defaulting to 100.
2026-05-29 05:00:51,118 [root] DEBUG: 13052: Disabling sleep skipping.
2026-05-29 05:00:51,118 [root] DEBUG: 13052: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:51,131 [root] DEBUG: 13052: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:51,131 [root] DEBUG: 13052: YaraScan: Scanning 0x00007FF627A60000, size 0x19174
2026-05-29 05:00:51,133 [root] DEBUG: 13052: Monitor initialised: 64-bit capemon loaded in process 13052 at 0x00007FFF18250000, thread 13056, image base 0x00007FF627A60000, stack from 0x0000008C31DC4000-0x0000008C31DD0000
2026-05-29 05:00:51,133 [root] DEBUG: 13052: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-29 05:00:51,144 [root] DEBUG: 13052: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:00:51,167 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:00:51,168 [root] DEBUG: 13052: set_hooks: Unable to hook LockResource
2026-05-29 05:00:51,176 [root] DEBUG: 13052: Hooked 627 out of 628 functions
2026-05-29 05:00:51,178 [root] DEBUG: 13052: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:51,183 [root] DEBUG: 13052: RestoreHeaders: Restored original import table.
2026-05-29 05:00:51,184 [root] INFO: Loaded monitor into process with pid 13052
2026-05-29 05:00:51,185 [root] DEBUG: 13052: caller_dispatch: Added region at 0x00007FF627A60000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x00007FF627A6D9A9, thread 13056).
2026-05-29 05:00:51,186 [root] DEBUG: 13052: YaraScan: Scanning 0x00007FF627A60000, size 0x19174
2026-05-29 05:00:51,188 [root] DEBUG: 13052: ProcessImageBase: Main module image at 0x00007FF627A60000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:51,190 [root] DEBUG: 13052: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:00:51,192 [root] DEBUG: 13052: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:00:51,193 [root] DEBUG: 13052: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:00:51,210 [root] DEBUG: 13052: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-29 05:00:51,211 [root] DEBUG: 13052: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:00:51,211 [root] DEBUG: 13052: DLL loaded at 0x00007FFF16300000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-29 05:00:51,225 [root] DEBUG: 13052: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-29 05:00:51,230 [root] DEBUG: 13052: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-29 05:00:51,237 [root] DEBUG: 13052: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:00:51,238 [root] DEBUG: 13052: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-29 05:00:51,239 [root] DEBUG: 13052: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-29 05:00:51,240 [root] DEBUG: 13052: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-29 05:00:51,240 [root] DEBUG: 13052: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-29 05:00:51,242 [root] DEBUG: 13052: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-29 05:00:51,246 [root] DEBUG: 13052: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-29 05:00:51,254 [root] DEBUG: 13052: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 05:00:51,265 [root] DEBUG: 13052: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-29 05:00:51,296 [root] DEBUG: 13052: NtTerminateProcess hook: Attempting to dump process 13052
2026-05-29 05:00:51,297 [root] DEBUG: 13052: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:00:51,298 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE131000, size: 0x1000.
2026-05-29 05:00:51,304 [root] DEBUG: 4484: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-29 05:00:51,305 [root] INFO: Process with pid 13052 has terminated
2026-05-29 05:00:51,306 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE121000, size: 0x1000.
2026-05-29 05:00:51,311 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-29 05:00:51,312 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:00:51,314 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-29 05:00:51,315 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:00:51,328 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-29 05:00:51,331 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-29 05:00:51,332 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:00:51,333 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-29 05:00:51,334 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:00:51,410 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13428: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF6C4CC0000
2026-05-29 05:00:51,412 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 13428
2026-05-29 05:00:51,413 [lib.api.process] INFO: Monitor config for process 13428: C:\lpw_albt\dll\13428.ini
2026-05-29 05:00:51,414 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,050 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,055 [root] DEBUG: Loader: Injecting process 13428 (thread 13432) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,056 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:52,057 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,058 [lib.api.process] INFO: Injected into 64-bit <Process 13428 ShellExperienceHost.exe>
2026-05-29 05:00:52,059 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 13428
2026-05-29 05:00:52,060 [lib.api.process] INFO: Monitor config for process 13428: C:\lpw_albt\dll\13428.ini
2026-05-29 05:00:52,060 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,769 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 13836: C:\Windows\system32\sppsvc.exe, ImageBase: 0x0000000000000000
2026-05-29 05:00:52,771 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 13840
2026-05-29 05:00:52,771 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 13836
2026-05-29 05:00:52,772 [lib.api.process] INFO: Monitor config for process 13836: C:\lpw_albt\dll\13836.ini
2026-05-29 05:00:52,773 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,778 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,783 [root] DEBUG: Loader: Injecting process 13836 (thread 13840) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,785 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\13836.ini to system path C:\13836.ini
2026-05-29 05:00:52,787 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 13836 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:00:52,788 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,790 [lib.api.process] INFO: Injected into 64-bit <Process 13836 sppsvc.exe>
2026-05-29 05:00:52,792 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 13840
2026-05-29 05:00:52,793 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 13836
2026-05-29 05:00:52,797 [lib.api.process] INFO: Monitor config for process 13836: C:\lpw_albt\dll\13836.ini
2026-05-29 05:00:52,797 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,803 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,808 [root] DEBUG: Loader: Injecting process 13836 (thread 13840) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,810 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\13836.ini to system path C:\13836.ini
2026-05-29 05:00:52,811 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 13836 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:00:52,812 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,814 [lib.api.process] INFO: Injected into 64-bit <Process 13836 sppsvc.exe>
2026-05-29 05:00:52,816 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 13836
2026-05-29 05:00:52,818 [lib.api.process] INFO: Monitor config for process 13836: C:\lpw_albt\dll\13836.ini
2026-05-29 05:00:52,818 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,823 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,830 [root] DEBUG: Loader: Injecting process 13836 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,831 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\13836.ini to system path C:\13836.ini
2026-05-29 05:00:52,832 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 14068: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-29 05:00:52,833 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 13836 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:00:52,835 [root] INFO: Announced 64-bit process name: svchost.exe pid: 14068
2026-05-29 05:00:52,835 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,836 [lib.api.process] INFO: Monitor config for process 14068: C:\lpw_albt\dll\14068.ini
2026-05-29 05:00:52,837 [lib.api.process] INFO: Injected into 64-bit <Process 13836 sppsvc.exe>
2026-05-29 05:00:52,838 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,842 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,849 [root] DEBUG: Loader: Injecting process 14068 (thread 14072) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,851 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:52,852 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,853 [lib.api.process] INFO: Injected into 64-bit <Process 14068 svchost.exe>
2026-05-29 05:00:52,855 [root] INFO: Announced 64-bit process name: svchost.exe pid: 14068
2026-05-29 05:00:52,855 [lib.api.process] INFO: Monitor config for process 14068: C:\lpw_albt\dll\14068.ini
2026-05-29 05:00:52,857 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,862 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,868 [root] DEBUG: Loader: Injecting process 14068 (thread 14072) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,870 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:52,871 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,874 [lib.api.process] INFO: Injected into 64-bit <Process 14068 svchost.exe>
2026-05-29 05:00:52,876 [root] INFO: Announced 64-bit process name: svchost.exe pid: 14068
2026-05-29 05:00:52,877 [lib.api.process] INFO: Monitor config for process 14068: C:\lpw_albt\dll\14068.ini
2026-05-29 05:00:52,877 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:52,881 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,886 [root] DEBUG: Loader: Injecting process 14068 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,887 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14072, handle 0x124
2026-05-29 05:00:52,889 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:52,890 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,891 [lib.api.process] INFO: Injected into 64-bit <Process 14068 svchost.exe>
2026-05-29 05:00:52,900 [root] DEBUG: 14068: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:52,901 [root] DEBUG: 14068: Interactive desktop enabled.
2026-05-29 05:00:52,902 [root] DEBUG: 14068: Dropped file limit defaulting to 100.
2026-05-29 05:00:52,905 [root] DEBUG: 14068: Disabling sleep skipping.
2026-05-29 05:00:52,907 [root] DEBUG: 14068: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:52,919 [root] DEBUG: 14068: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:52,921 [root] DEBUG: 14068: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-29 05:00:52,922 [root] DEBUG: 14068: Monitor initialised: 64-bit capemon loaded in process 14068 at 0x00007FFF18250000, thread 14072, image base 0x00007FF7BF220000, stack from 0x000000FE84744000-0x000000FE84750000
2026-05-29 05:00:52,923 [root] DEBUG: 14068: Commandline: C:\Windows\System32\svchost.exe -k WerSvcGroup
2026-05-29 05:00:52,938 [root] DEBUG: 14068: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:00:52,962 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:00:52,962 [root] DEBUG: 14068: set_hooks: Unable to hook LockResource
2026-05-29 05:00:52,967 [root] DEBUG: 14068: Hooked 627 out of 628 functions
2026-05-29 05:00:52,968 [root] DEBUG: 14068: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:52,973 [root] DEBUG: 14068: RestoreHeaders: Restored original import table.
2026-05-29 05:00:52,974 [root] INFO: Loaded monitor into process with pid 14068
2026-05-29 05:00:52,975 [root] DEBUG: 14068: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 14072).
2026-05-29 05:00:52,976 [root] DEBUG: 14068: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-29 05:00:52,977 [root] DEBUG: 14068: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:52,979 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:52,987 [root] DEBUG: Loader: Injecting process 13428 (thread 13432) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,988 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:52,988 [root] DEBUG: 14068: DLL loaded at 0x00007FFF523E0000: c:\windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:00:52,989 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:52,989 [root] DEBUG: 14068: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:00:52,990 [root] DEBUG: 14068: DLL loaded at 0x00007FFF3E0F0000: c:\windows\system32\WindowsPerformanceRecorderControl (0x12d000 bytes).
2026-05-29 05:00:52,991 [root] DEBUG: 14068: DLL loaded at 0x00007FFF16E00000: c:\windows\system32\WerEtw (0x3f000 bytes).
2026-05-29 05:00:52,990 [lib.api.process] INFO: Injected into 64-bit <Process 13428 ShellExperienceHost.exe>
2026-05-29 05:00:52,992 [root] DEBUG: 14068: DLL loaded at 0x00007FFF17270000: c:\windows\system32\wersvc (0x45000 bytes).
