| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-30 16:12:52 | 2026-05-30 16:14:44 | 112s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:55:30,792 [root] INFO: Date set to: 20260530T16:13:03, timeout set to: 200
2026-05-30 16:13:03,022 [root] DEBUG: Starting analyzer from: C:\lpw_albt
2026-05-30 16:13:03,022 [root] DEBUG: Storing results at: C:\gbSlmMlCP
2026-05-30 16:13:03,023 [root] DEBUG: Pipe server name: \\.\PIPE\hSVYyQPg
2026-05-30 16:13:03,024 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-30 16:13:03,025 [root] INFO: analysis running as an admin
2026-05-30 16:13:03,025 [root] INFO: analysis package specified: "edge"
2026-05-30 16:13:03,025 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-30 16:13:03,032 [root] DEBUG: imported analysis package "edge"
2026-05-30 16:13:03,033 [root] DEBUG: initializing analysis package "edge"...
2026-05-30 16:13:03,033 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-30 16:13:03,033 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-30 16:13:03,034 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-30 16:13:03,034 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-30 16:13:03,034 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-30 16:13:03,111 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-30 16:13:03,166 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-30 16:13:03,176 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-30 16:13:03,195 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-30 16:13:03,214 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-30 16:13:03,215 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-30 16:13:03,215 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-30 16:13:03,217 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-30 16:13:03,217 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-30 16:13:03,218 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-30 16:13:03,218 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-30 16:13:03,218 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-30 16:13:03,218 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-30 16:13:03,219 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-30 16:13:03,219 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-30 16:13:03,219 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-30 16:13:03,219 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-30 16:13:03,219 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-30 16:13:03,220 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-30 16:13:03,220 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-30 16:13:03,220 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-30 16:13:03,220 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-30 16:13:03,220 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-30 16:13:03,247 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 1408)
2026-05-30 16:13:03,247 [modules.auxiliary.disguise] INFO: Disguising GUID to 5171cce0-aa56-4cd9-87e1-72af7ec44967
2026-05-30 16:13:03,248 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-30 16:13:03,248 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-30 16:13:03,248 [root] DEBUG: attempting to configure 'Human' from data
2026-05-30 16:13:03,249 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-30 16:13:03,249 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-30 16:13:03,250 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-30 16:13:03,250 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-30 16:13:03,250 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-30 16:13:03,251 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-30 16:13:03,251 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-30 16:13:03,251 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-30 16:13:03,251 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-30 16:13:03,251 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-30 16:13:03,251 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-30 16:13:03,252 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-30 16:13:03,252 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-30 16:13:03,254 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-30 16:13:03,254 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-30 16:13:03,254 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-30 16:13:03,337 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-30 16:13:03,354 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:03,369 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:03,404 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:03,564 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:03,565 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-30 16:13:03,565 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-30 16:13:03,566 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-30 16:13:03,567 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-30 16:13:03,584 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-30 16:13:03,593 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:03,681 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:03,685 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-30 16:13:03,731 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF15C80000, thread 5072, image base 0x00007FF79BC10000, stack from 0x0000000009031000-0x0000000009040000
2026-05-30 16:13:03,732 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-30 16:13:03,746 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-30 16:13:03,776 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:03,783 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:03,783 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:04,112 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-30 16:13:05,005 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF79BD27BE7, thread 4696).
2026-05-30 16:13:05,006 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-30 16:13:05,040 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:11,350 [root] INFO: Restarting WMI Service
2026-05-30 16:13:11,363 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-30 16:13:11,363 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-30 16:13:11,364 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-30 16:13:11,422 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 8528
2026-05-30 16:13:11,423 [lib.api.process] INFO: Monitor config for process 8528: C:\lpw_albt\dll\8528.ini
2026-05-30 16:13:11,455 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:11,459 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:11,471 [root] DEBUG: Loader: Injecting process 8528 (thread 3980) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:11,475 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:11,476 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:11,478 [lib.api.process] INFO: Injected into 64-bit <Process 8528 msedge.exe>
2026-05-30 16:13:13,493 [lib.api.process] INFO: Successfully resumed process with pid 8528
2026-05-30 16:13:14,582 [root] DEBUG: 8528: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:14,583 [root] DEBUG: 8528: Disabling sleep skipping.
2026-05-30 16:13:14,584 [root] DEBUG: 8528: Interactive desktop enabled.
2026-05-30 16:13:14,584 [root] DEBUG: 8528: Dropped file limit defaulting to 100.
2026-05-30 16:13:14,670 [root] DEBUG: 8528: Edge-specific hook-set enabled.
2026-05-30 16:13:14,674 [root] DEBUG: 8528: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:14,685 [root] DEBUG: 8528: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:14,686 [root] DEBUG: 8528: Monitor initialised: 64-bit capemon loaded in process 8528 at 0x00007FFF15C80000, thread 3980, image base 0x00007FF7F5380000, stack from 0x0000008DC5BF4000-0x0000008DC5C00000
2026-05-30 16:13:14,686 [root] DEBUG: 8528: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-30 16:13:14,699 [root] DEBUG: 8528: Hooked 2 out of 2 functions
2026-05-30 16:13:15,725 [root] DEBUG: 8528: Yara error: Scanning timed out
2026-05-30 16:13:15,728 [root] DEBUG: 8528: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:15,750 [root] DEBUG: 8528: RestoreHeaders: Restored original import table.
2026-05-30 16:13:15,751 [root] INFO: Loaded monitor into process with pid 8528
2026-05-30 16:13:16,084 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-30 16:13:16,618 [root] DEBUG: 8528: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-30 16:13:16,706 [root] DEBUG: 8528: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:13:16,707 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-30 16:13:16,708 [root] DEBUG: 8528: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-30 16:13:16,709 [root] DEBUG: 8528: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-30 16:13:16,710 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-30 16:13:16,869 [root] DEBUG: 8528: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-30 16:13:16,892 [root] DEBUG: 8528: DLL loaded at 0x00007FFEFA620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-30 16:13:16,914 [root] DEBUG: 8528: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-30 16:13:17,002 [root] DEBUG: 8528: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-30 16:13:17,152 [root] DEBUG: 8528: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:13:17,153 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 7080: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:17,154 [root] DEBUG: 8528: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:13:17,154 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 7080
2026-05-30 16:13:17,154 [root] DEBUG: 8528: DLL loaded at 0x00007FFF166D0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-30 16:13:17,155 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 7080
2026-05-30 16:13:17,155 [root] DEBUG: 8528: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:17,156 [root] DEBUG: 8528: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-30 16:13:17,165 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-30 16:13:17,167 [root] DEBUG: 8528: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-30 16:13:17,168 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-30 16:13:17,171 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-30 16:13:17,173 [root] DEBUG: 8528: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:17,173 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3F6E0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-30 16:13:17,177 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-30 16:13:17,178 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-30 16:13:17,180 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-30 16:13:17,180 [root] DEBUG: 8528: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-30 16:13:17,181 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-30 16:13:17,181 [root] DEBUG: 8528: DLL loaded at 0x00007FFF15300000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-30 16:13:17,182 [root] DEBUG: 8528: DLL loaded at 0x00007FFF17040000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-30 16:13:17,183 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-30 16:13:17,184 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-30 16:13:17,187 [root] DEBUG: 8528: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-30 16:13:17,188 [root] DEBUG: 8528: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:17,188 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-30 16:13:17,189 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-30 16:13:17,190 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-30 16:13:17,233 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3F980000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-30 16:13:17,247 [root] DEBUG: 8528: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-30 16:13:17,248 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-30 16:13:17,249 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-30 16:13:17,249 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-30 16:13:17,251 [root] DEBUG: 8528: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-30 16:13:17,254 [root] DEBUG: 8528: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-30 16:13:17,256 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-30 16:13:17,257 [root] DEBUG: 8528: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-30 16:13:17,257 [root] DEBUG: 8528: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-30 16:13:17,258 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-30 16:13:17,259 [root] DEBUG: 8528: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-30 16:13:17,260 [root] DEBUG: 8528: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-30 16:13:17,261 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-30 16:13:17,262 [root] DEBUG: 8528: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-30 16:13:17,263 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-30 16:13:17,263 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-30 16:13:17,264 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-30 16:13:17,267 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-30 16:13:17,269 [root] DEBUG: 8528: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-30 16:13:17,270 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-30 16:13:17,270 [root] DEBUG: 8528: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-30 16:13:17,271 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-30 16:13:17,273 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-30 16:13:17,275 [root] DEBUG: 8528: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-30 16:13:17,277 [root] DEBUG: 8528: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-30 16:13:17,278 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-30 16:13:17,279 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-30 16:13:17,282 [root] DEBUG: 8528: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-30 16:13:17,284 [root] DEBUG: 8528: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-30 16:13:17,284 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-30 16:13:17,285 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-30 16:13:17,287 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-30 16:13:17,289 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-30 16:13:17,290 [root] DEBUG: 8528: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-30 16:13:17,290 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-30 16:13:17,292 [root] DEBUG: 8528: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-30 16:13:17,292 [root] DEBUG: 8528: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-30 16:13:17,297 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-30 16:13:17,353 [root] DEBUG: 8528: DLL loaded at 0x00007FFEF8CC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-30 16:13:17,413 [root] DEBUG: 8528: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-30 16:13:17,429 [root] DEBUG: 8528: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-30 16:13:17,430 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 9716: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:17,430 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 9716
2026-05-30 16:13:17,431 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 9716
2026-05-30 16:13:17,447 [root] DEBUG: 8528: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-30 16:13:17,529 [root] DEBUG: 8528: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-30 16:13:17,535 [root] DEBUG: 8528: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 6.430811e+00)
2026-05-30 16:13:17,535 [root] DEBUG: 8528: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 9404).