2026-05-29 05:00:52,993 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 13428
2026-05-29 05:00:52,994 [lib.api.process] INFO: Monitor config for process 13428: C:\lpw_albt\dll\13428.ini
2026-05-29 05:00:52,994 [root] DEBUG: 14068: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-29 05:00:52,995 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:53,001 [root] DEBUG: 14068: DLL loaded at 0x00007FFF55330000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-29 05:00:53,012 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,014 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,019 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,020 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,024 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,025 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,036 [root] DEBUG: 14068: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:00:53,046 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,047 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,051 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,052 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,056 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,057 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,068 [root] DEBUG: 14068: OpenProcessHandler: Injection info created for process 13884, handle 0x284: C:\lpw_albt\bin\PPLinject64.exe
2026-05-29 05:00:53,069 [root] DEBUG: 14068: OpenProcessHandler: Image base for process 13884 (handle 0x284): 0x00007FF64C4A0000.
2026-05-29 05:00:53,072 [root] DEBUG: 14068: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 05:00:53,075 [root] DEBUG: 14068: CreateProcessHandler: Injection info set for new process 13992: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF707980000
2026-05-29 05:00:53,076 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 13992
2026-05-29 05:00:53,081 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 13992
2026-05-29 05:00:53,161 [root] DEBUG: 14068: DLL loaded at 0x00007FFF47530000: c:\windows\system32\dbghelp (0x1e4000 bytes).
2026-05-29 05:00:53,162 [root] DEBUG: 14068: DLL loaded at 0x00007FFF474F0000: c:\windows\system32\dbgcore (0x34000 bytes).
2026-05-29 05:00:53,163 [root] DEBUG: 14068: DLL loaded at 0x00007FFF46350000: c:\windows\system32\faultrep (0x7b000 bytes).
2026-05-29 05:00:53,167 [root] DEBUG: 14068: DLL loaded at 0x00007FFF55330000: c:\windows\system32\wer (0xde000 bytes).
2026-05-29 05:00:53,176 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,177 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,182 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,182 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,185 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,186 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,202 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,202 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,206 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,207 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,210 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,211 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,223 [root] DEBUG: 14068: DLL loaded at 0x00007FFF57520000: c:\windows\system32\USERENV (0x2e000 bytes).
2026-05-29 05:00:53,225 [root] DEBUG: 14068: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-29 05:00:53,236 [root] DEBUG: 14068: CreateProcessHandler: Injection info set for new process 14088: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF707980000
2026-05-29 05:00:53,236 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 14088
2026-05-29 05:00:53,238 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 14088
2026-05-29 05:00:53,246 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14088, handle 0x195c: C:\Windows\System32\WerFault.exe
2026-05-29 05:00:53,351 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,352 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,356 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,357 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,361 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,362 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,369 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC4C8.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC4C8.tmp'
2026-05-29 05:00:53,370 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC4C8.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC4C8.tmp'
2026-05-29 05:00:53,400 [root] DEBUG: 14068: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-29 05:00:53,426 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERC4C8.tmp.csv
2026-05-29 05:00:53,432 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,434 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,438 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,440 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,444 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:00:53,447 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:00:53,455 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC527.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC527.tmp'
2026-05-29 05:00:53,457 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC527.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC527.tmp'
2026-05-29 05:00:53,470 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERC527.tmp.txt
2026-05-29 05:00:53,628 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:53,632 [root] DEBUG: Loader: Injecting process 13428 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:53,633 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13432, handle 0xb4
2026-05-29 05:00:53,633 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:00:53,634 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:53,635 [lib.api.process] INFO: Injected into 64-bit <Process 13428 ShellExperienceHost.exe>
2026-05-29 05:00:53,751 [root] DEBUG: 4484: DLL loaded at 0x0000000010670000: C:\Windows\system32\SearchFolder (0x6a000 bytes).
2026-05-29 05:00:53,752 [root] DEBUG: 4484: DLL loaded at 0x0000000010670000: C:\Windows\system32\SearchFolder (0x6a000 bytes).
2026-05-29 05:00:53,793 [root] DEBUG: 4484: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-29 05:00:53,795 [root] DEBUG: 4484: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-29 05:00:53,836 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14496, handle 0x22a4: C:\Windows\System32\rundll32.exe
2026-05-29 05:00:54,200 [root] DEBUG: 4484: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-29 05:00:54,316 [root] DEBUG: 4484: DLL loaded at 0x00007FFF13410000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-29 05:00:54,318 [root] DEBUG: 4484: DLL loaded at 0x00007FFF13410000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-29 05:00:54,423 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\SavedPictures.library-ms
2026-05-29 05:00:54,431 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
2026-05-29 05:00:54,439 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\CameraRoll.library-ms
2026-05-29 05:00:54,447 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
2026-05-29 05:00:54,455 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
2026-05-29 05:00:54,497 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 05:00:54,498 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5624, handle 0x26a0: Error obtaining target process name
2026-05-29 05:00:54,661 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-29 05:00:54,663 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-29 05:00:54,671 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F430000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-29 05:00:54,672 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F430000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-29 05:00:54,674 [root] DEBUG: 4484: DLL loaded at 0x00007FFF18990000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-29 05:00:54,675 [root] DEBUG: 4484: DLL loaded at 0x00007FFF18990000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-29 05:00:54,677 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2D0000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-29 05:00:54,678 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2D0000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-29 05:00:54,679 [root] DEBUG: 4484: DLL loaded at 0x000000000DD50000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-29 05:00:54,680 [root] DEBUG: 4484: DLL loaded at 0x000000000DD50000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-29 05:00:54,824 [root] DEBUG: 4484: DLL loaded at 0x00007FFF15420000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-29 05:00:54,825 [root] DEBUG: 4484: DLL loaded at 0x00007FFF15420000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-29 05:00:54,860 [root] DEBUG: 4484: DLL loaded at 0x00007FFF17F30000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-29 05:00:54,861 [root] DEBUG: 4484: DLL loaded at 0x00007FFF17F30000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-29 05:00:55,248 [root] INFO: Process with pid 11880 has terminated
2026-05-29 05:00:55,249 [root] DEBUG: 11880: NtTerminateProcess hook: Attempting to dump process 11880
2026-05-29 05:00:55,250 [root] DEBUG: 11880: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:00:55,734 [root] DEBUG: 4484: api-rate-cap: RegOpenKeyExW hook disabled due to rate
2026-05-29 05:00:55,760 [root] DEBUG: 4484: api-rate-cap: RtlSetCurrentTransaction hook disabled due to rate
2026-05-29 05:00:55,831 [root] DEBUG: 4484: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-29 05:00:56,852 [root] DEBUG: 4484: api-cap: NtQueryKey hook disabled due to count: 5000
2026-05-29 05:00:56,853 [root] DEBUG: 4484: api-cap: NtQueryKey hook disabled due to count: 5001
2026-05-29 05:00:56,871 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-29 05:00:56,927 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-29 05:00:57,087 [root] DEBUG: 4484: api-cap: NtClose hook disabled due to count: 5000
2026-05-29 05:00:57,140 [root] DEBUG: 4484: api-cap: NtOpenKeyEx hook disabled due to count: 5001
2026-05-29 05:00:57,142 [root] DEBUG: 4484: api-cap: NtOpenKeyEx hook disabled due to count: 5001
2026-05-29 05:00:57,186 [root] DEBUG: 4484: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-29 05:00:57,193 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8376: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-29 05:00:57,194 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8376
2026-05-29 05:00:57,195 [lib.api.process] INFO: Monitor config for process 8376: C:\lpw_albt\dll\8376.ini
2026-05-29 05:00:57,196 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:57,201 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:57,208 [root] DEBUG: Loader: Injecting process 8376 (thread 5696) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:57,209 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:57,210 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:57,212 [lib.api.process] INFO: Injected into 64-bit <Process 8376 dllhost.exe>
2026-05-29 05:00:57,213 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8376
2026-05-29 05:00:57,214 [lib.api.process] INFO: Monitor config for process 8376: C:\lpw_albt\dll\8376.ini
2026-05-29 05:00:57,215 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:00:57,221 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:00:57,225 [root] DEBUG: Loader: Injecting process 8376 (thread 5696) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:57,227 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:00:57,228 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:00:57,230 [lib.api.process] INFO: Injected into 64-bit <Process 8376 dllhost.exe>
2026-05-29 05:00:57,239 [root] DEBUG: 8376: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:00:57,241 [root] DEBUG: 8376: Interactive desktop enabled.
2026-05-29 05:00:57,242 [root] DEBUG: 8376: Dropped file limit defaulting to 100.
2026-05-29 05:00:57,244 [root] DEBUG: 8376: Disabling sleep skipping.
2026-05-29 05:00:57,248 [root] DEBUG: 8376: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:00:57,260 [root] DEBUG: 8376: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:00:57,264 [root] DEBUG: 8376: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:00:57,265 [root] DEBUG: 8376: Monitor initialised: 64-bit capemon loaded in process 8376 at 0x00007FFF18250000, thread 5696, image base 0x00007FF6706B0000, stack from 0x000000BC1A3C4000-0x000000BC1A3D0000
2026-05-29 05:00:57,265 [root] DEBUG: 8376: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-29 05:00:57,275 [root] DEBUG: 8376: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:00:57,297 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:00:57,298 [root] DEBUG: 8376: set_hooks: Unable to hook LockResource
2026-05-29 05:00:57,303 [root] DEBUG: 8376: Hooked 627 out of 628 functions
2026-05-29 05:00:57,304 [root] DEBUG: 8376: Syscall hook installed, syscall logging level 1
2026-05-29 05:00:57,309 [root] DEBUG: 8376: RestoreHeaders: Restored original import table.
2026-05-29 05:00:57,310 [root] INFO: Loaded monitor into process with pid 8376
2026-05-29 05:00:57,311 [root] DEBUG: 8376: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 5696).
2026-05-29 05:00:57,312 [root] DEBUG: 8376: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:00:57,314 [root] DEBUG: 8376: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:00:57,316 [root] DEBUG: 8376: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:00:57,317 [root] DEBUG: 8376: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:00:57,320 [root] DEBUG: 8376: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:00:57,335 [root] DEBUG: 8376: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 05:00:57,350 [root] DEBUG: 8376: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:00:57,351 [root] DEBUG: 8376: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-29 05:00:57,357 [root] DEBUG: 8376: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-29 05:00:57,370 [root] DEBUG: 8376: DLL loaded at 0x00007FFF51B20000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-29 05:00:57,373 [root] DEBUG: 8376: DLL loaded at 0x00007FFF47790000: C:\Windows\system32\PhotoMetadataHandler (0x84000 bytes).
2026-05-29 05:00:57,388 [root] DEBUG: 8376: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 05:00:58,659 [root] DEBUG: 4484: DLL loaded at 0x0000000010710000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-29 05:00:58,660 [root] DEBUG: 4484: DLL loaded at 0x0000000010710000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-29 05:00:58,710 [root] DEBUG: 4484: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-29 05:00:58,713 [root] DEBUG: 4484: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-29 05:01:02,468 [root] INFO: Process with pid 8376 has terminated
2026-05-29 05:01:02,469 [root] DEBUG: 8376: NtTerminateProcess hook: Attempting to dump process 8376
2026-05-29 05:01:02,470 [root] DEBUG: 8376: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:01:03,773 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 3976 (handle 0x2c48): 0x00007FF7BF860000.