2026-05-30 16:13:17,537 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 9892: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:17,537 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 9892
2026-05-30 16:13:17,538 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 9892
2026-05-30 16:13:17,540 [root] DEBUG: 8528: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 3.977021e-05)
2026-05-30 16:13:17,541 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 9920: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:17,541 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 9920
2026-05-30 16:13:17,542 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 9920
2026-05-30 16:13:17,588 [root] DEBUG: 8528: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-30 16:13:17,589 [root] DEBUG: 8528: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-30 16:13:17,643 [root] DEBUG: 8528: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-30 16:13:17,644 [root] DEBUG: 8528: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-30 16:13:17,645 [root] DEBUG: 8528: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-30 16:13:17,645 [root] DEBUG: 8528: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-30 16:13:17,711 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 10116: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:17,712 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 10144: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:17,712 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 10116
2026-05-30 16:13:17,712 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 10144
2026-05-30 16:13:17,713 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3F6B0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-30 16:13:17,713 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 10144
2026-05-30 16:13:17,713 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 10116
2026-05-30 16:13:17,727 [root] DEBUG: 8528: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-30 16:13:17,728 [root] DEBUG: 8528: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-30 16:13:17,729 [root] DEBUG: 8528: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-30 16:13:17,789 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3EA70000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-30 16:13:17,844 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3EFA0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-30 16:13:17,847 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3F8A0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-30 16:13:17,872 [root] DEBUG: 8528: DLL loaded at 0x00007FFF17080000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-30 16:13:17,956 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-30 16:13:17,958 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-30 16:13:17,959 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-30 16:13:17,980 [root] DEBUG: 8528: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-30 16:13:17,987 [root] DEBUG: 8528: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-30 16:13:17,989 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-30 16:13:18,010 [root] DEBUG: 8528: DLL loaded at 0x00007FFF16760000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-30 16:13:18,037 [root] DEBUG: 8528: DLL loaded at 0x00007FFF16A10000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-30 16:13:18,338 [root] DEBUG: 8528: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-30 16:13:18,812 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-30 16:13:19,111 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-30 16:13:19,167 [root] DEBUG: 8528: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:19,168 [root] DEBUG: 8528: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-30 16:13:22,752 [root] DEBUG: 8528: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-30 16:13:22,763 [root] DEBUG: 8528: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-30 16:13:22,770 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 11216: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:22,783 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 11216
2026-05-30 16:13:22,787 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 11232: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:22,791 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 11232
2026-05-30 16:13:22,795 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 11216
2026-05-30 16:13:22,797 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 11232
2026-05-30 16:13:23,959 [root] DEBUG: 8528: DLL loaded at 0x00007FFF0EAB0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-30 16:13:24,247 [root] DEBUG: 8528: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-30 16:13:24,250 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-30 16:13:24,390 [root] DEBUG: 8528: DLL loaded at 0x00007FFF0E450000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-30 16:13:24,527 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-30 16:13:24,528 [root] DEBUG: 8528: DLL loaded at 0x00007FFEF8850000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-30 16:13:24,529 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56250000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-30 16:13:24,530 [root] DEBUG: 8528: DLL loaded at 0x00007FFF561E0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-30 16:13:24,534 [root] DEBUG: 8528: DLL loaded at 0x00007FFF172C0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-30 16:13:24,570 [root] DEBUG: 8528: DLL loaded at 0x00007FFF42490000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-30 16:13:24,572 [root] DEBUG: 8528: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-30 16:13:24,573 [root] DEBUG: 8528: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-30 16:13:24,574 [root] DEBUG: 8528: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-30 16:13:29,423 [lib.api.process] INFO: Monitor config for process 832: C:\lpw_albt\dll\832.ini
2026-05-30 16:13:29,425 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:29,425 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:29,432 [root] DEBUG: Loader: Injecting process 832 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:29,435 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:29,436 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-30 16:13:29,436 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-30 16:13:29,437 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-30 16:13:29,461 [root] DEBUG: 832: Services hook set enabled
2026-05-30 16:13:29,464 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:29,478 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:29,479 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF15C80000, thread 5716, image base 0x00007FF7BF220000, stack from 0x000000CCA7B74000-0x000000CCA7B80000
2026-05-30 16:13:29,479 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-30 16:13:29,500 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-30 16:13:29,501 [root] INFO: Loaded monitor into process with pid 832
2026-05-30 16:13:29,502 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:29,502 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:29,503 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-30 16:13:31,317 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10680: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:31,320 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10680
2026-05-30 16:13:31,321 [lib.api.process] INFO: Monitor config for process 10680: C:\lpw_albt\dll\10680.ini
2026-05-30 16:13:31,321 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,322 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,329 [root] DEBUG: Loader: Injecting process 10680 (thread 6888) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,329 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:31,330 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,331 [lib.api.process] INFO: Injected into 64-bit <Process 10680 backgroundTaskHost.exe>
2026-05-30 16:13:31,333 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10680
2026-05-30 16:13:31,333 [lib.api.process] INFO: Monitor config for process 10680: C:\lpw_albt\dll\10680.ini
2026-05-30 16:13:31,334 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,335 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,340 [root] DEBUG: Loader: Injecting process 10680 (thread 6888) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,341 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:31,341 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,343 [lib.api.process] INFO: Injected into 64-bit <Process 10680 backgroundTaskHost.exe>
2026-05-30 16:13:31,343 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10680
2026-05-30 16:13:31,344 [lib.api.process] INFO: Monitor config for process 10680: C:\lpw_albt\dll\10680.ini
2026-05-30 16:13:31,344 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,344 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,349 [root] DEBUG: Loader: Injecting process 10680 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,352 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 6888, handle 0x120
2026-05-30 16:13:31,352 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:31,354 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,355 [lib.api.process] INFO: Injected into 64-bit <Process 10680 backgroundTaskHost.exe>
2026-05-30 16:13:31,489 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9864: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:31,490 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9864
2026-05-30 16:13:31,491 [lib.api.process] INFO: Monitor config for process 9864: C:\lpw_albt\dll\9864.ini
2026-05-30 16:13:31,493 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,494 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,502 [root] DEBUG: Loader: Injecting process 9864 (thread 11104) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,503 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:31,503 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,505 [lib.api.process] INFO: Injected into 64-bit <Process 9864 backgroundTaskHost.exe>
2026-05-30 16:13:31,507 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9864
2026-05-30 16:13:31,510 [lib.api.process] INFO: Monitor config for process 9864: C:\lpw_albt\dll\9864.ini
2026-05-30 16:13:31,595 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,596 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,602 [root] DEBUG: Loader: Injecting process 9864 (thread 11104) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,604 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:31,608 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,610 [lib.api.process] INFO: Injected into 64-bit <Process 9864 backgroundTaskHost.exe>
2026-05-30 16:13:31,615 [root] INFO: Process with pid 9864 has terminated
2026-05-30 16:13:31,656 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10544: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:31,657 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10544
2026-05-30 16:13:31,657 [lib.api.process] INFO: Monitor config for process 10544: C:\lpw_albt\dll\10544.ini
2026-05-30 16:13:31,681 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,683 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,693 [root] DEBUG: Loader: Injecting process 10544 (thread 10480) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,694 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:31,695 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,699 [lib.api.process] INFO: Injected into 64-bit <Process 10544 backgroundTaskHost.exe>
2026-05-30 16:13:31,701 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10544
2026-05-30 16:13:31,702 [lib.api.process] INFO: Monitor config for process 10544: C:\lpw_albt\dll\10544.ini
2026-05-30 16:13:31,703 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:31,704 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:31,709 [root] DEBUG: Loader: Injecting process 10544 (thread 10480) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,710 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:31,710 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:31,712 [lib.api.process] INFO: Injected into 64-bit <Process 10544 backgroundTaskHost.exe>
2026-05-30 16:13:31,714 [root] INFO: Process with pid 10544 has terminated
2026-05-30 16:13:31,797 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-30 16:13:34,663 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-30 16:13:35,213 [root] DEBUG: 8528: DLL loaded at 0x00007FFF3F9A0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-30 16:13:35,220 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 10484: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7F4370000
2026-05-30 16:13:35,221 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 10484
2026-05-30 16:13:35,221 [lib.api.process] INFO: Monitor config for process 10484: C:\lpw_albt\dll\10484.ini
2026-05-30 16:13:35,222 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:35,466 [root] DEBUG: 8528: DLL loaded at 0x00007FFF40900000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-30 16:13:35,873 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:13:35,873 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-30 16:13:35,874 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:13:35,874 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:13:35,874 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-30 16:13:35,874 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:13:35,875 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-30 16:13:35,875 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-30 16:13:35,882 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:35,887 [root] DEBUG: Loader: Injecting process 10484 (thread 7300) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:35,888 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:35,889 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:35,891 [lib.api.process] INFO: Injected into 64-bit <Process 10484 identity_helper.exe>
2026-05-30 16:13:35,909 [root] DEBUG: 8528: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-30 16:13:35,911 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4CBD0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-30 16:13:35,915 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 1980: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7F4370000
2026-05-30 16:13:35,916 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 1980
2026-05-30 16:13:35,917 [lib.api.process] INFO: Monitor config for process 1980: C:\lpw_albt\dll\1980.ini
2026-05-30 16:13:35,918 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:36,007 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:13:36,008 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-30 16:13:36,009 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:13:36,009 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:13:36,009 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-30 16:13:36,010 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:13:36,010 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-30 16:13:36,010 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-30 16:13:36,012 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:36,018 [root] DEBUG: Loader: Injecting process 1980 (thread 5580) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:36,020 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:36,021 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:36,024 [lib.api.process] INFO: Injected into 64-bit <Process 1980 identity_helper.exe>
2026-05-30 16:13:36,028 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 1980
2026-05-30 16:13:36,028 [lib.api.process] INFO: Monitor config for process 1980: C:\lpw_albt\dll\1980.ini
2026-05-30 16:13:36,029 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:36,110 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:13:36,110 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-30 16:13:36,111 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:13:36,111 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:13:36,111 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-30 16:13:36,111 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:13:36,111 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-30 16:13:36,111 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-30 16:13:36,113 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:36,118 [root] DEBUG: Loader: Injecting process 1980 (thread 5580) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:36,118 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:36,119 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:36,121 [lib.api.process] INFO: Injected into 64-bit <Process 1980 identity_helper.exe>
2026-05-30 16:13:36,281 [root] DEBUG: 1980: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:36,282 [root] DEBUG: 1980: Interactive desktop enabled.
2026-05-30 16:13:36,282 [root] DEBUG: 1980: Dropped file limit defaulting to 100.
2026-05-30 16:13:36,345 [root] DEBUG: 1980: Disabling sleep skipping.
2026-05-30 16:13:36,346 [root] DEBUG: 1980: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:36,361 [root] DEBUG: 1980: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:36,362 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:36,460 [root] DEBUG: 1980: Monitor initialised: 64-bit capemon loaded in process 1980 at 0x00007FFF15C80000, thread 5580, image base 0x00007FF7F4370000, stack from 0x00000002AB2F4000-0x00000002AB300000
2026-05-30 16:13:36,462 [root] DEBUG: 1980: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=6220,i,11808073459567193529,5979511840919348797,524288 --field-trial-handle=2360,i,7490981743879328103,7179834491009775954,262144 --variations-seed-version --pseudonymization-salt-handle=2376,i,7188834200906799960,921189437049491296
2026-05-30 16:13:36,463 [root] DEBUG: 1980: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-30 16:13:36,487 [root] DEBUG: 1980: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:36,510 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:36,512 [root] DEBUG: 1980: set_hooks: Unable to hook LockResource
2026-05-30 16:13:36,518 [root] DEBUG: 1980: Hooked 627 out of 628 functions
2026-05-30 16:13:36,534 [root] DEBUG: 1980: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:36,540 [root] DEBUG: 1980: RestoreHeaders: Restored original import table.
2026-05-30 16:13:36,544 [root] INFO: Loaded monitor into process with pid 1980
2026-05-30 16:13:36,544 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:36,560 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8756: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileCoAuth.exe, ImageBase: 0x00007FF748900000
2026-05-30 16:13:36,562 [root] INFO: Announced 64-bit process name: FileCoAuth.exe pid: 8756
2026-05-30 16:13:36,562 [lib.api.process] INFO: Monitor config for process 8756: C:\lpw_albt\dll\8756.ini
2026-05-30 16:13:36,563 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:36,893 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:13:36,893 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_atomic_wait.dll
2026-05-30 16:13:36,897 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:13:36,898 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:13:36,898 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_1.dll
2026-05-30 16:13:36,898 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:13:36,899 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-30 16:13:37,007 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:37,018 [root] DEBUG: Loader: Injecting process 8756 (thread 4748) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:37,019 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:37,021 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:37,024 [lib.api.process] INFO: Injected into 64-bit <Process 8756 FileCoAuth.exe>
2026-05-30 16:13:37,029 [root] INFO: Announced 64-bit process name: FileCoAuth.exe pid: 8756
2026-05-30 16:13:37,029 [lib.api.process] INFO: Monitor config for process 8756: C:\lpw_albt\dll\8756.ini
2026-05-30 16:13:37,030 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:37,164 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:13:37,164 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_atomic_wait.dll
2026-05-30 16:13:37,165 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:13:37,165 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:13:37,165 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_1.dll
2026-05-30 16:13:37,165 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:13:37,165 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-30 16:13:37,324 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:37,332 [root] DEBUG: Loader: Injecting process 8756 (thread 4748) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:37,333 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:37,334 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:37,335 [lib.api.process] INFO: Injected into 64-bit <Process 8756 FileCoAuth.exe>
2026-05-30 16:13:37,351 [root] DEBUG: 8756: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:37,353 [root] DEBUG: 8756: Interactive desktop enabled.
2026-05-30 16:13:37,353 [root] DEBUG: 8756: Dropped file limit defaulting to 100.
2026-05-30 16:13:37,356 [root] DEBUG: 8756: Disabling sleep skipping.
2026-05-30 16:13:37,359 [root] DEBUG: 8756: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:37,372 [root] DEBUG: 8756: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:37,373 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FF748900000, size 0x23fad2
2026-05-30 16:13:37,389 [root] DEBUG: 8756: Monitor initialised: 64-bit capemon loaded in process 8756 at 0x00007FFF15C80000, thread 4748, image base 0x00007FF748900000, stack from 0x000000D943134000-0x000000D943140000
2026-05-30 16:13:37,390 [root] DEBUG: 8756: Commandline: "C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileCoAuth.exe" -Embedding
2026-05-30 16:13:37,391 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\LoggingPlatform.DLL
2026-05-30 16:13:37,391 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncSessions.dll
2026-05-30 16:13:37,392 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncHost.DLL
2026-05-30 16:13:37,392 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\Telemetry.dll
2026-05-30 16:13:37,393 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncFS.DLL
2026-05-30 16:13:37,393 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\MSVCP140.dll
2026-05-30 16:13:37,394 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\VCRUNTIME140_1.dll
2026-05-30 16:13:37,394 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\UpdateRingSettings.dll
2026-05-30 16:13:37,395 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncEvents.dll
2026-05-30 16:13:37,395 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncSqlite3.dll
2026-05-30 16:13:37,395 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\MSVCP140_ATOMIC_WAIT.dll
2026-05-30 16:13:37,396 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\VCRUNTIME140.dll
2026-05-30 16:13:37,396 [root] DEBUG: 8756: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\adal.dll
2026-05-30 16:13:37,411 [root] DEBUG: 8756: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:37,442 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:37,445 [root] DEBUG: 8756: set_hooks: Unable to hook LockResource
2026-05-30 16:13:37,452 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:37,459 [root] DEBUG: 8756: Hooked 627 out of 628 functions
2026-05-30 16:13:37,476 [root] DEBUG: 8756: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:37,483 [root] DEBUG: 8756: RestoreHeaders: Restored original import table.
2026-05-30 16:13:37,485 [root] INFO: Loaded monitor into process with pid 8756
2026-05-30 16:13:37,485 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:37,486 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FFF18950000, size 0x1d2d1
2026-05-30 16:13:37,489 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FFF3F6A0000, size 0xa136
2026-05-30 16:13:37,492 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FFF141F0000, size 0x87804
2026-05-30 16:13:37,499 [root] DEBUG: 8756: caller_dispatch: Added region at 0x00007FFF141F0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x00007FFF14225311, thread 4748).
2026-05-30 16:13:37,500 [root] DEBUG: 8756: caller_dispatch: Scanning calling region at 0x00007FFF141F0000...
2026-05-30 16:13:37,501 [root] DEBUG: 8756: ProcessTrackedRegion: Region at 0x00007FFF141F0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\msvcp140.dll appears unmodified, skipping
2026-05-30 16:13:37,502 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FFF133E0000, size 0xaf16e
2026-05-30 16:13:37,512 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FFF133E0000, size 0xaf16e
2026-05-30 16:13:37,516 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:37,522 [root] DEBUG: 8756: YaraScan: Scanning 0x00007FFF133E0000, size 0xaf16e
2026-05-30 16:13:37,529 [root] DEBUG: 8756: caller_dispatch: Added region at 0x00007FFF133E0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FFF1344E0F1, thread 4748).
2026-05-30 16:13:37,530 [root] DEBUG: 8756: caller_dispatch: Scanning calling region at 0x00007FFF133E0000...
2026-05-30 16:13:37,530 [root] DEBUG: 8756: ProcessTrackedRegion: Region at 0x00007FFF133E0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\LoggingPlatform.dll appears unmodified, skipping
2026-05-30 16:13:37,545 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:37,571 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:37,596 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FFF0DCE0000, size 0x4b9994
2026-05-30 16:13:37,624 [root] DEBUG: 1980: caller_dispatch: Added region at 0x00007FFF0DCE0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF0DEDF156, thread 5580).
2026-05-30 16:13:37,625 [root] DEBUG: 1980: caller_dispatch: Scanning calling region at 0x00007FFF0DCE0000...
2026-05-30 16:13:37,638 [root] DEBUG: 1980: ProcessTrackedRegion: Region at 0x00007FFF0DCE0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-30 16:13:37,640 [root] DEBUG: 1980: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-30 16:13:37,696 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,716 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,732 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,747 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,762 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,780 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,800 [root] DEBUG: 1980: caller_dispatch: Added region at 0x00007FF7F4370000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7F4464096, thread 5580).
2026-05-30 16:13:37,801 [root] DEBUG: 1980: YaraScan: Scanning 0x00007FF7F4370000, size 0x28b4d8
2026-05-30 16:13:37,818 [root] DEBUG: 1980: ProcessImageBase: Main module image at 0x00007FF7F4370000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:37,823 [root] DEBUG: 1980: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:13:37,858 [root] DEBUG: 1980: DLL loaded at 0x000001903E000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-30 16:13:37,861 [root] DEBUG: 1980: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-30 16:13:37,864 [root] DEBUG: 1980: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-30 16:13:37,898 [root] DEBUG: 1980: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:13:39,105 [root] DEBUG: 4484: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-30 16:13:39,184 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db to files\0889094da20a6b8cf69c899d82007bf510f12d351a18d5608bffcca086b17ecf; Size is 81688; Max size: 100000000
2026-05-30 16:13:39,199 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000018.db to files\4bbd9c212d76fce6b51cb1897def4fb3c0984e445089d1ecf1b7d6f86760dca3; Size is 79472; Max size: 100000000
2026-05-30 16:13:39,266 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db to files\0889094da20a6b8cf69c899d82007bf510f12d351a18d5608bffcca086b17ecf; Size is 81688; Max size: 100000000
2026-05-30 16:13:39,412 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11624: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:39,414 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11624
2026-05-30 16:13:39,414 [lib.api.process] INFO: Monitor config for process 11624: C:\lpw_albt\dll\11624.ini
2026-05-30 16:13:39,415 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:39,416 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:39,421 [root] DEBUG: Loader: Injecting process 11624 (thread 11628) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,422 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:39,422 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,423 [lib.api.process] INFO: Injected into 64-bit <Process 11624 backgroundTaskHost.exe>
2026-05-30 16:13:39,425 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11624
2026-05-30 16:13:39,425 [lib.api.process] INFO: Monitor config for process 11624: C:\lpw_albt\dll\11624.ini
2026-05-30 16:13:39,426 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:39,427 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:39,434 [root] DEBUG: Loader: Injecting process 11624 (thread 11628) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,435 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:39,435 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,437 [lib.api.process] INFO: Injected into 64-bit <Process 11624 backgroundTaskHost.exe>
2026-05-30 16:13:39,438 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11624
2026-05-30 16:13:39,439 [lib.api.process] INFO: Monitor config for process 11624: C:\lpw_albt\dll\11624.ini
2026-05-30 16:13:39,443 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:39,444 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:39,449 [root] DEBUG: Loader: Injecting process 11624 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,450 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11628, handle 0x12c
2026-05-30 16:13:39,450 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:39,450 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,452 [lib.api.process] INFO: Injected into 64-bit <Process 11624 backgroundTaskHost.exe>
2026-05-30 16:13:39,520 [root] INFO: Announced 64-bit process name: OneDrive.exe pid: 10596
2026-05-30 16:13:39,520 [lib.api.process] INFO: Monitor config for process 10596: C:\lpw_albt\dll\10596.ini
2026-05-30 16:13:39,521 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:39,522 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:39,529 [root] DEBUG: Loader: Injecting process 10596 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,531 [root] DEBUG: 10596: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:39,532 [root] DEBUG: 10596: Interactive desktop enabled.
2026-05-30 16:13:39,532 [root] DEBUG: 10596: Dropped file limit defaulting to 100.
2026-05-30 16:13:39,533 [root] DEBUG: 10596: Disabling sleep skipping.
2026-05-30 16:13:39,534 [root] DEBUG: 10596: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:39,548 [root] DEBUG: 10596: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:39,550 [root] DEBUG: 10596: YaraScan: Scanning 0x00007FF743070000, size 0x48aa32
2026-05-30 16:13:39,566 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000018.db
2026-05-30 16:13:39,580 [root] DEBUG: 10596: Monitor initialised: 64-bit capemon loaded in process 10596 at 0x00007FFF15C80000, thread 11840, image base 0x00007FF743070000, stack from 0x0000004AC52F4000-0x0000004AC5300000
2026-05-30 16:13:39,581 [root] DEBUG: 10596: Commandline: /updateInstalled /background
2026-05-30 16:13:39,601 [root] DEBUG: 10596: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:39,637 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:39,638 [root] DEBUG: 10596: set_hooks: Unable to hook LockResource
2026-05-30 16:13:39,649 [root] DEBUG: 10596: Hooked 627 out of 628 functions
2026-05-30 16:13:39,671 [root] DEBUG: 10596: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:39,676 [root] INFO: Loaded monitor into process with pid 10596
2026-05-30 16:13:39,678 [root] DEBUG: 10596: DLL loaded at 0x00007FFF3EFC0000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-05-30 16:13:39,684 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:39,685 [root] DEBUG: 10596: DLL loaded at 0x00007FFF3F1E0000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-05-30 16:13:39,686 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:39,688 [lib.api.process] INFO: Injected into 64-bit <Process 10596 OneDrive.exe>
2026-05-30 16:13:39,693 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4F950000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-30 16:13:39,709 [root] DEBUG: 10596: caller_dispatch: Added region at 0x00007FF743070000 to tracked regions list (user32::FindWindowW returns to 0x00007FF743073F0C, thread 1932).
2026-05-30 16:13:39,710 [root] DEBUG: 10596: YaraScan: Scanning 0x00007FF743070000, size 0x48aa32
2026-05-30 16:13:39,735 [root] DEBUG: 10596: ProcessImageBase: Main module image at 0x00007FF743070000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:39,788 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\FeedbackHub\SubmissionPayload.json
2026-05-30 16:13:39,949 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\Personal\ECSConfig.json
2026-05-30 16:13:39,967 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\update.xml
2026-05-30 16:13:39,971 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KVL5QS5C\11d6494ec8d6087cf0f778a41c54621673d9830f[1].xml
2026-05-30 16:13:40,117 [root] DEBUG: 8528: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-30 16:13:40,119 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-30 16:13:40,316 [root] DEBUG: 10596: DLL loaded at 0x00007FFF393C0000: C:\Windows\SYSTEM32\rometadata (0x3b000 bytes).
2026-05-30 16:13:40,322 [root] DEBUG: 8528: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-30 16:13:40,323 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-30 16:13:40,324 [root] DEBUG: 8528: DLL loaded at 0x00007FFF50370000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-30 16:13:40,326 [root] DEBUG: 8528: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-30 16:13:40,327 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-30 16:13:40,330 [root] DEBUG: 8528: DLL loaded at 0x00007FFF45050000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-30 16:13:40,390 [root] DEBUG: 10596: DLL loaded at 0x00007FFF53A90000: C:\Windows\SYSTEM32\d2d1 (0x5c0000 bytes).
2026-05-30 16:13:40,391 [root] DEBUG: 10596: DLL loaded at 0x00007FFEDF960000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\Microsoft.UI.Xaml (0x628000 bytes).
2026-05-30 16:13:40,395 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-30 16:13:40,396 [root] DEBUG: 10596: DLL loaded at 0x00007FFF538A0000: C:\Windows\System32\dcomp (0x1e3000 bytes).
2026-05-30 16:13:40,400 [root] DEBUG: 10596: DLL loaded at 0x00007FFF49E50000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-30 16:13:40,420 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4F4D0000: C:\Windows\System32\BitsProxy (0x16000 bytes).
2026-05-30 16:13:40,443 [root] DEBUG: 10596: DLL loaded at 0x00007FFF46660000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-30 16:13:40,445 [root] DEBUG: 10596: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-30 16:13:40,456 [root] DEBUG: 10596: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-30 16:13:40,460 [root] DEBUG: 10596: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-30 16:13:40,479 [root] DEBUG: 10596: DLL loaded at 0x00007FFF55120000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-30 16:13:40,487 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4CE40000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-30 16:13:40,489 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4FAA0000: C:\Windows\SYSTEM32\d3d10warp (0x6f6000 bytes).
2026-05-30 16:13:40,492 [root] DEBUG: 10596: DLL loaded at 0x00007FFF16760000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-30 16:13:40,497 [root] DEBUG: 10596: DLL loaded at 0x000001BAC4770000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-30 16:13:40,503 [root] DEBUG: 10596: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-30 16:13:40,504 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4F9D0000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-30 16:13:40,508 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4C870000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-30 16:13:40,510 [root] DEBUG: 10596: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\dwrite (0x27f000 bytes).
2026-05-30 16:13:40,518 [root] DEBUG: 10596: DLL loaded at 0x00007FFF49830000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-05-30 16:13:40,527 [root] DEBUG: 10596: AllocationHandler: Adding allocation to tracked region list: 0x00007DF494831000, size: 0x1000.
2026-05-30 16:13:40,531 [root] DEBUG: 10596: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-30 16:13:40,541 [root] DEBUG: 10596: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\DataExchange (0x3e000 bytes).
2026-05-30 16:13:40,552 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 688: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:40,553 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 688
2026-05-30 16:13:40,553 [lib.api.process] INFO: Monitor config for process 688: C:\lpw_albt\dll\688.ini
2026-05-30 16:13:40,559 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,561 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,568 [root] DEBUG: Loader: Injecting process 688 (thread 10576) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,569 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:40,571 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,573 [lib.api.process] INFO: Injected into 64-bit <Process 688 backgroundTaskHost.exe>
2026-05-30 16:13:40,574 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 688
2026-05-30 16:13:40,575 [lib.api.process] INFO: Monitor config for process 688: C:\lpw_albt\dll\688.ini
2026-05-30 16:13:40,575 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,576 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,581 [root] DEBUG: Loader: Injecting process 688 (thread 10576) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,582 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:40,583 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,584 [root] DEBUG: 10596: DLL loaded at 0x00007FFF490B0000: C:\Windows\SYSTEM32\Windows.UI.Xaml.Controls (0x3dc000 bytes).
2026-05-30 16:13:40,584 [lib.api.process] INFO: Injected into 64-bit <Process 688 backgroundTaskHost.exe>
2026-05-30 16:13:40,586 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 688
2026-05-30 16:13:40,589 [lib.api.process] INFO: Monitor config for process 688: C:\lpw_albt\dll\688.ini
2026-05-30 16:13:40,590 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,591 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,597 [lib.api.process] INFO: Injected into 64-bit <Process 688 backgroundTaskHost.exe>
2026-05-30 16:13:40,605 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11004: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:40,608 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11004
2026-05-30 16:13:40,608 [lib.api.process] INFO: Monitor config for process 11004: C:\lpw_albt\dll\11004.ini
2026-05-30 16:13:40,609 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,610 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,611 [root] DEBUG: 10596: DLL loaded at 0x000001BAC8AA0000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\MSVCP140_APP (0x3e000 bytes).
2026-05-30 16:13:40,611 [root] DEBUG: 10596: DLL loaded at 0x000001BAC8AF0000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\VCRUNTIME140_1_APP (0x3000 bytes).
2026-05-30 16:13:40,612 [root] DEBUG: 10596: DLL loaded at 0x000001BAC8B10000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\VCRUNTIME140_APP (0x4000 bytes).
2026-05-30 16:13:40,612 [root] DEBUG: 10596: DLL loaded at 0x00007FFEDF660000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\Microsoft.ReactNative (0x2f5000 bytes).
2026-05-30 16:13:40,616 [root] DEBUG: Loader: Injecting process 11004 (thread 10944) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,618 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:40,622 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,623 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-30 16:13:40,624 [lib.api.process] INFO: Injected into 64-bit <Process 11004 backgroundTaskHost.exe>
2026-05-30 16:13:40,625 [root] DEBUG: 10596: DLL loaded at 0x00007FFF3FCB0000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\CheckboxWindows (0x37000 bytes).
2026-05-30 16:13:40,626 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11004
2026-05-30 16:13:40,627 [lib.api.process] INFO: Monitor config for process 11004: C:\lpw_albt\dll\11004.ini
2026-05-30 16:13:40,627 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,628 [root] DEBUG: 10596: DLL loaded at 0x00007FFF3FC70000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\ReactNativePicker (0x3f000 bytes).
2026-05-30 16:13:40,629 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,636 [root] DEBUG: Loader: Injecting process 11004 (thread 10944) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,637 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:40,638 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,639 [root] DEBUG: 10596: DLL loaded at 0x00007FFF130C0000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\RNSVG (0x111000 bytes).
2026-05-30 16:13:40,640 [lib.api.process] INFO: Injected into 64-bit <Process 11004 backgroundTaskHost.exe>
2026-05-30 16:13:40,640 [root] DEBUG: 10596: DLL loaded at 0x000001BAC8CD0000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\ReactNativeVideoCPP (0x3e000 bytes).