2026-05-29 05:01:03,774 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 3976, handle 0x2c48: C:\Windows\System32\conhost.exe
2026-05-29 05:01:06,916 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-29 05:01:06,917 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-29 05:01:06,935 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-29 05:01:06,939 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE111000, size: 0x1000.
2026-05-29 05:01:06,940 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE101000, size: 0x1000.
2026-05-29 05:01:06,953 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE0F1000, size: 0x1000.
2026-05-29 05:01:06,963 [root] DEBUG: 4484: DLL loaded at 0x00007FFF162E0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-29 05:01:06,964 [root] DEBUG: 4484: DLL loaded at 0x00007FFF162E0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-29 05:01:06,982 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17348: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6D4740000
2026-05-29 05:01:06,984 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 17348
2026-05-29 05:01:06,985 [lib.api.process] INFO: Monitor config for process 17348: C:\lpw_albt\dll\17348.ini
2026-05-29 05:01:07,997 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:08,003 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:08,008 [root] DEBUG: Loader: Injecting process 17348 (thread 17352) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:08,008 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:08,009 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:08,011 [lib.api.process] INFO: Injected into 64-bit <Process 17348 CHXSmartScreen.exe>
2026-05-29 05:01:08,013 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 17348
2026-05-29 05:01:08,014 [lib.api.process] INFO: Monitor config for process 17348: C:\lpw_albt\dll\17348.ini
2026-05-29 05:01:08,015 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:08,023 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:08,029 [root] DEBUG: Loader: Injecting process 17348 (thread 17352) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:08,030 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:08,030 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:08,032 [lib.api.process] INFO: Injected into 64-bit <Process 17348 CHXSmartScreen.exe>
2026-05-29 05:01:08,033 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 17348
2026-05-29 05:01:08,034 [lib.api.process] INFO: Monitor config for process 17348: C:\lpw_albt\dll\17348.ini
2026-05-29 05:01:08,035 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:08,042 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:08,047 [root] DEBUG: Loader: Injecting process 17348 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:08,049 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17352, handle 0x120
2026-05-29 05:01:08,050 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:08,051 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:08,052 [lib.api.process] INFO: Injected into 64-bit <Process 17348 CHXSmartScreen.exe>
2026-05-29 05:01:08,331 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE0F0000.
2026-05-29 05:01:08,332 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:01:08,334 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE110000.
2026-05-29 05:01:08,334 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:01:08,336 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE100000.
2026-05-29 05:01:08,337 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:01:08,338 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-29 05:01:08,339 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:01:08,341 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-29 05:01:08,342 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-29 05:01:20,522 [root] DEBUG: 14068: OpenProcessHandler: Injection info created for process 4484, handle 0x328: C:\Windows\explorer.exe
2026-05-29 05:01:20,523 [root] DEBUG: 14068: OpenProcessHandler: Image base for process 4484 (handle 0x328): 0x00007FF79BC10000.
2026-05-29 05:01:20,524 [root] DEBUG: 14068: CreateProcessHandler: Injection info set for new process 17680: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF707980000
2026-05-29 05:01:20,525 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 17680
2026-05-29 05:01:20,526 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 17680
2026-05-29 05:01:20,583 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,584 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,590 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,592 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,597 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,597 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,613 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,614 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,618 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,619 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,623 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,623 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,642 [root] DEBUG: 14068: CreateProcessHandler: Injection info set for new process 17768: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF707980000
2026-05-29 05:01:20,643 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 17768
2026-05-29 05:01:20,644 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 17768
2026-05-29 05:01:20,682 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,683 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,688 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,689 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,692 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,693 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,712 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,714 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,718 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,719 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,723 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,723 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,748 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,749 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,759 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,759 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,764 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,766 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,783 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,784 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,789 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,790 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,794 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,799 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,888 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,890 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,895 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,895 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,900 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,901 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,910 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER3065.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER3065.tmp'
2026-05-29 05:01:20,912 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER3065.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER3065.tmp'
2026-05-29 05:01:20,938 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER3065.tmp.csv
2026-05-29 05:01:20,945 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,947 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,951 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,952 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,957 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:20,959 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:20,967 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER30A4.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER30A4.tmp'
2026-05-29 05:01:20,969 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER30A4.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER30A4.tmp'
2026-05-29 05:01:20,974 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER30A4.tmp.txt
2026-05-29 05:01:21,349 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:21,351 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:21,354 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:21,355 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:21,359 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:21,360 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:21,370 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER323C.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER323C.tmp'
2026-05-29 05:01:21,372 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER323C.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER323C.tmp'
2026-05-29 05:01:21,400 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER323C.tmp.csv
2026-05-29 05:01:21,406 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:21,408 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:21,413 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:21,417 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:21,425 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:21,426 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:21,437 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER327B.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER327B.tmp'
2026-05-29 05:01:21,438 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER327B.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER327B.tmp'
2026-05-29 05:01:21,443 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER327B.tmp.txt
2026-05-29 05:01:21,766 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 18360: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-29 05:01:21,769 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 18360
2026-05-29 05:01:21,770 [lib.api.process] INFO: Monitor config for process 18360: C:\lpw_albt\dll\18360.ini
2026-05-29 05:01:21,882 [root] INFO: Process with pid 4484 appears to have terminated
2026-05-29 05:01:22,032 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17372: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF659080000
2026-05-29 05:01:22,034 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17372
2026-05-29 05:01:22,035 [lib.api.process] INFO: Monitor config for process 17372: C:\lpw_albt\dll\17372.ini
2026-05-29 05:01:22,038 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:22,374 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 448: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF7ED740000
2026-05-29 05:01:22,376 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 448
2026-05-29 05:01:22,377 [lib.api.process] INFO: Monitor config for process 448: C:\lpw_albt\dll\448.ini
2026-05-29 05:01:22,379 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:22,779 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:22,784 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:22,789 [root] DEBUG: Loader: Injecting process 18360 (thread 18364) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:22,791 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:22,793 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:22,794 [lib.api.process] INFO: Injected into 64-bit <Process 18360 dllhost.exe>
2026-05-29 05:01:22,796 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 18360
2026-05-29 05:01:22,797 [lib.api.process] INFO: Monitor config for process 18360: C:\lpw_albt\dll\18360.ini
2026-05-29 05:01:22,799 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:22,805 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:22,810 [root] DEBUG: Loader: Injecting process 18360 (thread 18364) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:22,812 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:22,812 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:22,813 [lib.api.process] INFO: Injected into 64-bit <Process 18360 dllhost.exe>
2026-05-29 05:01:22,819 [root] DEBUG: 18360: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:01:22,821 [root] DEBUG: 18360: Interactive desktop enabled.
2026-05-29 05:01:22,821 [root] DEBUG: 18360: Dropped file limit defaulting to 100.
2026-05-29 05:01:22,823 [root] DEBUG: 18360: Disabling sleep skipping.
2026-05-29 05:01:22,825 [root] DEBUG: 18360: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:01:22,839 [root] DEBUG: 18360: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:01:22,841 [root] DEBUG: 18360: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:01:22,843 [root] DEBUG: 18360: Monitor initialised: 64-bit capemon loaded in process 18360 at 0x00007FFF18250000, thread 18364, image base 0x00007FF6706B0000, stack from 0x0000007B34EF4000-0x0000007B34F00000
2026-05-29 05:01:22,845 [root] DEBUG: 18360: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-29 05:01:22,856 [root] DEBUG: 18360: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:01:22,879 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:01:22,881 [root] DEBUG: 18360: set_hooks: Unable to hook LockResource
2026-05-29 05:01:22,885 [root] DEBUG: 18360: Hooked 627 out of 628 functions
2026-05-29 05:01:22,887 [root] DEBUG: 18360: Syscall hook installed, syscall logging level 1
2026-05-29 05:01:22,892 [root] DEBUG: 18360: RestoreHeaders: Restored original import table.
2026-05-29 05:01:22,894 [root] INFO: Loaded monitor into process with pid 18360
2026-05-29 05:01:22,896 [root] DEBUG: 18360: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 18364).