2026-05-30 16:13:40,641 [root] INFO: Process with pid 11004 has terminated
2026-05-30 16:13:40,658 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11944: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:40,658 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11944
2026-05-30 16:13:40,659 [lib.api.process] INFO: Monitor config for process 11944: C:\lpw_albt\dll\11944.ini
2026-05-30 16:13:40,660 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,661 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,667 [root] DEBUG: Loader: Injecting process 11944 (thread 11948) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,668 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:40,669 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,670 [lib.api.process] INFO: Injected into 64-bit <Process 11944 backgroundTaskHost.exe>
2026-05-30 16:13:40,672 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11944
2026-05-30 16:13:40,673 [lib.api.process] INFO: Monitor config for process 11944: C:\lpw_albt\dll\11944.ini
2026-05-30 16:13:40,673 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,675 [root] DEBUG: 10596: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-30 16:13:40,676 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,686 [root] DEBUG: Loader: Injecting process 11944 (thread 11948) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,688 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:40,689 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,691 [lib.api.process] INFO: Injected into 64-bit <Process 11944 backgroundTaskHost.exe>
2026-05-30 16:13:40,693 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 11944
2026-05-30 16:13:40,693 [lib.api.process] INFO: Monitor config for process 11944: C:\lpw_albt\dll\11944.ini
2026-05-30 16:13:40,694 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,695 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,702 [root] DEBUG: Loader: Injecting process 11944 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,703 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11948, handle 0x98
2026-05-30 16:13:40,704 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:40,704 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,706 [lib.api.process] INFO: Injected into 64-bit <Process 11944 backgroundTaskHost.exe>
2026-05-30 16:13:40,712 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10996: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:40,712 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10996
2026-05-30 16:13:40,713 [lib.api.process] INFO: Monitor config for process 10996: C:\lpw_albt\dll\10996.ini
2026-05-30 16:13:40,729 [root] INFO: Process with pid 8756 appears to have terminated
2026-05-30 16:13:40,737 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,740 [root] DEBUG: 1980: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:13:40,747 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,748 [root] DEBUG: 1980: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:13:40,753 [root] DEBUG: 1980: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-30 16:13:40,755 [root] DEBUG: Loader: Injecting process 10996 (thread 11048) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,756 [root] DEBUG: 1980: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-30 16:13:40,757 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:40,759 [root] DEBUG: 1980: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-30 16:13:40,762 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,775 [lib.api.process] INFO: Injected into 64-bit <Process 10996 backgroundTaskHost.exe>
2026-05-30 16:13:40,776 [root] DEBUG: 1980: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-30 16:13:40,778 [root] DEBUG: 1980: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-30 16:13:40,779 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10996
2026-05-30 16:13:40,779 [root] DEBUG: 1980: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-30 16:13:40,779 [lib.api.process] INFO: Monitor config for process 10996: C:\lpw_albt\dll\10996.ini
2026-05-30 16:13:40,780 [root] DEBUG: 1980: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-30 16:13:40,781 [root] DEBUG: 1980: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-30 16:13:40,781 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,785 [root] DEBUG: 10596: DLL loaded at 0x00007FFF163B0000: C:\Windows\SYSTEM32\familysafetyext (0x8000 bytes).
2026-05-30 16:13:40,786 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,788 [root] DEBUG: 10596: DLL loaded at 0x00007FFF58AB0000: C:\Windows\System32\Normaliz (0x8000 bytes).
2026-05-30 16:13:40,791 [root] DEBUG: 10596: DLL loaded at 0x00007FFF15160000: C:\Windows\System32\wpc (0x198000 bytes).
2026-05-30 16:13:40,799 [root] DEBUG: Loader: Injecting process 10996 (thread 11048) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,800 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:40,801 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,802 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\System32\samcli (0x19000 bytes).
2026-05-30 16:13:40,808 [lib.api.process] INFO: Injected into 64-bit <Process 10996 backgroundTaskHost.exe>
2026-05-30 16:13:40,809 [root] DEBUG: 10596: DLL loaded at 0x00007FFF452A0000: C:\Windows\System32\wlidprov (0xaa000 bytes).
2026-05-30 16:13:40,814 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10996
2026-05-30 16:13:40,816 [root] DEBUG: 1980: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-30 16:13:40,817 [lib.api.process] INFO: Monitor config for process 10996: C:\lpw_albt\dll\10996.ini
2026-05-30 16:13:40,817 [root] DEBUG: 10596: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-30 16:13:40,823 [root] DEBUG: 10596: DLL loaded at 0x00007FFF3D570000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-30 16:13:40,824 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,825 [root] DEBUG: 1980: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-30 16:13:40,826 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,827 [root] INFO: Stopping Task Scheduler Service
2026-05-30 16:13:40,836 [root] DEBUG: Loader: Injecting process 10996 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,837 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json
2026-05-30 16:13:40,838 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11048, handle 0x124
2026-05-30 16:13:40,839 [root] DEBUG: 1980: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:40,840 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:40,842 [root] DEBUG: 1980: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-30 16:13:40,846 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,849 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\78c091ac6d34daa9d603629dd088840de549030f.tbres
2026-05-30 16:13:40,856 [root] DEBUG: 1980: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-30 16:13:40,882 [root] INFO: Stopped Task Scheduler Service
2026-05-30 16:13:40,882 [root] DEBUG: 1980: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-30 16:13:40,884 [lib.api.process] INFO: Injected into 64-bit <Process 10996 backgroundTaskHost.exe>
2026-05-30 16:13:40,886 [root] DEBUG: 10596: DLL loaded at 0x00007FFF42E10000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-30 16:13:40,895 [root] DEBUG: 1980: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-30 16:13:40,907 [root] INFO: Starting Task Scheduler Service
2026-05-30 16:13:40,918 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12392: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:40,922 [root] DEBUG: 1980: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-30 16:13:40,923 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12392
2026-05-30 16:13:40,924 [lib.api.process] INFO: Monitor config for process 12392: C:\lpw_albt\dll\12392.ini
2026-05-30 16:13:40,924 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12472: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:40,926 [root] DEBUG: 1980: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-30 16:13:40,926 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,931 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,938 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12472
2026-05-30 16:13:40,940 [root] DEBUG: 1980: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-30 16:13:40,941 [root] DEBUG: Loader: Injecting process 12392 (thread 12396) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,941 [lib.api.process] INFO: Monitor config for process 12472: C:\lpw_albt\dll\12472.ini
2026-05-30 16:13:40,954 [root] INFO: Started Task Scheduler Service
2026-05-30 16:13:40,955 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:40,956 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,959 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,964 [lib.api.process] INFO: Monitor config for process 1292: C:\lpw_albt\dll\1292.ini
2026-05-30 16:13:40,968 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,978 [lib.api.process] INFO: Injected into 64-bit <Process 12392 backgroundTaskHost.exe>
2026-05-30 16:13:40,979 [root] DEBUG: Loader: Injecting process 12472 (thread 12476) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,982 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12392
2026-05-30 16:13:40,982 [lib.api.process] INFO: Monitor config for process 12392: C:\lpw_albt\dll\12392.ini
2026-05-30 16:13:40,983 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:40,983 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,984 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:40,984 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,985 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,986 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:40,991 [lib.api.process] INFO: Injected into 64-bit <Process 12472 backgroundTaskHost.exe>
2026-05-30 16:13:40,992 [root] DEBUG: Loader: Injecting process 12392 (thread 12396) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,993 [root] DEBUG: Loader: Injecting process 1292 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:40,994 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:41,000 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12472
2026-05-30 16:13:41,004 [root] DEBUG: 1980: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-30 16:13:41,005 [lib.api.process] INFO: Monitor config for process 12472: C:\lpw_albt\dll\12472.ini
2026-05-30 16:13:41,006 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:41,006 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,014 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:41,016 [root] DEBUG: 1292: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:41,017 [root] DEBUG: 1292: Disabling sleep skipping.
2026-05-30 16:13:41,018 [root] DEBUG: 1292: Interactive desktop enabled.
2026-05-30 16:13:41,020 [lib.api.process] INFO: Injected into 64-bit <Process 12392 backgroundTaskHost.exe>
2026-05-30 16:13:41,022 [root] DEBUG: 1292: Dropped file limit defaulting to 100.
2026-05-30 16:13:41,023 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12392
2026-05-30 16:13:41,024 [root] DEBUG: Loader: Injecting process 12472 (thread 12476) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,024 [lib.api.process] INFO: Monitor config for process 12392: C:\lpw_albt\dll\12392.ini
2026-05-30 16:13:41,025 [root] DEBUG: 1292: Services hook set enabled
2026-05-30 16:13:41,033 [root] DEBUG: 1980: DLL loaded at 0x000001903CC20000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-30 16:13:41,033 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:41,034 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:41,048 [root] DEBUG: 1292: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:41,049 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:41,049 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,061 [lib.api.process] INFO: Injected into 64-bit <Process 12472 backgroundTaskHost.exe>
2026-05-30 16:13:41,062 [root] DEBUG: Loader: Injecting process 12392 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,064 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12396, handle 0x120
2026-05-30 16:13:41,064 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12472
2026-05-30 16:13:41,065 [lib.api.process] INFO: Monitor config for process 12472: C:\lpw_albt\dll\12472.ini
2026-05-30 16:13:41,065 [root] DEBUG: 1292: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:41,066 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:41,066 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:41,066 [root] DEBUG: 1292: Monitor initialised: 64-bit capemon loaded in process 1292 at 0x00007FFF15C80000, thread 12732, image base 0x00007FF7BF220000, stack from 0x000000250E8F4000-0x000000250E900000
2026-05-30 16:13:41,067 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,068 [root] DEBUG: 1292: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-30 16:13:41,068 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:41,069 [lib.api.process] INFO: Injected into 64-bit <Process 12392 backgroundTaskHost.exe>
2026-05-30 16:13:41,081 [root] DEBUG: 1980: DLL loaded at 0x00007FFF4B780000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-30 16:13:41,083 [root] DEBUG: Loader: Injecting process 12472 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,084 [root] DEBUG: 1980: DLL loaded at 0x00007FFF4B840000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-30 16:13:41,085 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12476, handle 0x120
2026-05-30 16:13:41,088 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12980: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:41,089 [root] DEBUG: 1980: DLL loaded at 0x00007FFF43150000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-30 16:13:41,091 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12980
2026-05-30 16:13:41,095 [root] DEBUG: 1980: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-30 16:13:41,095 [lib.api.process] INFO: Monitor config for process 12980: C:\lpw_albt\dll\12980.ini
2026-05-30 16:13:41,096 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:41,098 [root] DEBUG: 1292: Hooked 69 out of 69 functions
2026-05-30 16:13:41,098 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:41,107 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,108 [root] INFO: Loaded monitor into process with pid 1292
2026-05-30 16:13:41,109 [root] DEBUG: 1980: DLL loaded at 0x00007FFF4F6E0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-30 16:13:41,109 [lib.api.process] INFO: Injected into 64-bit <Process 12472 backgroundTaskHost.exe>
2026-05-30 16:13:41,110 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:41,111 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,113 [lib.api.process] INFO: Injected into 64-bit <Process 1292 svchost.exe>
2026-05-30 16:13:41,119 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:41,130 [root] DEBUG: Loader: Injecting process 12980 (thread 12984) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,131 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:41,132 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,142 [lib.api.process] INFO: Injected into 64-bit <Process 12980 backgroundTaskHost.exe>
2026-05-30 16:13:41,145 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12980
2026-05-30 16:13:41,146 [lib.api.process] INFO: Monitor config for process 12980: C:\lpw_albt\dll\12980.ini
2026-05-30 16:13:41,152 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:41,156 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:41,162 [root] DEBUG: Loader: Injecting process 12980 (thread 12984) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,163 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:41,165 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:41,167 [root] DEBUG: 1980: DLL loaded at 0x00007FFF55EF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-30 16:13:41,167 [lib.api.process] INFO: Injected into 64-bit <Process 12980 backgroundTaskHost.exe>
2026-05-30 16:13:41,168 [root] DEBUG: 1980: DLL loaded at 0x00007FFF53070000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-30 16:13:41,170 [root] INFO: Process with pid 12980 has terminated
2026-05-30 16:13:41,176 [root] DEBUG: 1980: DLL loaded at 0x00007FFF48B40000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-30 16:13:41,179 [root] DEBUG: 1980: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-30 16:13:41,199 [root] DEBUG: 1980: DLL loaded at 0x00007FFF43060000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-30 16:13:41,280 [root] DEBUG: 1980: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-30 16:13:41,281 [root] DEBUG: 1980: DLL loaded at 0x00007FFF56FA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-30 16:13:41,282 [root] DEBUG: 1980: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-30 16:13:41,282 [root] DEBUG: 1980: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-30 16:13:41,283 [root] DEBUG: 1980: DLL loaded at 0x00007FFF43DD0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-30 16:13:41,369 [root] DEBUG: 1980: DLL loaded at 0x00007FFF3D810000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-30 16:13:41,400 [root] DEBUG: 1980: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-30 16:13:41,450 [root] DEBUG: 1980: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-30 16:13:42,139 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000017.db to files\0889094da20a6b8cf69c899d82007bf510f12d351a18d5608bffcca086b17ecf; Size is 81688; Max size: 100000000
2026-05-30 16:13:42,146 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000018.db to files\4bbd9c212d76fce6b51cb1897def4fb3c0984e445089d1ecf1b7d6f86760dca3; Size is 79472; Max size: 100000000
2026-05-30 16:13:42,148 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000019.db to files\57ab9b7dd1eb45168f5d8bf19d6cd96446d46f59ab6b7874e6dee1ac874bc9af; Size is 78648; Max size: 100000000
2026-05-30 16:13:42,184 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000018.db to files\4bbd9c212d76fce6b51cb1897def4fb3c0984e445089d1ecf1b7d6f86760dca3; Size is 79472; Max size: 100000000
2026-05-30 16:13:43,119 [root] DEBUG: 10596: DLL loaded at 0x00007FFF524B0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-30 16:13:43,184 [root] DEBUG: 10596: DLL loaded at 0x00007FFF166D0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-30 16:13:43,190 [root] DEBUG: 10596: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:43,191 [root] DEBUG: 10596: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-30 16:13:43,264 [root] DEBUG: 10596: DLL loaded at 0x00007FFF50490000: C:\Windows\System32\Windows.Graphics (0x8d000 bytes).