2026-05-29 05:01:22,897 [root] DEBUG: 18360: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:01:22,899 [root] DEBUG: 18360: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:01:22,904 [root] DEBUG: 18360: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:01:22,907 [root] DEBUG: 18360: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:01:22,910 [root] DEBUG: 18360: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:01:22,927 [root] DEBUG: 18360: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 05:01:22,942 [root] DEBUG: 18360: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:01:22,944 [root] DEBUG: 18360: DLL loaded at 0x00007FFF51390000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-29 05:01:22,951 [root] DEBUG: 18360: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-29 05:01:23,315 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:23,320 [root] DEBUG: Loader: Injecting process 17372 (thread 17612) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:23,322 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:23,323 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:23,325 [lib.api.process] INFO: Injected into 64-bit <Process 17372 StartMenuExperienceHost.exe>
2026-05-29 05:01:23,326 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17372
2026-05-29 05:01:23,327 [lib.api.process] INFO: Monitor config for process 17372: C:\lpw_albt\dll\17372.ini
2026-05-29 05:01:23,327 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:23,970 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:23,975 [root] DEBUG: Loader: Injecting process 448 (thread 1244) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:23,975 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:23,977 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:23,978 [lib.api.process] INFO: Injected into 64-bit <Process 448 TextInputHost.exe>
2026-05-29 05:01:23,980 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 448
2026-05-29 05:01:23,981 [lib.api.process] INFO: Monitor config for process 448: C:\lpw_albt\dll\448.ini
2026-05-29 05:01:23,981 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:24,373 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14696: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:01:24,375 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 14696
2026-05-29 05:01:24,375 [lib.api.process] INFO: Monitor config for process 14696: C:\lpw_albt\dll\14696.ini
2026-05-29 05:01:24,377 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:24,858 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:24,863 [root] DEBUG: Loader: Injecting process 17372 (thread 17612) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:24,864 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:24,865 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:24,866 [lib.api.process] INFO: Injected into 64-bit <Process 17372 StartMenuExperienceHost.exe>
2026-05-29 05:01:24,868 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17372
2026-05-29 05:01:24,870 [lib.api.process] INFO: Monitor config for process 17372: C:\lpw_albt\dll\17372.ini
2026-05-29 05:01:24,870 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:24,988 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-29 05:01:25,475 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:25,480 [root] DEBUG: Loader: Injecting process 448 (thread 1244) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:25,481 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:25,482 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:25,483 [lib.api.process] INFO: Injected into 64-bit <Process 448 TextInputHost.exe>
2026-05-29 05:01:25,484 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 448
2026-05-29 05:01:25,486 [lib.api.process] INFO: Monitor config for process 448: C:\lpw_albt\dll\448.ini
2026-05-29 05:01:25,487 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:25,824 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:25,829 [root] DEBUG: Loader: Injecting process 14696 (thread 6180) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:25,831 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:25,832 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:25,834 [lib.api.process] INFO: Injected into 64-bit <Process 14696 SearchApp.exe>
2026-05-29 05:01:25,836 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 14696
2026-05-29 05:01:25,837 [lib.api.process] INFO: Monitor config for process 14696: C:\lpw_albt\dll\14696.ini
2026-05-29 05:01:25,838 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:25,999 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 6216: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-29 05:01:26,000 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 4968
2026-05-29 05:01:26,000 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6216
2026-05-29 05:01:26,001 [lib.api.process] INFO: Monitor config for process 6216: C:\lpw_albt\dll\6216.ini
2026-05-29 05:01:26,003 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:26,009 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:26,015 [root] DEBUG: Loader: Injecting process 6216 (thread 4968) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,017 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\6216.ini to system path C:\6216.ini
2026-05-29 05:01:26,018 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 6216 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:01:26,019 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,020 [lib.api.process] INFO: Injected into 64-bit <Process 6216 svchost.exe>
2026-05-29 05:01:26,022 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 4968
2026-05-29 05:01:26,022 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6216
2026-05-29 05:01:26,023 [lib.api.process] INFO: Monitor config for process 6216: C:\lpw_albt\dll\6216.ini
2026-05-29 05:01:26,024 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:26,030 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:26,034 [root] DEBUG: Loader: Injecting process 6216 (thread 4968) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,036 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\6216.ini to system path C:\6216.ini
2026-05-29 05:01:26,038 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 6216 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:01:26,039 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,041 [lib.api.process] INFO: Injected into 64-bit <Process 6216 svchost.exe>
2026-05-29 05:01:26,042 [root] DEBUG: 14068: OpenProcessHandler: Injection info created for process 1964, handle 0x268: C:\lpw_albt\bin\PPLinject64.exe
2026-05-29 05:01:26,043 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6216
2026-05-29 05:01:26,043 [lib.api.process] INFO: Monitor config for process 6216: C:\lpw_albt\dll\6216.ini
2026-05-29 05:01:26,044 [root] DEBUG: 14068: OpenProcessHandler: Image base for process 1964 (handle 0x268): 0x00007FF64C4A0000.
2026-05-29 05:01:26,046 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:26,046 [root] DEBUG: 14068: CreateProcessHandler: Injection info set for new process 5624: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF707980000
2026-05-29 05:01:26,047 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 5624
2026-05-29 05:01:26,049 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 5624
2026-05-29 05:01:26,054 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:26,061 [root] DEBUG: Loader: Injecting process 6216 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,064 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\6216.ini to system path C:\6216.ini
2026-05-29 05:01:26,066 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 6216 C:\lpw_albt\dll\uwEeDg.dll
2026-05-29 05:01:26,067 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,069 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,069 [lib.api.process] INFO: Injected into 64-bit <Process 6216 svchost.exe>
2026-05-29 05:01:26,071 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,075 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,077 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,082 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,084 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,100 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,101 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,105 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,106 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,112 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,113 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,134 [root] DEBUG: 14068: CreateProcessHandler: Injection info set for new process 4700: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF707980000
2026-05-29 05:01:26,136 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 4700
2026-05-29 05:01:26,139 [root] DEBUG: 14068: ProcessMessage: Skipping monitoring process 4700
2026-05-29 05:01:26,250 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,253 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,256 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,258 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,262 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,264 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,274 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER4558.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER4558.tmp'
2026-05-29 05:01:26,277 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER4558.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER4558.tmp'
2026-05-29 05:01:26,303 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER4558.tmp.csv
2026-05-29 05:01:26,309 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,311 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,315 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,316 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,319 [root] DEBUG: 14068: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:01:26,321 [root] DEBUG: 14068: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:01:26,329 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER4588.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER4588.tmp'
2026-05-29 05:01:26,332 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER4588.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER4588.tmp'
2026-05-29 05:01:26,345 [root] INFO: Added new file to list with pid 14068 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER4588.tmp.txt
2026-05-29 05:01:26,605 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:26,611 [root] DEBUG: Loader: Injecting process 17372 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,612 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17612, handle 0xb4
2026-05-29 05:01:26,614 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:26,615 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:26,617 [lib.api.process] INFO: Injected into 64-bit <Process 17372 StartMenuExperienceHost.exe>
2026-05-29 05:01:27,044 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,050 [root] DEBUG: Loader: Injecting process 448 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,051 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1244, handle 0x120
2026-05-29 05:01:27,052 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,053 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,055 [lib.api.process] INFO: Injected into 64-bit <Process 448 TextInputHost.exe>
2026-05-29 05:01:27,260 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,265 [root] DEBUG: Loader: Injecting process 14696 (thread 6180) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,267 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,267 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,269 [lib.api.process] INFO: Injected into 64-bit <Process 14696 SearchApp.exe>
2026-05-29 05:01:27,271 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 14696
2026-05-29 05:01:27,272 [lib.api.process] INFO: Monitor config for process 14696: C:\lpw_albt\dll\14696.ini
2026-05-29 05:01:27,273 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,467 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17268: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:01:27,468 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17268
2026-05-29 05:01:27,469 [lib.api.process] INFO: Monitor config for process 17268: C:\lpw_albt\dll\17268.ini
2026-05-29 05:01:27,471 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2504: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:01:27,472 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,473 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5608: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 05:01:27,473 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2504
2026-05-29 05:01:27,474 [lib.api.process] INFO: Monitor config for process 2504: C:\lpw_albt\dll\2504.ini
2026-05-29 05:01:27,475 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 5608
2026-05-29 05:01:27,477 [lib.api.process] INFO: Monitor config for process 5608: C:\lpw_albt\dll\5608.ini
2026-05-29 05:01:27,478 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,479 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,480 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,484 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,485 [root] DEBUG: Loader: Injecting process 17268 (thread 5100) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,486 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:27,487 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,488 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,488 [root] DEBUG: Loader: Injecting process 5608 (thread 18048) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,490 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:27,490 [lib.api.process] INFO: Injected into 64-bit <Process 17268 backgroundTaskHost.exe>
2026-05-29 05:01:27,491 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,493 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17268
2026-05-29 05:01:27,494 [lib.api.process] INFO: Injected into 64-bit <Process 5608 backgroundTaskHost.exe>
2026-05-29 05:01:27,495 [lib.api.process] INFO: Monitor config for process 17268: C:\lpw_albt\dll\17268.ini
2026-05-29 05:01:27,495 [root] DEBUG: Loader: Injecting process 2504 (thread 5668) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,496 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,497 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 5608
2026-05-29 05:01:27,498 [lib.api.process] INFO: Monitor config for process 5608: C:\lpw_albt\dll\5608.ini
2026-05-29 05:01:27,499 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:27,501 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,501 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,504 [lib.api.process] INFO: Injected into 64-bit <Process 2504 backgroundTaskHost.exe>
2026-05-29 05:01:27,505 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2504
2026-05-29 05:01:27,506 [lib.api.process] INFO: Monitor config for process 2504: C:\lpw_albt\dll\2504.ini
2026-05-29 05:01:27,507 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,508 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,508 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,511 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,514 [root] DEBUG: Loader: Injecting process 17268 (thread 5100) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,515 [root] DEBUG: Loader: Injecting process 5608 (thread 18048) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,516 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,517 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,519 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,520 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,521 [root] DEBUG: Loader: Injecting process 2504 (thread 5668) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,521 [lib.api.process] INFO: Injected into 64-bit <Process 17268 backgroundTaskHost.exe>
2026-05-29 05:01:27,521 [lib.api.process] INFO: Injected into 64-bit <Process 5608 backgroundTaskHost.exe>
2026-05-29 05:01:27,522 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,524 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,524 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 5608
2026-05-29 05:01:27,525 [lib.api.process] INFO: Monitor config for process 5608: C:\lpw_albt\dll\5608.ini
2026-05-29 05:01:27,526 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,526 [lib.api.process] INFO: Injected into 64-bit <Process 2504 backgroundTaskHost.exe>
2026-05-29 05:01:27,526 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17268
2026-05-29 05:01:27,527 [lib.api.process] INFO: Monitor config for process 17268: C:\lpw_albt\dll\17268.ini
2026-05-29 05:01:27,527 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,528 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2504
2026-05-29 05:01:27,530 [lib.api.process] INFO: Monitor config for process 2504: C:\lpw_albt\dll\2504.ini
2026-05-29 05:01:27,531 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:27,533 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,535 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,538 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:27,540 [root] DEBUG: Loader: Injecting process 17268 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,541 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5100, handle 0xb4
2026-05-29 05:01:27,542 [root] DEBUG: Loader: Injecting process 5608 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,544 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,545 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 18048, handle 0x124
2026-05-29 05:01:27,546 [root] DEBUG: Loader: Injecting process 2504 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,547 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,549 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,549 [lib.api.process] INFO: Injected into 64-bit <Process 17268 backgroundTaskHost.exe>
2026-05-29 05:01:27,550 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5668, handle 0x128
2026-05-29 05:01:27,552 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,553 [lib.api.process] INFO: Injected into 64-bit <Process 5608 backgroundTaskHost.exe>
2026-05-29 05:01:27,554 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:27,556 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:27,558 [lib.api.process] INFO: Injected into 64-bit <Process 2504 backgroundTaskHost.exe>
2026-05-29 05:01:27,968 [root] INFO: Process with pid 18360 has terminated
2026-05-29 05:01:27,970 [root] DEBUG: 18360: NtTerminateProcess hook: Attempting to dump process 18360
2026-05-29 05:01:27,971 [root] DEBUG: 18360: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:01:28,686 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:28,691 [root] DEBUG: Loader: Injecting process 14696 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:28,692 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 6180, handle 0x120
2026-05-29 05:01:28,693 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:28,694 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:28,696 [lib.api.process] INFO: Injected into 64-bit <Process 14696 SearchApp.exe>
2026-05-29 05:01:28,713 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17612: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:01:28,714 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17612
2026-05-29 05:01:28,715 [lib.api.process] INFO: Monitor config for process 17612: C:\lpw_albt\dll\17612.ini
2026-05-29 05:01:28,718 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:30,482 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:30,486 [root] DEBUG: Loader: Injecting process 17612 (thread 5752) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:30,487 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:30,489 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:30,490 [lib.api.process] INFO: Injected into 64-bit <Process 17612 SearchApp.exe>
2026-05-29 05:01:30,494 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17612
2026-05-29 05:01:30,495 [lib.api.process] INFO: Monitor config for process 17612: C:\lpw_albt\dll\17612.ini
2026-05-29 05:01:30,496 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:32,037 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:32,042 [root] DEBUG: Loader: Injecting process 17612 (thread 5752) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:32,044 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:32,045 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:32,047 [lib.api.process] INFO: Injected into 64-bit <Process 17612 SearchApp.exe>
2026-05-29 05:01:32,050 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17612
2026-05-29 05:01:32,051 [lib.api.process] INFO: Monitor config for process 17612: C:\lpw_albt\dll\17612.ini
2026-05-29 05:01:32,051 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:33,665 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:33,670 [root] DEBUG: Loader: Injecting process 17612 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:33,671 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5752, handle 0x84
2026-05-29 05:01:33,673 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:33,674 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:33,675 [lib.api.process] INFO: Injected into 64-bit <Process 17612 SearchApp.exe>
2026-05-29 05:01:33,681 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17640: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:01:33,683 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17640
2026-05-29 05:01:33,684 [lib.api.process] INFO: Monitor config for process 17640: C:\lpw_albt\dll\17640.ini
2026-05-29 05:01:33,686 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:35,217 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:35,222 [root] DEBUG: Loader: Injecting process 17640 (thread 8560) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:35,224 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:35,225 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:35,226 [lib.api.process] INFO: Injected into 64-bit <Process 17640 SearchApp.exe>
2026-05-29 05:01:35,228 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17640
2026-05-29 05:01:35,229 [lib.api.process] INFO: Monitor config for process 17640: C:\lpw_albt\dll\17640.ini
2026-05-29 05:01:35,230 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:36,815 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:36,820 [root] DEBUG: Loader: Injecting process 17640 (thread 8560) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:36,822 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:36,823 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:36,824 [lib.api.process] INFO: Injected into 64-bit <Process 17640 SearchApp.exe>
2026-05-29 05:01:37,842 [root] INFO: Process with pid 17640 has terminated
2026-05-29 05:01:39,053 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 3728: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF6C4CC0000
2026-05-29 05:01:39,054 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 3728
2026-05-29 05:01:39,055 [lib.api.process] INFO: Monitor config for process 3728: C:\lpw_albt\dll\3728.ini
2026-05-29 05:01:39,061 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:40,652 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:40,656 [root] DEBUG: Loader: Injecting process 3728 (thread 3596) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:40,658 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:40,659 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:40,661 [lib.api.process] INFO: Injected into 64-bit <Process 3728 ShellExperienceHost.exe>
2026-05-29 05:01:40,665 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 3728
2026-05-29 05:01:40,666 [lib.api.process] INFO: Monitor config for process 3728: C:\lpw_albt\dll\3728.ini
2026-05-29 05:01:40,668 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:41,076 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17112: C:\Windows\System32\mobsync.exe, ImageBase: 0x00007FF639FA0000
2026-05-29 05:01:41,078 [root] INFO: Announced 64-bit process name: mobsync.exe pid: 17112
2026-05-29 05:01:41,079 [lib.api.process] INFO: Monitor config for process 17112: C:\lpw_albt\dll\17112.ini
2026-05-29 05:01:41,081 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:41,087 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:41,092 [root] DEBUG: Loader: Injecting process 17112 (thread 17116) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:41,093 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:41,095 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:41,097 [lib.api.process] INFO: Injected into 64-bit <Process 17112 mobsync.exe>
2026-05-29 05:01:41,099 [root] INFO: Announced 64-bit process name: mobsync.exe pid: 17112
2026-05-29 05:01:41,100 [lib.api.process] INFO: Monitor config for process 17112: C:\lpw_albt\dll\17112.ini
2026-05-29 05:01:41,102 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:41,110 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:41,116 [lib.api.process] INFO: Injected into 64-bit <Process 17112 mobsync.exe>
2026-05-29 05:01:41,130 [root] DEBUG: 17112: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:01:41,133 [root] DEBUG: 17112: Interactive desktop enabled.
2026-05-29 05:01:41,134 [root] DEBUG: 17112: Dropped file limit defaulting to 100.
2026-05-29 05:01:41,139 [root] DEBUG: 17112: Disabling sleep skipping.
2026-05-29 05:01:41,141 [root] DEBUG: 17112: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:01:41,156 [root] DEBUG: 17112: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:01:41,157 [root] DEBUG: 17112: YaraScan: Scanning 0x00007FF639FA0000, size 0x1d056
2026-05-29 05:01:41,159 [root] DEBUG: 17112: Monitor initialised: 64-bit capemon loaded in process 17112 at 0x00007FFF18250000, thread 17116, image base 0x00007FF639FA0000, stack from 0x000000C7435C4000-0x000000C7435D0000
2026-05-29 05:01:41,160 [root] DEBUG: 17112: Commandline: C:\Windows\System32\mobsync.exe -Embedding
2026-05-29 05:01:41,173 [root] DEBUG: 17112: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:01:41,199 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:01:41,202 [root] DEBUG: 17112: set_hooks: Unable to hook LockResource
2026-05-29 05:01:41,209 [root] DEBUG: 17112: Hooked 627 out of 628 functions
2026-05-29 05:01:41,212 [root] DEBUG: 17112: Syscall hook installed, syscall logging level 1
2026-05-29 05:01:41,216 [root] DEBUG: 17112: RestoreHeaders: Restored original import table.
2026-05-29 05:01:41,218 [root] INFO: Loaded monitor into process with pid 17112
2026-05-29 05:01:41,219 [root] DEBUG: 17112: caller_dispatch: Added region at 0x00007FF639FA0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF639FA4861, thread 17116).
2026-05-29 05:01:41,221 [root] DEBUG: 17112: YaraScan: Scanning 0x00007FF639FA0000, size 0x1d056
2026-05-29 05:01:41,223 [root] DEBUG: 17112: ProcessImageBase: Main module image at 0x00007FF639FA0000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:01:41,226 [root] DEBUG: 17112: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:01:41,231 [root] DEBUG: 17112: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:01:41,232 [root] DEBUG: 17112: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:01:41,237 [root] DEBUG: 17112: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:01:41,248 [root] DEBUG: 17112: DLL loaded at 0x00007FFF4A560000: C:\Windows\System32\SyncCenter (0x83000 bytes).
2026-05-29 05:01:41,250 [root] DEBUG: 17112: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32 (0x29a000 bytes).
2026-05-29 05:01:41,253 [root] DEBUG: 17112: DLL loaded at 0x00007FFF507C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-29 05:01:41,266 [root] DEBUG: 17112: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 05:01:41,271 [root] DEBUG: 17112: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-29 05:01:41,277 [root] DEBUG: 17112: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-29 05:01:41,278 [root] DEBUG: 17112: DLL loaded at 0x00007FFF52B00000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-29 05:01:41,279 [root] DEBUG: 17112: DLL loaded at 0x00007FFF4A410000: C:\Windows\system32\SyncInfrastructure (0x6e000 bytes).
2026-05-29 05:01:41,281 [root] DEBUG: 17112: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 05:01:41,282 [root] DEBUG: 17112: DLL loaded at 0x00007FFF49700000: C:\Windows\System32\cscui (0xcd000 bytes).
2026-05-29 05:01:41,285 [root] DEBUG: 17112: DLL loaded at 0x00007FFF57360000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-29 05:01:41,291 [root] DEBUG: 17112: DLL loaded at 0x00007FFF434D0000: C:\Windows\System32\CSCAPI (0x12000 bytes).