2026-05-30 16:13:43,271 [root] DEBUG: 10596: DLL loaded at 0x000001BAC8DC0000: C:\Windows\SYSTEM32\icuuc (0x9000 bytes).
2026-05-30 16:13:43,271 [root] DEBUG: 10596: DLL loaded at 0x000001BAC8DD0000: C:\Windows\SYSTEM32\icuin (0x8000 bytes).
2026-05-30 16:13:43,272 [root] DEBUG: 10596: DLL loaded at 0x00007FFF39190000: C:\Windows\SYSTEM32\icu (0x22e000 bytes).
2026-05-30 16:13:43,272 [root] DEBUG: 10596: DLL loaded at 0x00007FFEDE5C0000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\hermes (0x477000 bytes).
2026-05-30 16:13:43,331 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-30 16:13:43,362 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-30 16:13:43,381 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-30 16:13:43,396 [root] DEBUG: 10596: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-30 16:13:43,403 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\Personal\CxP.db-journal to files\f42c6334fd90fd1364d44aa25db7ee29bb5e5894dd29cf15757e71191dc928fe; Size is 512; Max size: 100000000
2026-05-30 16:13:43,434 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\Personal\CxP.db-journal
2026-05-30 16:13:43,436 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-30 16:13:43,445 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\Personal\CxP.db-journal to files\121dce4a12fea425acea5f17c0c7e0f12db9c9562d7b5bd20a7645e94a301566; Size is 4616; Max size: 100000000
2026-05-30 16:13:43,514 [root] DEBUG: 10596: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:13:43,518 [root] DEBUG: 10596: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-30 16:13:43,563 [root] DEBUG: 10596: DLL loaded at 0x00007FFF41C10000: C:\Windows\SYSTEM32\ntshrui (0x7d000 bytes).
2026-05-30 16:13:43,573 [root] DEBUG: 10596: DLL loaded at 0x00007FFF434D0000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-05-30 16:13:43,579 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13400: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:43,583 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13400
2026-05-30 16:13:43,583 [lib.api.process] INFO: Monitor config for process 13400: C:\lpw_albt\dll\13400.ini
2026-05-30 16:13:43,585 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,587 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,625 [root] DEBUG: Loader: Injecting process 13400 (thread 13404) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,645 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:43,647 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,655 [lib.api.process] INFO: Injected into 64-bit <Process 13400 backgroundTaskHost.exe>
2026-05-30 16:13:43,661 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13400
2026-05-30 16:13:43,671 [lib.api.process] INFO: Monitor config for process 13400: C:\lpw_albt\dll\13400.ini
2026-05-30 16:13:43,672 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,673 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,677 [root] DEBUG: 10596: DLL loaded at 0x00007FFF498E0000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2026-05-30 16:13:43,684 [root] DEBUG: Loader: Injecting process 13400 (thread 13404) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,703 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:43,705 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,706 [root] DEBUG: 10596: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-30 16:13:43,708 [lib.api.process] INFO: Injected into 64-bit <Process 13400 backgroundTaskHost.exe>
2026-05-30 16:13:43,711 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13400
2026-05-30 16:13:43,717 [lib.api.process] INFO: Monitor config for process 13400: C:\lpw_albt\dll\13400.ini
2026-05-30 16:13:43,753 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,754 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,761 [root] DEBUG: Loader: Injecting process 13400 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,761 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13404, handle 0x120
2026-05-30 16:13:43,762 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:43,765 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,768 [lib.api.process] INFO: Injected into 64-bit <Process 13400 backgroundTaskHost.exe>
2026-05-30 16:13:43,817 [root] DEBUG: 10596: DLL loaded at 0x00007FFF406E0000: C:\Windows\System32\Windows.UI.Core.TextInput (0x104000 bytes).
2026-05-30 16:13:43,866 [root] DEBUG: 10596: AllocationHandler: Adding allocation to tracked region list: 0x00007DF494821000, size: 0x1000.
2026-05-30 16:13:43,937 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13852: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:43,938 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13852
2026-05-30 16:13:43,939 [lib.api.process] INFO: Monitor config for process 13852: C:\lpw_albt\dll\13852.ini
2026-05-30 16:13:43,939 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,940 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,946 [root] DEBUG: Loader: Injecting process 13852 (thread 13856) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,947 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:43,948 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,949 [lib.api.process] INFO: Injected into 64-bit <Process 13852 backgroundTaskHost.exe>
2026-05-30 16:13:43,950 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13852
2026-05-30 16:13:43,951 [lib.api.process] INFO: Monitor config for process 13852: C:\lpw_albt\dll\13852.ini
2026-05-30 16:13:43,953 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,956 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,964 [root] DEBUG: Loader: Injecting process 13852 (thread 13856) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,965 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:43,966 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,968 [lib.api.process] INFO: Injected into 64-bit <Process 13852 backgroundTaskHost.exe>
2026-05-30 16:13:43,969 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13852
2026-05-30 16:13:43,969 [lib.api.process] INFO: Monitor config for process 13852: C:\lpw_albt\dll\13852.ini
2026-05-30 16:13:43,969 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,971 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,977 [root] DEBUG: Loader: Injecting process 13852 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,977 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13856, handle 0x120
2026-05-30 16:13:43,978 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:43,978 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,979 [lib.api.process] INFO: Injected into 64-bit <Process 13852 backgroundTaskHost.exe>
2026-05-30 16:13:43,985 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14020: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:43,985 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 14020
2026-05-30 16:13:43,986 [lib.api.process] INFO: Monitor config for process 14020: C:\lpw_albt\dll\14020.ini
2026-05-30 16:13:43,989 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:43,990 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:43,996 [root] DEBUG: Loader: Injecting process 14020 (thread 14024) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,997 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:43,997 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:43,999 [lib.api.process] INFO: Injected into 64-bit <Process 14020 backgroundTaskHost.exe>
2026-05-30 16:13:44,001 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 14020
2026-05-30 16:13:44,001 [lib.api.process] INFO: Monitor config for process 14020: C:\lpw_albt\dll\14020.ini
2026-05-30 16:13:44,001 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:44,003 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:44,010 [root] DEBUG: Loader: Injecting process 14020 (thread 14024) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:44,010 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:44,011 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:44,013 [lib.api.process] INFO: Injected into 64-bit <Process 14020 backgroundTaskHost.exe>
2026-05-30 16:13:44,014 [root] INFO: Process with pid 14020 has terminated
2026-05-30 16:13:44,025 [root] DEBUG: 10596: DLL loaded at 0x00007FFF56D70000: C:\Windows\system32\cryptdll (0x15000 bytes).
2026-05-30 16:13:44,026 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4C8A0000: C:\Windows\system32\TQUERY (0x32e000 bytes).
2026-05-30 16:13:44,028 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4B130000: C:\Windows\system32\ESENT (0x335000 bytes).
2026-05-30 16:13:44,029 [root] DEBUG: 10596: DLL loaded at 0x00007FFF4C580000: C:\Windows\system32\mssrch (0x2de000 bytes).
2026-05-30 16:13:44,244 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14192: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-30 16:13:44,245 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14192
2026-05-30 16:13:44,246 [lib.api.process] INFO: Monitor config for process 14192: C:\lpw_albt\dll\14192.ini
2026-05-30 16:13:44,247 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:44,247 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:44,254 [root] DEBUG: Loader: Injecting process 14192 (thread 14196) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:44,257 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:44,260 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:44,262 [lib.api.process] INFO: Injected into 64-bit <Process 14192 dllhost.exe>
2026-05-30 16:13:44,264 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14192
2026-05-30 16:13:44,265 [lib.api.process] INFO: Monitor config for process 14192: C:\lpw_albt\dll\14192.ini
2026-05-30 16:13:44,265 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:44,267 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:44,273 [root] DEBUG: Loader: Injecting process 14192 (thread 14196) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:44,273 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:44,276 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:44,281 [lib.api.process] INFO: Injected into 64-bit <Process 14192 dllhost.exe>
2026-05-30 16:13:44,289 [root] DEBUG: 14192: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:44,290 [root] DEBUG: 14192: Interactive desktop enabled.
2026-05-30 16:13:44,290 [root] DEBUG: 14192: Dropped file limit defaulting to 100.
2026-05-30 16:13:44,299 [root] DEBUG: 14192: Disabling sleep skipping.
2026-05-30 16:13:44,300 [root] DEBUG: 14192: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:44,314 [root] DEBUG: 14192: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:44,315 [root] DEBUG: 14192: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-30 16:13:44,316 [root] DEBUG: 14192: Monitor initialised: 64-bit capemon loaded in process 14192 at 0x00007FFF15C80000, thread 14196, image base 0x00007FF6706B0000, stack from 0x00000043EFBE4000-0x00000043EFBF0000
2026-05-30 16:13:44,318 [root] DEBUG: 14192: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-30 16:13:44,338 [root] DEBUG: 14192: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:44,365 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:44,366 [root] DEBUG: 14192: set_hooks: Unable to hook LockResource
2026-05-30 16:13:44,373 [root] DEBUG: 14192: Hooked 627 out of 628 functions
2026-05-30 16:13:44,375 [root] DEBUG: 14192: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:44,380 [root] DEBUG: 14192: RestoreHeaders: Restored original import table.
2026-05-30 16:13:44,380 [root] INFO: Loaded monitor into process with pid 14192
2026-05-30 16:13:44,381 [root] DEBUG: 14192: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 14196).
2026-05-30 16:13:44,382 [root] DEBUG: 14192: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-30 16:13:44,387 [root] DEBUG: 14192: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:44,390 [root] DEBUG: 14192: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:13:44,391 [root] DEBUG: 14192: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-30 16:13:44,394 [root] DEBUG: 14192: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:13:44,409 [root] DEBUG: 14192: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-30 16:13:44,431 [root] DEBUG: 14192: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:13:44,433 [root] DEBUG: 14192: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-30 16:13:44,445 [root] DEBUG: 14192: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-30 16:13:44,461 [root] DEBUG: 14192: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-30 16:13:44,470 [root] DEBUG: 14192: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-30 16:13:44,471 [root] DEBUG: 14192: DLL loaded at 0x00007FFF55710000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-30 16:13:44,516 [root] DEBUG: 14192: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-30 16:13:44,533 [root] DEBUG: 14192: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-30 16:13:44,546 [root] DEBUG: 14192: DLL loaded at 0x00007FFF47420000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-30 16:13:44,709 [root] DEBUG: 14192: DLL loaded at 0x00007FFF57560000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-30 16:13:44,713 [root] DEBUG: 14192: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-30 16:13:44,746 [root] DEBUG: 14192: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-30 16:13:44,749 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:44,750 [root] DEBUG: 14192: OpenProcessHandler: Injection info created for process 4484, handle 0x438: Error obtaining target process name
2026-05-30 16:13:45,506 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-30 16:13:45,506 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:45,509 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:45,519 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,522 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00000000031D0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00000000031D0044, thread 14884).
2026-05-30 16:13:45,523 [root] DEBUG: 4484: DumpPEsInRange: Scanning range 0x00000000031D0000 - 0x00000000031D0135.
2026-05-30 16:13:45,525 [root] DEBUG: 4484: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-30 16:13:45,529 [lib.common.results] INFO: Uploading file C:\gbSlmMlCP\CAPE\4484_2152545132030652026 to CAPE\694ea164d62a1cf5eb95306ab684d548c002d262eadbfbae91c35280cbfaf084; Size is 309; Max size: 100000000
2026-05-30 16:13:45,531 [root] DEBUG: 4484: DumpMemory: Payload successfully created: C:\gbSlmMlCP\CAPE\4484_2152545132030652026 (size 309 bytes)
2026-05-30 16:13:45,532 [root] DEBUG: 4484: DumpRegion: Dumped entire allocation from 0x00000000031D0000, size 4096 bytes.
2026-05-30 16:13:45,541 [root] DEBUG: 4484: ProcessTrackedRegion: Dumped region at 0x00000000031D0000.
2026-05-30 16:13:45,544 [root] DEBUG: 4484: YaraScan: Scanning 0x00000000031D0000, size 0x135
2026-05-30 16:13:45,545 [root] DEBUG: 4484: Monitor config - unrecognised key host-ip.
2026-05-30 16:13:45,546 [root] DEBUG: 4484: Monitor config - unrecognised key host-port.