2026-05-29 05:01:42,393 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:42,398 [root] DEBUG: Loader: Injecting process 3728 (thread 3596) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:42,399 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:42,400 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:42,401 [lib.api.process] INFO: Injected into 64-bit <Process 3728 ShellExperienceHost.exe>
2026-05-29 05:01:42,402 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 3728
2026-05-29 05:01:42,403 [lib.api.process] INFO: Monitor config for process 3728: C:\lpw_albt\dll\3728.ini
2026-05-29 05:01:42,404 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:44,102 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:44,106 [root] DEBUG: Loader: Injecting process 3728 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:44,107 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 3596, handle 0x120
2026-05-29 05:01:44,109 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:44,109 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:44,111 [lib.api.process] INFO: Injected into 64-bit <Process 3728 ShellExperienceHost.exe>
2026-05-29 05:01:49,419 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 18600: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF6C4CC0000
2026-05-29 05:01:49,420 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 18600
2026-05-29 05:01:49,421 [lib.api.process] INFO: Monitor config for process 18600: C:\lpw_albt\dll\18600.ini
2026-05-29 05:01:49,423 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:51,193 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:51,199 [root] DEBUG: Loader: Injecting process 18600 (thread 18604) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:51,200 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:51,202 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:51,204 [lib.api.process] INFO: Injected into 64-bit <Process 18600 ShellExperienceHost.exe>
2026-05-29 05:01:51,207 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 18600
2026-05-29 05:01:51,208 [lib.api.process] INFO: Monitor config for process 18600: C:\lpw_albt\dll\18600.ini
2026-05-29 05:01:51,209 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:51,387 [root] DEBUG: 17112: NtTerminateProcess hook: Attempting to dump process 17112
2026-05-29 05:01:51,391 [root] DEBUG: 17112: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:01:51,399 [root] INFO: Process with pid 17112 has terminated
2026-05-29 05:01:53,090 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:53,095 [root] DEBUG: Loader: Injecting process 18600 (thread 18604) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:53,096 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:53,098 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:53,100 [lib.api.process] INFO: Injected into 64-bit <Process 18600 ShellExperienceHost.exe>
2026-05-29 05:01:53,102 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 18600
2026-05-29 05:01:53,103 [lib.api.process] INFO: Monitor config for process 18600: C:\lpw_albt\dll\18600.ini
2026-05-29 05:01:53,104 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:54,381 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 18876: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:01:54,384 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 18876
2026-05-29 05:01:54,387 [lib.api.process] INFO: Monitor config for process 18876: C:\lpw_albt\dll\18876.ini
2026-05-29 05:01:54,389 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:55,071 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:55,076 [root] DEBUG: Loader: Injecting process 18600 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:55,078 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 18604, handle 0x134
2026-05-29 05:01:55,080 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:55,080 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:55,082 [lib.api.process] INFO: Injected into 64-bit <Process 18600 ShellExperienceHost.exe>
2026-05-29 05:01:56,193 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:56,198 [root] DEBUG: Loader: Injecting process 18876 (thread 18880) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:56,200 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:01:56,200 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:56,202 [lib.api.process] INFO: Injected into 64-bit <Process 18876 SearchApp.exe>
2026-05-29 05:01:56,204 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 18876
2026-05-29 05:01:56,205 [lib.api.process] INFO: Monitor config for process 18876: C:\lpw_albt\dll\18876.ini
2026-05-29 05:01:56,206 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:01:58,204 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:01:58,209 [root] DEBUG: Loader: Injecting process 18876 (thread 18880) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:58,210 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:01:58,211 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:01:58,213 [lib.api.process] INFO: Injected into 64-bit <Process 18876 SearchApp.exe>
2026-05-29 05:01:58,216 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 18876
2026-05-29 05:01:58,216 [lib.api.process] INFO: Monitor config for process 18876: C:\lpw_albt\dll\18876.ini
2026-05-29 05:01:58,218 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:00,373 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:00,379 [root] DEBUG: Loader: Injecting process 18876 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:00,381 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 18880, handle 0xa8
2026-05-29 05:02:00,382 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:00,384 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:00,388 [lib.api.process] INFO: Injected into 64-bit <Process 18876 SearchApp.exe>
2026-05-29 05:02:00,396 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 19196: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:00,398 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 19196
2026-05-29 05:02:00,400 [lib.api.process] INFO: Monitor config for process 19196: C:\lpw_albt\dll\19196.ini
2026-05-29 05:02:00,402 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:02,339 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:02,344 [root] DEBUG: Loader: Injecting process 19196 (thread 19200) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:02,345 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:02,346 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:02,348 [lib.api.process] INFO: Injected into 64-bit <Process 19196 SearchApp.exe>
2026-05-29 05:02:02,351 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 19196
2026-05-29 05:02:02,352 [lib.api.process] INFO: Monitor config for process 19196: C:\lpw_albt\dll\19196.ini
2026-05-29 05:02:02,352 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:04,208 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:04,213 [root] DEBUG: Loader: Injecting process 19196 (thread 19200) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:04,213 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:04,215 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:04,218 [lib.api.process] INFO: Injected into 64-bit <Process 19196 SearchApp.exe>
2026-05-29 05:02:05,233 [root] INFO: Process with pid 19196 has terminated
2026-05-29 05:02:05,238 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 19348: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:05,239 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 19348
2026-05-29 05:02:05,240 [lib.api.process] INFO: Monitor config for process 19348: C:\lpw_albt\dll\19348.ini
2026-05-29 05:02:05,241 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:06,253 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 19432: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF659080000
2026-05-29 05:02:06,258 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 19432
2026-05-29 05:02:06,260 [lib.api.process] INFO: Monitor config for process 19432: C:\lpw_albt\dll\19432.ini
2026-05-29 05:02:06,264 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:07,169 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:07,174 [root] DEBUG: Loader: Injecting process 19348 (thread 19352) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:07,175 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:07,176 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:07,177 [lib.api.process] INFO: Injected into 64-bit <Process 19348 SearchApp.exe>
2026-05-29 05:02:07,180 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 19348
2026-05-29 05:02:07,181 [lib.api.process] INFO: Monitor config for process 19348: C:\lpw_albt\dll\19348.ini
2026-05-29 05:02:07,182 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:08,294 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:08,299 [root] DEBUG: Loader: Injecting process 19432 (thread 19436) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:08,302 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:08,303 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:08,305 [lib.api.process] INFO: Injected into 64-bit <Process 19432 StartMenuExperienceHost.exe>
2026-05-29 05:02:08,308 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 19432
2026-05-29 05:02:08,311 [lib.api.process] INFO: Monitor config for process 19432: C:\lpw_albt\dll\19432.ini
2026-05-29 05:02:08,311 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:09,069 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:09,075 [root] DEBUG: Loader: Injecting process 19348 (thread 19352) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:09,077 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:09,077 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:09,079 [lib.api.process] INFO: Injected into 64-bit <Process 19348 SearchApp.exe>
2026-05-29 05:02:09,082 [root] INFO: Process with pid 19348 has terminated
2026-05-29 05:02:10,383 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:10,389 [root] DEBUG: Loader: Injecting process 19432 (thread 19436) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:10,390 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:10,391 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:10,393 [lib.api.process] INFO: Injected into 64-bit <Process 19432 StartMenuExperienceHost.exe>
2026-05-29 05:02:10,395 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 19432
2026-05-29 05:02:10,396 [lib.api.process] INFO: Monitor config for process 19432: C:\lpw_albt\dll\19432.ini
2026-05-29 05:02:10,397 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:12,383 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:12,388 [root] DEBUG: Loader: Injecting process 19432 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:12,389 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 19436, handle 0x120
2026-05-29 05:02:12,390 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:12,392 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:12,393 [lib.api.process] INFO: Injected into 64-bit <Process 19432 StartMenuExperienceHost.exe>
2026-05-29 05:02:12,469 [root] INFO: Announced starting service "b'wisvc'"
2026-05-29 05:02:13,483 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 6440: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-29 05:02:13,484 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6440
2026-05-29 05:02:13,485 [lib.api.process] INFO: Monitor config for process 6440: C:\lpw_albt\dll\6440.ini
2026-05-29 05:02:13,487 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:13,496 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:13,500 [root] DEBUG: Loader: Injecting process 6440 (thread 6476) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:13,501 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:13,503 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:13,504 [lib.api.process] INFO: Injected into 64-bit <Process 6440 svchost.exe>
2026-05-29 05:02:13,506 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6440
2026-05-29 05:02:13,507 [lib.api.process] INFO: Monitor config for process 6440: C:\lpw_albt\dll\6440.ini
2026-05-29 05:02:13,508 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:13,515 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:13,520 [root] DEBUG: Loader: Injecting process 6440 (thread 6476) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:13,522 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:13,523 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:13,525 [lib.api.process] INFO: Injected into 64-bit <Process 6440 svchost.exe>
2026-05-29 05:02:13,527 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6440
2026-05-29 05:02:13,529 [lib.api.process] INFO: Monitor config for process 6440: C:\lpw_albt\dll\6440.ini
2026-05-29 05:02:13,531 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:13,535 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:13,540 [root] DEBUG: Loader: Injecting process 6440 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:13,541 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 6476, handle 0xb4
2026-05-29 05:02:13,542 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:13,544 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:13,546 [lib.api.process] INFO: Injected into 64-bit <Process 6440 svchost.exe>
2026-05-29 05:02:13,553 [root] DEBUG: 6440: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:02:13,555 [root] DEBUG: 6440: Interactive desktop enabled.
2026-05-29 05:02:13,556 [root] DEBUG: 6440: Dropped file limit defaulting to 100.
2026-05-29 05:02:13,557 [root] DEBUG: 6440: Disabling sleep skipping.
2026-05-29 05:02:13,559 [root] DEBUG: 6440: Services hook set enabled
2026-05-29 05:02:13,562 [root] DEBUG: 6440: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:02:13,575 [root] DEBUG: 6440: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:02:13,576 [root] DEBUG: 6440: Monitor initialised: 64-bit capemon loaded in process 6440 at 0x00007FFF18250000, thread 6476, image base 0x00007FF7BF220000, stack from 0x00000067C7274000-0x00000067C7280000
2026-05-29 05:02:13,579 [root] DEBUG: 6440: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-29 05:02:13,591 [root] DEBUG: 6440: Hooked 69 out of 69 functions
2026-05-29 05:02:13,593 [root] DEBUG: 6440: RestoreHeaders: Restored original import table.
2026-05-29 05:02:13,594 [root] INFO: Loaded monitor into process with pid 6440
2026-05-29 05:02:13,597 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:02:13,602 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:02:13,606 [root] DEBUG: 6440: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:02:13,612 [root] DEBUG: 6440: DLL loaded at 0x00007FFF40A10000: c:\windows\system32\flightsettings (0xe6000 bytes).
2026-05-29 05:02:13,614 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-29 05:02:13,620 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-29 05:02:13,621 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-29 05:02:13,623 [root] DEBUG: 6440: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 05:02:13,625 [root] DEBUG: 6440: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-29 05:02:13,630 [root] DEBUG: 6440: DLL loaded at 0x00007FFF566C0000: c:\windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-29 05:02:13,633 [root] DEBUG: 6440: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 05:02:13,637 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-29 05:02:13,639 [root] DEBUG: 6440: DLL loaded at 0x00007FFF42C10000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-05-29 05:02:13,642 [root] DEBUG: 6440: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:02:13,644 [root] DEBUG: 6440: DLL loaded at 0x00007FFF42490000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-29 05:02:13,646 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-29 05:02:13,648 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52DC0000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-29 05:02:13,650 [root] DEBUG: 6440: DLL loaded at 0x00007FFF569F0000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-05-29 05:02:13,651 [root] DEBUG: 6440: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-29 05:02:13,654 [root] DEBUG: 6440: DLL loaded at 0x00007FFF40900000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-29 05:02:13,656 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57560000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-29 05:02:13,657 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F590000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-05-29 05:02:13,658 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-29 05:02:13,672 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-29 05:02:13,674 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3EE40000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-05-29 05:02:13,677 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-29 05:02:13,679 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-29 05:02:13,680 [root] DEBUG: 6440: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-29 05:02:13,700 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:13,704 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:13,709 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:13,713 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:13,715 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:13,716 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:13,720 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:13,722 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:13,725 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:13,731 [root] DEBUG: 6440: DLL loaded at 0x00007FFF18230000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-29 05:02:13,738 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3F290000: C:\Windows\system32\fcon (0x45000 bytes).
2026-05-29 05:02:13,745 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-29 05:02:13,773 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:13,774 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:13,776 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:13,778 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:13,779 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:13,780 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:13,781 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:13,782 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:13,786 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:13,788 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:13,794 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:13,797 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:13,799 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:13,801 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:13,801 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:13,807 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:13,808 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:13,809 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:13,811 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:13,812 [root] DEBUG: 6440: DLL loaded at 0x00007FFF490D0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:13,841 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:13,842 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:13,843 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:13,849 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:13,855 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:13,857 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:13,858 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:13,864 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:13,865 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:13,887 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:13,888 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:13,891 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:13,892 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:13,894 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:13,895 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:13,897 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:13,900 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:13,902 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:13,904 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:13,907 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:13,909 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:13,911 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:13,913 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:13,914 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:13,916 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:13,918 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:13,921 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:13,923 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:13,924 [root] DEBUG: 6440: DLL loaded at 0x00007FFF490D0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:13,950 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:13,952 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:13,955 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:13,956 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:13,957 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:13,958 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:13,959 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:13,962 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:13,965 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:13,987 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:13,988 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:13,990 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:13,992 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:13,993 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:13,994 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:13,996 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:13,997 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,000 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,001 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,004 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,004 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,006 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,008 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,009 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,010 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,013 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,013 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,015 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,015 [root] DEBUG: 6440: DLL loaded at 0x00007FFF490D0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,046 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,047 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,050 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,051 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,052 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,054 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,055 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,057 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,061 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,083 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,085 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,086 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,087 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,089 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,090 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,091 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,095 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,097 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,098 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,101 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,102 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,105 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,106 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,110 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,112 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,114 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,115 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,117 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,117 [root] DEBUG: 6440: DLL loaded at 0x00007FFF490D0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,155 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,157 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,160 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,160 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,162 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,164 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,165 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,167 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,170 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,191 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,192 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,195 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,198 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,200 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,202 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,204 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49EA0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,205 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,207 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,210 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,213 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,214 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,216 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,217 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,219 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,220 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,221 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,222 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,224 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,225 [root] DEBUG: 6440: DLL loaded at 0x00007FFF490D0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,288 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,289 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,292 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,295 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,296 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,298 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,299 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,301 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,304 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,327 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,329 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,331 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,332 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,333 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,334 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,335 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,336 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,338 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,339 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,343 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,345 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,346 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,348 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,349 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,350 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,352 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,355 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,358 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,359 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3DE90000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,383 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,385 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,388 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,389 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,392 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,394 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,395 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,396 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,399 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,423 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,424 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,426 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,427 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,428 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,430 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,431 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,432 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,435 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,436 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,439 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,441 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,442 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,443 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,444 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,445 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,449 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,450 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,452 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,453 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3DE90000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,477 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,480 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,487 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,488 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,489 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,491 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,492 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,493 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,494 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,517 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,519 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,524 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,525 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,527 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,529 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,530 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,532 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,535 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,536 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,541 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,542 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,545 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,546 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,546 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,547 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,548 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,550 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,551 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,553 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3DE90000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,576 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,578 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,580 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,581 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,582 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,583 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,584 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,586 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,588 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,611 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,613 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,614 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,616 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,617 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,618 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,619 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,620 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,624 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,629 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,634 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,635 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,637 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,639 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,641 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,642 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,643 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,644 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,645 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,647 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3DE90000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:14,674 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,676 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,679 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,680 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,680 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,681 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,682 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,685 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,687 [root] DEBUG: 6440: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 05:02:14,709 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 05:02:14,710 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 05:02:14,713 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 05:02:14,717 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 05:02:14,718 [root] DEBUG: 6440: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 05:02:14,720 [root] DEBUG: 6440: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 05:02:14,722 [root] DEBUG: 6440: DLL loaded at 0x00007FFF49230000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 05:02:14,724 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 05:02:14,726 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 05:02:14,727 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 05:02:14,732 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D360000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 05:02:14,735 [root] DEBUG: 6440: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 05:02:14,735 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 05:02:14,737 [root] DEBUG: 6440: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 05:02:14,738 [root] DEBUG: 6440: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 05:02:14,740 [root] DEBUG: 6440: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 05:02:14,742 [root] DEBUG: 6440: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 05:02:14,743 [root] DEBUG: 6440: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 05:02:14,744 [root] DEBUG: 6440: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 05:02:14,745 [root] DEBUG: 6440: DLL loaded at 0x00007FFF3DE90000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 05:02:17,677 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20024: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:17,679 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20024
2026-05-29 05:02:17,681 [lib.api.process] INFO: Monitor config for process 20024: C:\lpw_albt\dll\20024.ini
2026-05-29 05:02:17,684 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:19,404 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20072: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-29 05:02:19,407 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 20072
2026-05-29 05:02:19,409 [lib.api.process] INFO: Monitor config for process 20072: C:\lpw_albt\dll\20072.ini
2026-05-29 05:02:19,411 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:19,417 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:19,424 [root] DEBUG: Loader: Injecting process 20072 (thread 20076) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:19,425 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:19,426 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:19,428 [lib.api.process] INFO: Injected into 64-bit <Process 20072 dllhost.exe>
2026-05-29 05:02:19,429 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 20072
2026-05-29 05:02:19,430 [lib.api.process] INFO: Monitor config for process 20072: C:\lpw_albt\dll\20072.ini
2026-05-29 05:02:19,431 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:19,438 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:19,442 [root] DEBUG: Loader: Injecting process 20072 (thread 20076) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:19,444 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:19,448 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:19,449 [lib.api.process] INFO: Injected into 64-bit <Process 20072 dllhost.exe>
2026-05-29 05:02:19,455 [root] DEBUG: 20072: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 05:02:19,456 [root] DEBUG: 20072: Interactive desktop enabled.
2026-05-29 05:02:19,457 [root] DEBUG: 20072: Dropped file limit defaulting to 100.
2026-05-29 05:02:19,459 [root] DEBUG: 20072: Disabling sleep skipping.
2026-05-29 05:02:19,460 [root] DEBUG: 20072: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 05:02:19,473 [root] DEBUG: 20072: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 05:02:19,474 [root] DEBUG: 20072: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:02:19,475 [root] DEBUG: 20072: Monitor initialised: 64-bit capemon loaded in process 20072 at 0x00007FFF18250000, thread 20076, image base 0x00007FF6706B0000, stack from 0x000000346D9F4000-0x000000346DA00000