2026-05-30 16:13:45,548 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:45,549 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-30 16:13:45,579 [root] DEBUG: 4484: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:45,625 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:45,636 [root] DEBUG: 4484: set_hooks: Unable to hook LockResource
2026-05-30 16:13:45,663 [root] DEBUG: 4484: Hooked 627 out of 628 functions
2026-05-30 16:13:45,693 [root] INFO: Loaded monitor into process with pid 4484
2026-05-30 16:13:45,696 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-30 16:13:45,700 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,907 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 15412: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:45,908 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 15412
2026-05-30 16:13:45,908 [lib.api.process] INFO: Monitor config for process 15412: C:\lpw_albt\dll\15412.ini
2026-05-30 16:13:45,909 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:45,910 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:45,919 [root] DEBUG: Loader: Injecting process 15412 (thread 15416) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,919 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:45,920 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,921 [lib.api.process] INFO: Injected into 64-bit <Process 15412 backgroundTaskHost.exe>
2026-05-30 16:13:45,923 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 15412
2026-05-30 16:13:45,923 [lib.api.process] INFO: Monitor config for process 15412: C:\lpw_albt\dll\15412.ini
2026-05-30 16:13:45,923 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:45,924 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:45,928 [root] DEBUG: Loader: Injecting process 15412 (thread 15416) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,930 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:45,931 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,932 [lib.api.process] INFO: Injected into 64-bit <Process 15412 backgroundTaskHost.exe>
2026-05-30 16:13:45,935 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 15412
2026-05-30 16:13:45,936 [lib.api.process] INFO: Monitor config for process 15412: C:\lpw_albt\dll\15412.ini
2026-05-30 16:13:45,936 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:45,938 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:45,950 [root] DEBUG: Loader: Injecting process 15412 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,951 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15416, handle 0x120
2026-05-30 16:13:45,952 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:45,953 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:45,955 [lib.api.process] INFO: Injected into 64-bit <Process 15412 backgroundTaskHost.exe>
2026-05-30 16:13:46,832 [root] DEBUG: 10596: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-30 16:13:47,421 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4D390000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-30 16:13:47,422 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 15228: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:13:47,424 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 15228
2026-05-30 16:13:47,425 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 15228
2026-05-30 16:13:47,776 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-30 16:13:47,777 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-30 16:13:47,794 [root] DEBUG: 4484: DLL loaded at 0x00007FFED5EB0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-30 16:13:47,795 [root] DEBUG: 4484: DLL loaded at 0x00007FFED5EB0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-30 16:13:47,829 [root] DEBUG: 4484: DLL loaded at 0x00007FFED5AC0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-30 16:13:47,830 [root] DEBUG: 4484: DLL loaded at 0x00007FFED5AC0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-30 16:13:48,231 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14860: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7BB740000
2026-05-30 16:13:48,233 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 14860
2026-05-30 16:13:48,233 [lib.api.process] INFO: Monitor config for process 14860: C:\lpw_albt\dll\14860.ini
2026-05-30 16:13:48,234 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,288 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-30 16:13:48,315 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-30 16:13:48,351 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,358 [root] DEBUG: Loader: Injecting process 14860 (thread 15048) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,360 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:48,361 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,363 [lib.api.process] INFO: Injected into 64-bit <Process 14860 WmiPrvSE.exe>
2026-05-30 16:13:48,367 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 14860
2026-05-30 16:13:48,368 [lib.api.process] INFO: Monitor config for process 14860: C:\lpw_albt\dll\14860.ini
2026-05-30 16:13:48,368 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,521 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,533 [root] DEBUG: Loader: Injecting process 14860 (thread 15048) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,535 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:48,537 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,541 [lib.api.process] INFO: Injected into 64-bit <Process 14860 WmiPrvSE.exe>
2026-05-30 16:13:48,551 [root] DEBUG: 14860: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:48,552 [root] DEBUG: 14860: Interactive desktop enabled.
2026-05-30 16:13:48,561 [root] DEBUG: 14860: Dropped file limit defaulting to 100.
2026-05-30 16:13:48,585 [root] DEBUG: 14860: Disabling sleep skipping.
2026-05-30 16:13:48,590 [root] DEBUG: 14860: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:48,608 [root] DEBUG: 14860: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:48,610 [root] DEBUG: 14860: YaraScan: Scanning 0x00007FF7BB740000, size 0x7dcfe
2026-05-30 16:13:48,610 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 16820: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:48,613 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 16820
2026-05-30 16:13:48,613 [root] DEBUG: 14860: Monitor initialised: 64-bit capemon loaded in process 14860 at 0x00007FFF15C80000, thread 15048, image base 0x00007FF7BB740000, stack from 0x0000006F0FB50000-0x0000006F0FB60000
2026-05-30 16:13:48,614 [lib.api.process] INFO: Monitor config for process 16820: C:\lpw_albt\dll\16820.ini
2026-05-30 16:13:48,614 [root] DEBUG: 14860: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding
2026-05-30 16:13:48,615 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,616 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,627 [root] DEBUG: Loader: Injecting process 16820 (thread 16824) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,629 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:48,631 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,631 [root] DEBUG: 14860: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:48,636 [lib.api.process] INFO: Injected into 64-bit <Process 16820 backgroundTaskHost.exe>
2026-05-30 16:13:48,639 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 16820
2026-05-30 16:13:48,639 [lib.api.process] INFO: Monitor config for process 16820: C:\lpw_albt\dll\16820.ini
2026-05-30 16:13:48,640 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,643 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,660 [root] DEBUG: Loader: Injecting process 16820 (thread 16824) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,661 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:48,661 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:48,662 [root] DEBUG: 14860: set_hooks: Unable to hook LockResource
2026-05-30 16:13:48,662 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,669 [lib.api.process] INFO: Injected into 64-bit <Process 16820 backgroundTaskHost.exe>
2026-05-30 16:13:48,671 [root] DEBUG: 14860: Hooked 627 out of 628 functions
2026-05-30 16:13:48,672 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 16820
2026-05-30 16:13:48,673 [lib.api.process] INFO: Monitor config for process 16820: C:\lpw_albt\dll\16820.ini
2026-05-30 16:13:48,673 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,675 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,678 [root] DEBUG: 14860: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:48,683 [root] DEBUG: Loader: Injecting process 16820 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,684 [root] DEBUG: 14860: RestoreHeaders: Restored original import table.
2026-05-30 16:13:48,684 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16824, handle 0x124
2026-05-30 16:13:48,685 [root] INFO: Loaded monitor into process with pid 14860
2026-05-30 16:13:48,686 [root] DEBUG: 14860: caller_dispatch: Added region at 0x00007FF7BB740000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7BB752CD1, thread 15048).
2026-05-30 16:13:48,687 [root] DEBUG: 14860: YaraScan: Scanning 0x00007FF7BB740000, size 0x7dcfe
2026-05-30 16:13:48,688 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:48,693 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,694 [root] DEBUG: 14860: ProcessImageBase: Main module image at 0x00007FF7BB740000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:48,700 [lib.api.process] INFO: Injected into 64-bit <Process 16820 backgroundTaskHost.exe>
2026-05-30 16:13:48,703 [root] DEBUG: 14860: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:13:48,704 [root] DEBUG: 14860: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-30 16:13:48,709 [root] DEBUG: 14860: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:13:48,713 [lib.api.process] INFO: Monitor config for process 7948: C:\lpw_albt\dll\7948.ini
2026-05-30 16:13:48,716 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,717 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,725 [root] DEBUG: Loader: Injecting process 7948 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,733 [root] DEBUG: 7948: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:48,738 [root] DEBUG: 7948: Disabling sleep skipping.
2026-05-30 16:13:48,741 [root] DEBUG: 7948: Interactive desktop enabled.
2026-05-30 16:13:48,742 [root] DEBUG: 7948: Dropped file limit defaulting to 100.
2026-05-30 16:13:48,744 [root] DEBUG: 7948: Services hook set enabled
2026-05-30 16:13:48,750 [root] DEBUG: 7948: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:48,757 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17280: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:48,765 [root] DEBUG: 7948: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:48,769 [root] DEBUG: 7948: Monitor initialised: 64-bit capemon loaded in process 7948 at 0x00007FFF15C80000, thread 17204, image base 0x00007FF7BF220000, stack from 0x000000DA31B74000-0x000000DA31B80000
2026-05-30 16:13:48,772 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17280
2026-05-30 16:13:48,775 [root] DEBUG: 7948: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-30 16:13:48,778 [lib.api.process] INFO: Monitor config for process 17280: C:\lpw_albt\dll\17280.ini
2026-05-30 16:13:48,779 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,783 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,801 [root] DEBUG: Loader: Injecting process 17280 (thread 17284) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,801 [root] DEBUG: 7948: Hooked 69 out of 69 functions
2026-05-30 16:13:48,802 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:48,804 [root] INFO: Loaded monitor into process with pid 7948
2026-05-30 16:13:48,805 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,808 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:48,811 [lib.api.process] INFO: Injected into 64-bit <Process 17280 backgroundTaskHost.exe>
2026-05-30 16:13:48,813 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,814 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17280
2026-05-30 16:13:48,815 [lib.api.process] INFO: Monitor config for process 17280: C:\lpw_albt\dll\17280.ini
2026-05-30 16:13:48,815 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,815 [lib.api.process] INFO: Injected into 64-bit <Process 7948 svchost.exe>
2026-05-30 16:13:48,816 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,831 [root] DEBUG: Loader: Injecting process 17280 (thread 17284) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,833 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:48,834 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,836 [lib.api.process] INFO: Injected into 64-bit <Process 17280 backgroundTaskHost.exe>
2026-05-30 16:13:48,842 [root] INFO: Process with pid 17280 has terminated
2026-05-30 16:13:48,856 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12032: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:48,873 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12032
2026-05-30 16:13:48,874 [lib.api.process] INFO: Monitor config for process 12032: C:\lpw_albt\dll\12032.ini
2026-05-30 16:13:48,875 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,876 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,888 [root] DEBUG: Loader: Injecting process 12032 (thread 9028) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,889 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:48,890 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,895 [lib.api.process] INFO: Injected into 64-bit <Process 12032 backgroundTaskHost.exe>
2026-05-30 16:13:48,905 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12032
2026-05-30 16:13:48,906 [lib.api.process] INFO: Monitor config for process 12032: C:\lpw_albt\dll\12032.ini
2026-05-30 16:13:48,908 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,909 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,921 [root] DEBUG: Loader: Injecting process 12032 (thread 9028) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,924 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:48,926 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-30 16:13:48,927 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,929 [lib.api.process] INFO: Injected into 64-bit <Process 12032 backgroundTaskHost.exe>
2026-05-30 16:13:48,930 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12032
2026-05-30 16:13:48,931 [lib.api.process] INFO: Monitor config for process 12032: C:\lpw_albt\dll\12032.ini
2026-05-30 16:13:48,932 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,934 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,936 [root] INFO: Process with pid 712 has terminated
2026-05-30 16:13:48,939 [root] DEBUG: Loader: Injecting process 12032 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,940 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9028, handle 0x120
2026-05-30 16:13:48,940 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:48,943 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,945 [lib.api.process] INFO: Injected into 64-bit <Process 12032 backgroundTaskHost.exe>
2026-05-30 16:13:48,958 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12336: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:48,959 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12336
2026-05-30 16:13:48,960 [lib.api.process] INFO: Monitor config for process 12336: C:\lpw_albt\dll\12336.ini
2026-05-30 16:13:48,963 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:48,965 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:48,966 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000019.db
2026-05-30 16:13:48,981 [root] DEBUG: Loader: Injecting process 12336 (thread 12420) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,984 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:48,986 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:48,989 [lib.api.process] INFO: Injected into 64-bit <Process 12336 backgroundTaskHost.exe>
2026-05-30 16:13:48,994 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12336
2026-05-30 16:13:48,996 [lib.api.process] INFO: Monitor config for process 12336: C:\lpw_albt\dll\12336.ini
2026-05-30 16:13:49,000 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,003 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,008 [root] DEBUG: Loader: Injecting process 12336 (thread 12420) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,014 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,021 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,029 [lib.api.process] INFO: Injected into 64-bit <Process 12336 backgroundTaskHost.exe>
2026-05-30 16:13:49,034 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12336
2026-05-30 16:13:49,035 [lib.api.process] INFO: Monitor config for process 12336: C:\lpw_albt\dll\12336.ini
2026-05-30 16:13:49,035 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,037 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,039 [root] DEBUG: 4484: Dropped file limit reached.
2026-05-30 16:13:49,046 [root] DEBUG: Loader: Injecting process 12336 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,047 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12420, handle 0x120
2026-05-30 16:13:49,047 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,048 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,054 [lib.api.process] INFO: Injected into 64-bit <Process 12336 backgroundTaskHost.exe>
2026-05-30 16:13:49,079 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12944: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:49,081 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12944
2026-05-30 16:13:49,081 [lib.api.process] INFO: Monitor config for process 12944: C:\lpw_albt\dll\12944.ini
2026-05-30 16:13:49,083 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,084 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,094 [root] DEBUG: Loader: Injecting process 12944 (thread 12700) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,098 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:49,107 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,123 [lib.api.process] INFO: Injected into 64-bit <Process 12944 backgroundTaskHost.exe>
2026-05-30 16:13:49,128 [root] DEBUG: 4484: DLL loaded at 0x00007FFF56D70000: C:\Windows\system32\cryptdll (0x15000 bytes).
2026-05-30 16:13:49,139 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12944
2026-05-30 16:13:49,139 [root] DEBUG: 4484: DLL loaded at 0x00007FFF56D70000: C:\Windows\system32\cryptdll (0x15000 bytes).
2026-05-30 16:13:49,140 [lib.api.process] INFO: Monitor config for process 12944: C:\lpw_albt\dll\12944.ini
2026-05-30 16:13:49,141 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C8A0000: C:\Windows\system32\TQUERY (0x32e000 bytes).
2026-05-30 16:13:49,141 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C8A0000: C:\Windows\system32\TQUERY (0x32e000 bytes).
2026-05-30 16:13:49,142 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4B130000: C:\Windows\system32\ESENT (0x335000 bytes).
2026-05-30 16:13:49,142 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4B130000: C:\Windows\system32\ESENT (0x335000 bytes).
2026-05-30 16:13:49,143 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C580000: C:\Windows\system32\mssrch (0x2de000 bytes).
2026-05-30 16:13:49,143 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C580000: C:\Windows\system32\mssrch (0x2de000 bytes).
2026-05-30 16:13:49,146 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,150 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,158 [root] DEBUG: Loader: Injecting process 12944 (thread 12700) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,159 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,160 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,161 [lib.api.process] INFO: Injected into 64-bit <Process 12944 backgroundTaskHost.exe>
2026-05-30 16:13:49,163 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12944
2026-05-30 16:13:49,164 [lib.api.process] INFO: Monitor config for process 12944: C:\lpw_albt\dll\12944.ini
2026-05-30 16:13:49,165 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,167 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,174 [root] DEBUG: Loader: Injecting process 12944 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,174 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12700, handle 0x120
2026-05-30 16:13:49,175 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,176 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,177 [lib.api.process] INFO: Injected into 64-bit <Process 12944 backgroundTaskHost.exe>
2026-05-30 16:13:49,184 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17176: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:49,185 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17176
2026-05-30 16:13:49,185 [lib.api.process] INFO: Monitor config for process 17176: C:\lpw_albt\dll\17176.ini
2026-05-30 16:13:49,186 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,187 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,191 [root] DEBUG: 14192: DLL loaded at 0x00007FFF51B20000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-30 16:13:49,191 [root] DEBUG: 14192: DLL loaded at 0x00007FFF47790000: C:\Windows\system32\PhotoMetadataHandler (0x84000 bytes).
2026-05-30 16:13:49,192 [root] DEBUG: Loader: Injecting process 17176 (thread 17172) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,192 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:49,193 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,194 [lib.api.process] INFO: Injected into 64-bit <Process 17176 backgroundTaskHost.exe>
2026-05-30 16:13:49,197 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17176
2026-05-30 16:13:49,197 [lib.api.process] INFO: Monitor config for process 17176: C:\lpw_albt\dll\17176.ini
2026-05-30 16:13:49,197 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,199 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,207 [root] DEBUG: Loader: Injecting process 17176 (thread 17172) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,207 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,208 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,209 [lib.api.process] INFO: Injected into 64-bit <Process 17176 backgroundTaskHost.exe>
2026-05-30 16:13:49,211 [root] INFO: Process with pid 17176 has terminated
2026-05-30 16:13:49,226 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10732: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:49,226 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10732
2026-05-30 16:13:49,227 [lib.api.process] INFO: Monitor config for process 10732: C:\lpw_albt\dll\10732.ini
2026-05-30 16:13:49,228 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,229 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,234 [root] DEBUG: Loader: Injecting process 10732 (thread 12408) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,235 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:49,236 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,237 [lib.api.process] INFO: Injected into 64-bit <Process 10732 backgroundTaskHost.exe>
2026-05-30 16:13:49,238 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10732
2026-05-30 16:13:49,239 [lib.api.process] INFO: Monitor config for process 10732: C:\lpw_albt\dll\10732.ini
2026-05-30 16:13:49,239 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,240 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,246 [root] DEBUG: 10596: api-cap: LdrpCallInitRoutine hook disabled due to count: 5000
2026-05-30 16:13:49,251 [root] DEBUG: Loader: Injecting process 10732 (thread 12408) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,251 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,252 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,253 [lib.api.process] INFO: Injected into 64-bit <Process 10732 backgroundTaskHost.exe>
2026-05-30 16:13:49,254 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10732
2026-05-30 16:13:49,255 [lib.api.process] INFO: Monitor config for process 10732: C:\lpw_albt\dll\10732.ini
2026-05-30 16:13:49,255 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,258 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,264 [root] DEBUG: Loader: Injecting process 10732 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,266 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12408, handle 0x124
2026-05-30 16:13:49,267 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,269 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,271 [lib.api.process] INFO: Injected into 64-bit <Process 10732 backgroundTaskHost.exe>
2026-05-30 16:13:49,280 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14432: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-30 16:13:49,281 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 14432
2026-05-30 16:13:49,281 [lib.api.process] INFO: Monitor config for process 14432: C:\lpw_albt\dll\14432.ini
2026-05-30 16:13:49,282 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,283 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,289 [root] DEBUG: Loader: Injecting process 14432 (thread 336) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,290 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:49,292 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,293 [root] DEBUG: 4484: api-cap: NtClose hook disabled due to count: 5000
2026-05-30 16:13:49,296 [lib.api.process] INFO: Injected into 64-bit <Process 14432 backgroundTaskHost.exe>
2026-05-30 16:13:49,300 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 14432
2026-05-30 16:13:49,300 [lib.api.process] INFO: Monitor config for process 14432: C:\lpw_albt\dll\14432.ini
2026-05-30 16:13:49,300 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:49,301 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:49,309 [root] DEBUG: Loader: Injecting process 14432 (thread 336) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,310 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:49,312 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:49,313 [lib.api.process] INFO: Injected into 64-bit <Process 14432 backgroundTaskHost.exe>
2026-05-30 16:13:49,314 [root] INFO: Process with pid 14432 has terminated
2026-05-30 16:13:49,393 [root] DEBUG: 10596: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-30 16:13:49,471 [root] DEBUG: 10596: api-cap: NtQueryKey hook disabled due to count: 5000
2026-05-30 16:13:49,647 [root] DEBUG: 10596: api-cap: NtClose hook disabled due to count: 5000
2026-05-30 16:13:50,200 [root] DEBUG: 10596: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-30 16:13:50,242 [root] DEBUG: 10596: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-30 16:13:50,299 [root] INFO: Announced starting service "b'edgeupdate'"
2026-05-30 16:13:50,300 [lib.api.process] INFO: Monitor config for process 676: C:\lpw_albt\dll\676.ini
2026-05-30 16:13:50,301 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:50,303 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:50,307 [root] DEBUG: Loader: Injecting process 676 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:50,309 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\676.ini to system path C:\676.ini
2026-05-30 16:13:50,311 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\lpw_albt\dll\RRWCoUiC.dll
2026-05-30 16:13:50,312 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:50,314 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-30 16:13:50,348 [root] DEBUG: 10596: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-30 16:13:50,822 [root] DEBUG: 14860: DLL loaded at 0x00007FFF3FD20000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-30 16:13:50,828 [root] DEBUG: 14860: DLL loaded at 0x00007FFF3F950000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-30 16:13:50,842 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 18428, handle 0x21b8: C:\Windows\System32\services.exe
2026-05-30 16:13:50,857 [root] DEBUG: 14860: DLL loaded at 0x00007FFF4D000000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-30 16:13:50,888 [root] DEBUG: 14860: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-30 16:13:50,889 [root] DEBUG: 14860: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-30 16:13:50,889 [root] DEBUG: 14860: DLL loaded at 0x00007FFF13BC0000: C:\Windows\system32\umpowmi (0x1b000 bytes).
2026-05-30 16:13:50,890 [root] DEBUG: 14860: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-30 16:13:51,212 [root] DEBUG: 4484: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-30 16:13:51,564 [root] INFO: Process with pid 1980 has terminated
2026-05-30 16:13:51,589 [root] DEBUG: 1980: NtTerminateProcess hook: Attempting to dump process 1980
2026-05-30 16:13:51,592 [root] DEBUG: 1980: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:13:51,937 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:51,939 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-30 16:13:51,940 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-30 16:13:51,940 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-30 16:13:51,945 [root] DEBUG: 676: Services hook set enabled
2026-05-30 16:13:52,117 [root] DEBUG: 4484: api-cap: NtQueryKey hook disabled due to count: 5000
2026-05-30 16:13:52,118 [root] DEBUG: 4484: api-cap: NtQueryKey hook disabled due to count: 5001
2026-05-30 16:13:52,141 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:52,143 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFF13BE0000, thread 19624, image base 0x00007FF7839A0000, stack from 0x000000F2F00F1000-0x000000F2F0100000
2026-05-30 16:13:52,144 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-30 16:13:52,181 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-30 16:13:52,185 [root] INFO: Loaded monitor into process with pid 676
2026-05-30 16:13:52,328 [root] DEBUG: 4484: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-30 16:13:53,074 [root] DEBUG: 10596: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-30 16:13:53,136 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:53,138 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 8044, handle 0xf6c: Error obtaining target process name
2026-05-30 16:13:53,140 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:53,141 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6136, handle 0x29a4: Error obtaining target process name
2026-05-30 16:13:53,142 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:53,145 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5624, handle 0xe28: Error obtaining target process name
2026-05-30 16:13:53,146 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:53,147 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 8528, handle 0x16a4: Error obtaining target process name
2026-05-30 16:13:53,147 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:53,148 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5128, handle 0xf64: Error obtaining target process name
2026-05-30 16:13:53,150 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:53,152 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6400, handle 0x8e4: Error obtaining target process name
2026-05-30 16:13:53,155 [root] DEBUG: 4484: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-30 16:13:53,238 [root] DEBUG: 4484: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-30 16:13:53,255 [root] DEBUG: 10596: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5000
2026-05-30 16:13:53,256 [root] DEBUG: 4484: api-cap: CoCreateInstance hook disabled due to count: 5000
2026-05-30 16:13:53,349 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-30 16:13:53,355 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-30 16:13:53,365 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-30 16:13:53,368 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 20980: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x0000000000150000
2026-05-30 16:13:53,376 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 20980
2026-05-30 16:13:53,378 [lib.api.process] INFO: Monitor config for process 20980: C:\lpw_albt\dll\20980.ini
2026-05-30 16:13:53,380 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:53,387 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:53,501 [root] DEBUG: Loader: Injecting process 20980 (thread 20984) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:53,504 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:53,505 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:53,511 [lib.api.process] INFO: Injected into 32-bit <Process 20980 MicrosoftEdgeUpdate.exe>
2026-05-30 16:13:53,522 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 20980
2026-05-30 16:13:53,523 [lib.api.process] INFO: Monitor config for process 20980: C:\lpw_albt\dll\20980.ini
2026-05-30 16:13:53,525 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:53,527 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:53,536 [root] DEBUG: Loader: Injecting process 20980 (thread 20984) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:53,537 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:53,538 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:53,542 [lib.api.process] INFO: Injected into 32-bit <Process 20980 MicrosoftEdgeUpdate.exe>
2026-05-30 16:13:53,543 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 20980
2026-05-30 16:13:53,544 [lib.api.process] INFO: Monitor config for process 20980: C:\lpw_albt\dll\20980.ini
2026-05-30 16:13:53,544 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:53,546 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:53,557 [root] DEBUG: Loader: Injecting process 20980 with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:53,560 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2026-05-30 16:13:53,622 [root] DEBUG: 20980: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:53,624 [root] DEBUG: 20980: Interactive desktop enabled.
2026-05-30 16:13:53,624 [root] DEBUG: 20980: Dropped file limit defaulting to 100.
2026-05-30 16:13:53,629 [root] DEBUG: 20980: Disabling sleep skipping.
2026-05-30 16:13:53,634 [root] DEBUG: 20980: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:53,636 [root] DEBUG: 20980: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:13:53,638 [root] DEBUG: 20980: Monitor initialised: 32-bit capemon loaded in process 20980 at 0x75180000, thread 21204, image base 0x150000, stack from 0x3285000-0x3290000
2026-05-30 16:13:53,639 [root] DEBUG: 20980: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
2026-05-30 16:13:53,684 [root] DEBUG: 20980: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:13:53,701 [root] DEBUG: 20980: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:13:53,702 [root] DEBUG: 20980: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:13:53,709 [root] DEBUG: 20980: Hooked 632 out of 632 functions
2026-05-30 16:13:53,711 [root] DEBUG: 20980: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:53,720 [root] DEBUG: 20980: RestoreHeaders: Restored original import table.
2026-05-30 16:13:53,721 [root] INFO: Loaded monitor into process with pid 20980
2026-05-30 16:13:53,722 [root] DEBUG: 20980: caller_dispatch: Added region at 0x03140000 to tracked regions list (ntdll::LdrLoadDll returns to 0x03140037, thread 21204).
2026-05-30 16:13:53,723 [root] DEBUG: 20980: DumpPEsInRange: Scanning range 0x03140000 - 0x03140129.
2026-05-30 16:13:53,723 [root] DEBUG: 20980: ScanForDisguisedPE: Size too small: 0x129 bytes
2026-05-30 16:13:53,732 [lib.common.results] INFO: Uploading file C:\gbSlmMlCP\CAPE\20980_1349045753132030652026 to CAPE\d980cd566b156ddb6018046a6c1abe871f7b8c91c3cb26ce065cdc6c978f4b12; Size is 297; Max size: 100000000
2026-05-30 16:13:53,735 [root] DEBUG: 20980: DumpMemory: Payload successfully created: C:\gbSlmMlCP\CAPE\20980_1349045753132030652026 (size 297 bytes)
2026-05-30 16:13:53,736 [root] DEBUG: 20980: DumpRegion: Dumped entire allocation from 0x03140000, size 4096 bytes.
2026-05-30 16:13:53,736 [root] DEBUG: 20980: ProcessTrackedRegion: Dumped region at 0x03140000.