2026-05-29 05:02:19,476 [root] DEBUG: 20072: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-29 05:02:19,491 [root] DEBUG: 20072: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 05:02:19,513 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 05:02:19,515 [root] DEBUG: 20072: set_hooks: Unable to hook LockResource
2026-05-29 05:02:19,519 [root] DEBUG: 20072: Hooked 627 out of 628 functions
2026-05-29 05:02:19,521 [root] DEBUG: 20072: Syscall hook installed, syscall logging level 1
2026-05-29 05:02:19,526 [root] DEBUG: 20072: RestoreHeaders: Restored original import table.
2026-05-29 05:02:19,528 [root] INFO: Loaded monitor into process with pid 20072
2026-05-29 05:02:19,529 [root] DEBUG: 20072: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 20076).
2026-05-29 05:02:19,531 [root] DEBUG: 20072: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 05:02:19,535 [root] DEBUG: 20072: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-29 05:02:19,539 [root] DEBUG: 20072: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 05:02:19,542 [root] DEBUG: 20072: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 05:02:19,546 [root] DEBUG: 20072: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 05:02:19,560 [root] DEBUG: 20072: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 05:02:19,576 [root] DEBUG: 20072: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 05:02:19,578 [root] DEBUG: 20072: DLL loaded at 0x00007FFF51390000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-29 05:02:19,584 [root] DEBUG: 20072: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-29 05:02:19,750 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:19,755 [root] DEBUG: Loader: Injecting process 20024 (thread 20028) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:19,757 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:19,758 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:19,760 [lib.api.process] INFO: Injected into 64-bit <Process 20024 SearchApp.exe>
2026-05-29 05:02:19,762 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20024
2026-05-29 05:02:19,762 [lib.api.process] INFO: Monitor config for process 20024: C:\lpw_albt\dll\20024.ini
2026-05-29 05:02:19,763 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:21,840 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:21,851 [root] DEBUG: Loader: Injecting process 20024 (thread 20028) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:21,852 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:21,853 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:21,854 [lib.api.process] INFO: Injected into 64-bit <Process 20024 SearchApp.exe>
2026-05-29 05:02:21,856 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20024
2026-05-29 05:02:21,857 [lib.api.process] INFO: Monitor config for process 20024: C:\lpw_albt\dll\20024.ini
2026-05-29 05:02:21,857 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:23,443 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:23,448 [root] DEBUG: Loader: Injecting process 20024 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:23,449 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 20028, handle 0x120
2026-05-29 05:02:23,451 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:23,453 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:23,454 [lib.api.process] INFO: Injected into 64-bit <Process 20024 SearchApp.exe>
2026-05-29 05:02:23,460 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20468: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:23,461 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20468
2026-05-29 05:02:23,462 [lib.api.process] INFO: Monitor config for process 20468: C:\lpw_albt\dll\20468.ini
2026-05-29 05:02:23,465 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:24,632 [root] INFO: Process with pid 20072 has terminated
2026-05-29 05:02:24,634 [root] DEBUG: 20072: NtTerminateProcess hook: Attempting to dump process 20072
2026-05-29 05:02:24,638 [root] DEBUG: 20072: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 05:02:24,955 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:24,960 [root] DEBUG: Loader: Injecting process 20468 (thread 20472) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:24,962 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:24,964 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:24,966 [lib.api.process] INFO: Injected into 64-bit <Process 20468 SearchApp.exe>
2026-05-29 05:02:24,968 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20468
2026-05-29 05:02:24,970 [lib.api.process] INFO: Monitor config for process 20468: C:\lpw_albt\dll\20468.ini
2026-05-29 05:02:24,970 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:27,027 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:27,032 [root] DEBUG: Loader: Injecting process 20468 (thread 20472) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:27,033 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:27,034 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:27,036 [lib.api.process] INFO: Injected into 64-bit <Process 20468 SearchApp.exe>
2026-05-29 05:02:28,043 [root] INFO: Process with pid 20468 has terminated
2026-05-29 05:02:29,237 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20136: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF659080000
2026-05-29 05:02:29,239 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 20136
2026-05-29 05:02:29,240 [lib.api.process] INFO: Monitor config for process 20136: C:\lpw_albt\dll\20136.ini
2026-05-29 05:02:29,242 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2256: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:29,242 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:29,244 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 2256
2026-05-29 05:02:29,245 [lib.api.process] INFO: Monitor config for process 2256: C:\lpw_albt\dll\2256.ini
2026-05-29 05:02:29,248 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:31,100 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:31,106 [root] DEBUG: Loader: Injecting process 2256 (thread 14484) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:31,108 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:31,109 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:31,112 [lib.api.process] INFO: Injected into 64-bit <Process 2256 SearchApp.exe>
2026-05-29 05:02:31,114 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 2256
2026-05-29 05:02:31,115 [lib.api.process] INFO: Monitor config for process 2256: C:\lpw_albt\dll\2256.ini
2026-05-29 05:02:31,116 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:31,354 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:31,360 [root] DEBUG: Loader: Injecting process 20136 (thread 20092) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:31,362 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:31,364 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:31,366 [lib.api.process] INFO: Injected into 64-bit <Process 20136 StartMenuExperienceHost.exe>
2026-05-29 05:02:31,367 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 20136
2026-05-29 05:02:31,368 [lib.api.process] INFO: Monitor config for process 20136: C:\lpw_albt\dll\20136.ini
2026-05-29 05:02:31,369 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:33,006 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:33,012 [root] DEBUG: Loader: Injecting process 2256 (thread 14484) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:33,013 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:33,015 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:33,016 [lib.api.process] INFO: Injected into 64-bit <Process 2256 SearchApp.exe>
2026-05-29 05:02:33,018 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 2256
2026-05-29 05:02:33,019 [lib.api.process] INFO: Monitor config for process 2256: C:\lpw_albt\dll\2256.ini
2026-05-29 05:02:33,020 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:33,383 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:33,390 [root] DEBUG: Loader: Injecting process 20136 (thread 20092) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:33,391 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:33,392 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:33,394 [lib.api.process] INFO: Injected into 64-bit <Process 20136 StartMenuExperienceHost.exe>
2026-05-29 05:02:33,396 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 20136
2026-05-29 05:02:33,397 [lib.api.process] INFO: Monitor config for process 20136: C:\lpw_albt\dll\20136.ini
2026-05-29 05:02:33,397 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:34,948 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:34,954 [root] DEBUG: Loader: Injecting process 2256 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:34,955 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14484, handle 0x84
2026-05-29 05:02:34,956 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:34,958 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:34,960 [lib.api.process] INFO: Injected into 64-bit <Process 2256 SearchApp.exe>
2026-05-29 05:02:35,222 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:35,227 [root] DEBUG: Loader: Injecting process 20136 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:35,228 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 20092, handle 0x120
2026-05-29 05:02:35,230 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:35,231 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:35,233 [lib.api.process] INFO: Injected into 64-bit <Process 20136 StartMenuExperienceHost.exe>
2026-05-29 05:02:40,519 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20376: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:40,520 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20376
2026-05-29 05:02:40,520 [lib.api.process] INFO: Monitor config for process 20376: C:\lpw_albt\dll\20376.ini
2026-05-29 05:02:40,523 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:42,457 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:42,461 [root] DEBUG: Loader: Injecting process 20376 (thread 20424) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:42,463 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:42,463 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:42,465 [lib.api.process] INFO: Injected into 64-bit <Process 20376 SearchApp.exe>
2026-05-29 05:02:42,466 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20376
2026-05-29 05:02:42,467 [lib.api.process] INFO: Monitor config for process 20376: C:\lpw_albt\dll\20376.ini
2026-05-29 05:02:42,468 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:44,586 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:44,592 [root] DEBUG: Loader: Injecting process 20376 (thread 20424) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:44,593 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:44,594 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:44,595 [lib.api.process] INFO: Injected into 64-bit <Process 20376 SearchApp.exe>
2026-05-29 05:02:44,597 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20376
2026-05-29 05:02:44,598 [lib.api.process] INFO: Monitor config for process 20376: C:\lpw_albt\dll\20376.ini
2026-05-29 05:02:44,598 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:46,676 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:46,681 [root] DEBUG: Loader: Injecting process 20376 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:46,683 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 20424, handle 0x120
2026-05-29 05:02:46,684 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:46,685 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:46,687 [lib.api.process] INFO: Injected into 64-bit <Process 20376 SearchApp.exe>
2026-05-29 05:02:46,693 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 6080: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:46,694 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6080
2026-05-29 05:02:46,695 [lib.api.process] INFO: Monitor config for process 6080: C:\lpw_albt\dll\6080.ini
2026-05-29 05:02:46,696 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:48,614 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:48,618 [root] DEBUG: Loader: Injecting process 6080 (thread 20092) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:48,619 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:48,620 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:48,622 [lib.api.process] INFO: Injected into 64-bit <Process 6080 SearchApp.exe>
2026-05-29 05:02:48,625 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6080
2026-05-29 05:02:48,626 [lib.api.process] INFO: Monitor config for process 6080: C:\lpw_albt\dll\6080.ini
2026-05-29 05:02:48,627 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:50,736 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:50,741 [root] DEBUG: Loader: Injecting process 6080 (thread 20092) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:50,742 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:50,743 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:50,745 [lib.api.process] INFO: Injected into 64-bit <Process 6080 SearchApp.exe>
2026-05-29 05:02:51,763 [root] INFO: Process with pid 6080 has terminated
2026-05-29 05:02:52,941 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14220: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF659080000
2026-05-29 05:02:52,942 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 14220
2026-05-29 05:02:52,944 [lib.api.process] INFO: Monitor config for process 14220: C:\lpw_albt\dll\14220.ini
2026-05-29 05:02:52,945 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:54,954 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:54,959 [root] DEBUG: Loader: Injecting process 14220 (thread 14236) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:54,960 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:54,963 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:54,964 [lib.api.process] INFO: Injected into 64-bit <Process 14220 StartMenuExperienceHost.exe>
2026-05-29 05:02:54,966 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 14220
2026-05-29 05:02:54,968 [lib.api.process] INFO: Monitor config for process 14220: C:\lpw_albt\dll\14220.ini
2026-05-29 05:02:54,969 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:56,964 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:56,970 [root] DEBUG: Loader: Injecting process 14220 (thread 14236) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:56,971 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:56,972 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:56,974 [lib.api.process] INFO: Injected into 64-bit <Process 14220 StartMenuExperienceHost.exe>
2026-05-29 05:02:56,976 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 14220
2026-05-29 05:02:56,977 [lib.api.process] INFO: Monitor config for process 14220: C:\lpw_albt\dll\14220.ini
2026-05-29 05:02:56,978 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:58,232 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20100: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF662BA0000
2026-05-29 05:02:58,234 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20100
2026-05-29 05:02:58,236 [lib.api.process] INFO: Monitor config for process 20100: C:\lpw_albt\dll\20100.ini
2026-05-29 05:02:58,238 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 05:02:58,973 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:58,978 [root] DEBUG: Loader: Injecting process 14220 with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:58,980 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14236, handle 0x120
2026-05-29 05:02:58,981 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 05:02:58,983 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:58,984 [lib.api.process] INFO: Injected into 64-bit <Process 14220 StartMenuExperienceHost.exe>
2026-05-29 05:02:59,743 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\uwEeDg.dll, loader C:\lpw_albt\bin\MooDbyJw.exe
2026-05-29 05:02:59,748 [root] DEBUG: Loader: Injecting process 20100 (thread 1276) with C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:59,750 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 05:02:59,751 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\uwEeDg.dll.
2026-05-29 05:02:59,752 [lib.api.process] INFO: Injected into 64-bit <Process 20100 SearchApp.exe>
2026-05-29 05:02:59,753 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 20100
2026-05-29 05:02:59,754 [lib.api.process] INFO: Monitor config for process 20100: C:\lpw_albt\dll\20100.ini
2026-05-29 05:02:59,755 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-29 04:59:36 | 2026-05-29 05:03:13 | none |
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (8268) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (10788) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 104.115.81.98 [VT] | unknown | - |
| Y | 104.115.81.75 [VT] | unknown | - |
| Y | 20.227.97.55 [VT] | unknown | - |
| Y | 72.153.5.62 [VT] | unknown | - |
| Y | 72.153.5.96 [VT] | unknown | - |
| Y | 72.153.5.141 [VT] | unknown | - |
| Y | 23.202.166.56 [VT] | unknown | - |
| Y | 150.171.109.24 [VT] | unknown | - |
| Y | 104.29.139.128 [VT] | unknown | - |
| Y | 104.29.139.123 [VT] | unknown | - |
| Y | 104.29.148.137 [VT] | unknown | - |
| Y | 104.29.139.77 [VT] | unknown | - |
| Y | 104.29.139.157 [VT] | unknown | - |
| Y | 104.29.140.158 [VT] | unknown | - |
| Y | 104.29.141.87 [VT] | unknown | - |
| Y | 104.29.140.156 [VT] | unknown | - |
| Y | 104.29.145.242 [VT] | unknown | - |
| Y | 104.29.140.153 [VT] | unknown | - |
| Y | 104.29.132.25 [VT] | unknown | - |
| Y | 104.29.132.112 [VT] | unknown | - |
| Y | 104.29.132.82 [VT] | unknown | - |
| Y | 104.29.132.63 [VT] | unknown | - |
| Y | 104.29.132.66 [VT] | unknown | - |
| Y | 104.29.141.120 [VT] | unknown | - |
| Y | 104.29.142.46 [VT] | unknown | - |
| Y | 104.29.141.176 [VT] | unknown | - |
| Y | 104.29.141.225 [VT] | unknown | - |
| Y | 104.29.141.159 [VT] | unknown | - |
| Y | 104.29.149.160 [VT] | unknown | - |
| Y | 104.29.149.138 [VT] | unknown | - |
| Y | 104.29.149.149 [VT] | unknown | - |
| Y | 104.29.149.139 [VT] | unknown | - |
| Y | 104.29.149.140 [VT] | unknown | - |
| N | 162.159.138.234 [VT] | unknown | - |
| N | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 146.75.119.82 [VT] | unknown | - |
| N | 23.209.183.176 [VT] | unknown | - |
| N | 205.196.6.132 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 23.56.110.169 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| N | 162.159.138.232 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 162.159.137.232 [VT] | unknown | - |
| N | 162.159.135.233 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 142.250.195.227 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| N | 199.232.215.52 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-udp.steamserver.net [VT] |
CNAME udp.ipv6check.akadns.net
[VT]
AAAA 2404:3fc0:1:102::670a:7d36 [VT] AAAA 2404:3fc0:1:102::670a:7d37 [VT] AAAA 2404:3fc0:1:100::670a:7d06 [VT] AAAA 2404:3fc0:1:100::42 [VT] AAAA 2404:3fc0:1:102::670a:7d38 [VT] CNAME syd.udp.ipv6check.akadns.net [VT] AAAA 2404:3fc0:1:100::670a:7d08 [VT] AAAA 2404:3fc0:1:102::670a:7d35 [VT] AAAA 2404:3fc0:1:100::32 [VT] |
|
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.155
[VT]
A 149.135.84.160 [VT] |
23.56.110.24 [VT] |
| c.pki.goog [VT] |
A 142.250.195.227
[VT]
CNAME pki-goog.l.google.com [VT] |
142.250.207.3 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.136.234 [VT] |
| discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.130.233 [VT] |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.135.232 [VT] |
| cdn.discordapp.com [VT] | 162.159.134.233 [VT] | |
| updates.discord.com [VT] | 162.159.136.232 [VT] | |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| cmp1-sea1.steamserver.net [VT] | A 205.196.6.132 [VT] | 205.196.6.132 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| clientconfig.akamai.steamstatic.com [VT] |
A 23.209.183.106
[VT]
A 23.209.183.176 [VT] |
23.211.125.111 [VT] |
| shared.steamstatic.com [VT] |
A 199.232.215.52
[VT]
A 199.232.211.52 [VT] CNAME shared.valve.map.fastly.net [VT] |
199.232.211.52 [VT] |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.128.235 [VT] |
| disabled.invalid [VT] | NXDOMAIN |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.