2026-05-30 16:13:53,737 [root] DEBUG: 20980: YaraScan: Scanning 0x03140000, size 0x129
2026-05-30 16:13:53,738 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:53,738 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:53,740 [lib.api.process] INFO: Injected into 32-bit <Process 20980 MicrosoftEdgeUpdate.exe>
2026-05-30 16:13:53,744 [root] DEBUG: 20980: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 20984).
2026-05-30 16:13:53,746 [root] DEBUG: 20980: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:13:53,748 [root] DEBUG: 20980: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:53,755 [root] DEBUG: 20980: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:13:53,756 [root] DEBUG: 20980: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:13:53,774 [root] DEBUG: 20980: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-30 16:13:53,788 [root] DEBUG: 20980: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-30 16:13:53,793 [root] DEBUG: 20980: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-30 16:13:53,794 [root] DEBUG: 20980: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-30 16:13:53,795 [root] DEBUG: 20980: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-30 16:13:53,795 [root] DEBUG: 20980: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-30 16:13:53,796 [root] DEBUG: 20980: DLL loaded at 0x6AEB0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-30 16:13:53,831 [root] DEBUG: 20980: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:13:53,834 [root] DEBUG: 20980: DLL loaded at 0x755E0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:13:53,859 [root] DEBUG: 20980: DLL loaded at 0x75560000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:13:53,861 [root] DEBUG: 20980: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-30 16:13:53,862 [root] DEBUG: 20980: DLL loaded at 0x754C0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:13:53,863 [root] DEBUG: 20980: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:13:53,863 [root] DEBUG: 20980: DLL loaded at 0x754A0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:13:53,864 [root] DEBUG: 20980: DLL loaded at 0x754F0000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:13:53,865 [root] DEBUG: 20980: DLL loaded at 0x755B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:13:53,868 [root] DEBUG: 20980: DLL loaded at 0x75490000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:13:53,872 [root] DEBUG: 20980: DLL loaded at 0x75150000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:13:53,881 [root] DEBUG: 20980: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:13:53,882 [root] DEBUG: 20980: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-30 16:13:53,883 [root] DEBUG: 20980: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-30 16:13:53,894 [root] DEBUG: 20980: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-30 16:13:53,942 [root] DEBUG: 20980: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:13:53,945 [root] DEBUG: 20980: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-30 16:13:53,961 [root] DEBUG: 20980: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-30 16:13:53,984 [root] DEBUG: 20980: DLL loaded at 0x755E0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\psmachine (0x58000 bytes).
2026-05-30 16:13:54,086 [root] DEBUG: 4484: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-30 16:13:54,096 [root] INFO: Added new file to list with pid 10596 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings.ini
2026-05-30 16:13:54,153 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\SyncEngine-2026-05-29.0052.1104.1.odl to files\0f47bc9fb54e56ecfca9518cc321e640e6f7d65f18c5dac43f23bf18d37b4342; Size is 636407; Max size: 100000000
2026-05-30 16:13:54,261 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:13:54,262 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5740, handle 0x3b4: Error obtaining target process name
2026-05-30 16:13:54,294 [root] INFO: Process with pid 14192 has terminated
2026-05-30 16:13:54,295 [root] DEBUG: 14192: NtTerminateProcess hook: Attempting to dump process 14192
2026-05-30 16:13:54,297 [root] DEBUG: 14192: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:13:54,400 [root] DEBUG: 20980: DLL loaded at 0x75580000: C:\Windows\System32\SystemSettings.DataModel (0x57000 bytes).
2026-05-30 16:13:54,406 [root] DEBUG: 20980: caller_dispatch: Added region at 0x75580000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x755AB711, thread 9684).
2026-05-30 16:13:54,408 [root] DEBUG: 20980: ProcessTrackedRegion: Region at 0x75580000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\SystemSettings.DataModel.dll is in known range, skipping
2026-05-30 16:13:54,420 [root] DEBUG: 20980: DLL loaded at 0x75550000: C:\Windows\SYSTEM32\USERENV (0x25000 bytes).
2026-05-30 16:13:54,422 [root] DEBUG: 20980: caller_dispatch: Added region at 0x75550000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x75557B6E, thread 9684).
2026-05-30 16:13:54,423 [root] DEBUG: 20980: ProcessTrackedRegion: Region at 0x75550000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\userenv.dll is in known range, skipping
2026-05-30 16:13:54,441 [root] DEBUG: 20980: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:13:54,442 [root] DEBUG: 20980: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:13:54,460 [root] DEBUG: 20980: DLL loaded at 0x73BE0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x3ba000 bytes).
2026-05-30 16:13:54,494 [root] DEBUG: 20980: DLL loaded at 0x77270000: C:\Windows\System32\CFGMGR32 (0x3b000 bytes).
2026-05-30 16:13:54,509 [root] DEBUG: 20980: DLL loaded at 0x754C0000: C:\Windows\System32\StructuredQuery (0x81000 bytes).
2026-05-30 16:13:54,515 [root] DEBUG: 20980: caller_dispatch: Added region at 0x754C0000 to tracked regions list (user32::GetKeyboardLayout returns to 0x754E420D, thread 5644).
2026-05-30 16:13:54,516 [root] DEBUG: 20980: ProcessTrackedRegion: Region at 0x754C0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\StructuredQuery.dll is in known range, skipping
2026-05-30 16:13:54,537 [root] DEBUG: 20980: DLL loaded at 0x750B0000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2026-05-30 16:13:54,552 [root] DEBUG: 20980: DLL loaded at 0x74390000: C:\Windows\System32\Windows.StateRepositoryPS (0x93000 bytes).
2026-05-30 16:13:54,577 [root] DEBUG: 20980: DLL loaded at 0x742F0000: C:\Windows\system32\Windows.Storage.Search (0x9d000 bytes).
2026-05-30 16:13:54,612 [root] DEBUG: 20980: DLL loaded at 0x754B0000: C:\Windows\SYSTEM32\LINKINFO (0xb000 bytes).
2026-05-30 16:13:54,665 [root] DEBUG: 20980: DLL loaded at 0x73A00000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-30 16:13:54,683 [root] DEBUG: 20980: DLL loaded at 0x6AE60000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-30 16:13:54,731 [root] DEBUG: 20980: DLL loaded at 0x74220000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-30 16:13:54,737 [root] DEBUG: 20980: DLL loaded at 0x75490000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-30 16:13:54,744 [root] DEBUG: 20980: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-05-30 16:13:54,747 [root] DEBUG: 20980: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-30 16:13:54,750 [root] DEBUG: 20980: DLL loaded at 0x75490000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-30 16:13:54,755 [root] DEBUG: 20980: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-30 16:13:54,781 [root] DEBUG: 20980: DLL loaded at 0x748D0000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-30 16:13:54,788 [root] DEBUG: 20980: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-30 16:13:54,790 [root] DEBUG: 20980: DLL loaded at 0x748C0000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-30 16:13:54,802 [root] DEBUG: 20980: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-30 16:13:54,807 [root] DEBUG: 20980: DLL loaded at 0x74210000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-30 16:13:54,835 [root] DEBUG: 20980: DLL loaded at 0x74120000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-30 16:13:54,873 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\SyncEngine-2026-05-30.2013.10596.1.odl to files\5eae0ff9e33ad9f2d398c1e266160ab8354608ea8a5eb71ed627f1ea00ba7554; Size is 16192; Max size: 100000000
2026-05-30 16:13:55,134 [root] DEBUG: 20980: DLL loaded at 0x740A0000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-30 16:13:55,582 [root] DEBUG: 4484: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-30 16:13:55,696 [root] DEBUG: 20980: DLL loaded at 0x74200000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-30 16:13:55,699 [root] DEBUG: 20980: DLL loaded at 0x741A0000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:13:55,701 [root] DEBUG: 20980: DLL loaded at 0x74070000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:13:55,704 [root] DEBUG: 20980: DLL loaded at 0x74050000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-30 16:13:55,706 [root] DEBUG: 20980: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-30 16:13:55,995 [root] DEBUG: 20980: DLL loaded at 0x74040000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-05-30 16:13:56,054 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 21536, handle 0x10e4: C:\Windows\System32\rundll32.exe
2026-05-30 16:13:56,313 [root] DEBUG: 20980: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:13:56,314 [root] DEBUG: 20980: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:13:56,323 [root] DEBUG: 20980: DLL loaded at 0x74000000: C:\Windows\System32\netprofm (0x32000 bytes).
2026-05-30 16:13:56,332 [root] DEBUG: 20980: DLL loaded at 0x73FF0000: C:\Windows\System32\npmproxy (0xa000 bytes).
2026-05-30 16:13:56,375 [root] DEBUG: 20980: DLL loaded at 0x739C0000: C:\Windows\System32\OneCoreCommonProxyStub (0x3d000 bytes).
2026-05-30 16:13:57,667 [root] INFO: Added new file to list with pid 20980 and path C:\Program Files (x86)\Microsoft\EdgeUpdate\Download\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}\1.3.237.7\MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe
2026-05-30 16:13:57,750 [root] DEBUG: 20980: DLL loaded at 0x76420000: C:\Windows\System32\WINTRUST (0x4c000 bytes).
2026-05-30 16:13:57,765 [root] DEBUG: 20980: DLL loaded at 0x73990000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-05-30 16:13:57,774 [root] DEBUG: 20980: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:13:57,807 [root] DEBUG: 20980: DLL loaded at 0x73970000: C:\Windows\SYSTEM32\gpapi (0x1e000 bytes).
2026-05-30 16:13:57,846 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\{136AA3F3-5555-4E91-ABE1-4D912270F72F}-MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe to files\a99745cb5df5e6ec9dff5b6db54998e80ba7e691401872b1e2434e83f4f039c5; Size is 1684864; Max size: 100000000
2026-05-30 16:13:58,282 [root] DEBUG: 4484: DLL loaded at 0x00007FFF13720000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-30 16:13:58,283 [root] DEBUG: 4484: DLL loaded at 0x00007FFF13720000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-30 16:13:58,519 [root] DEBUG: 20980: CreateProcessHandler: Injection info set for new process 21872: C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{132FA329-097C-4B4D-AC56-20B4E40CBDB1}\MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe, ImageBase: 0x00460000
2026-05-30 16:13:58,521 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe pid: 21872
2026-05-30 16:13:58,521 [lib.api.process] INFO: Monitor config for process 21872: C:\lpw_albt\dll\21872.ini
2026-05-30 16:13:58,523 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,525 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:58,536 [root] DEBUG: Loader: Injecting process 21872 (thread 21876) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,537 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:58,538 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,541 [lib.api.process] INFO: Injected into 32-bit <Process 21872 MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe>
2026-05-30 16:13:58,549 [root] DEBUG: 20980: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-30 16:13:58,551 [root] DEBUG: 20980: WriteMemoryHandler: shellcode at 0x06C63AA8 (size 0x11c0) injected into process 21872 at 0x02750000.
2026-05-30 16:13:58,554 [lib.common.results] INFO: Uploading file C:\gbSlmMlCP\CAPE\20980_2259158132030652026 to CAPE\6c6e25209c1905ec87abe744f474fd4674ee76c4051720b23be7e7b49e73882b; Size is 4522; Max size: 100000000
2026-05-30 16:13:58,556 [root] DEBUG: 20980: DumpMemory: Payload successfully created: C:\gbSlmMlCP\CAPE\20980_2259158132030652026 (size 4522 bytes)
2026-05-30 16:13:58,557 [root] DEBUG: 20980: WriteMemoryHandler: Dumped injected code/data from buffer.
2026-05-30 16:13:58,559 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe pid: 21872
2026-05-30 16:13:58,560 [lib.api.process] INFO: Monitor config for process 21872: C:\lpw_albt\dll\21872.ini
2026-05-30 16:13:58,561 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,564 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:58,573 [root] DEBUG: Loader: Injecting process 21872 (thread 21876) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,574 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:58,574 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,579 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 21980: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-30 16:13:58,579 [lib.api.process] INFO: Injected into 32-bit <Process 21872 MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe>
2026-05-30 16:13:58,580 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21980
2026-05-30 16:13:58,581 [lib.api.process] INFO: Monitor config for process 21980: C:\lpw_albt\dll\21980.ini
2026-05-30 16:13:58,581 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe pid: 21872
2026-05-30 16:13:58,582 [lib.api.process] INFO: Monitor config for process 21872: C:\lpw_albt\dll\21872.ini
2026-05-30 16:13:58,583 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,583 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,586 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:58,591 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:58,607 [root] DEBUG: Loader: Injecting process 21872 (thread 21876) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,609 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:58,614 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,616 [root] DEBUG: Loader: Injecting process 21980 (thread 21984) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:58,617 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:58,618 [lib.api.process] INFO: Injected into 32-bit <Process 21872 MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe>
2026-05-30 16:13:58,620 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:58,622 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe pid: 21872
2026-05-30 16:13:58,626 [lib.api.process] INFO: Monitor config for process 21872: C:\lpw_albt\dll\21872.ini
2026-05-30 16:13:58,626 [lib.api.process] INFO: Injected into 64-bit <Process 21980 dllhost.exe>
2026-05-30 16:13:58,628 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,630 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21980
2026-05-30 16:13:58,630 [lib.api.process] INFO: Monitor config for process 21980: C:\lpw_albt\dll\21980.ini
2026-05-30 16:13:58,631 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,634 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:58,635 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:58,641 [root] DEBUG: 4484: api-cap: GetSystemTimeAsFileTime hook disabled due to count: 5000
2026-05-30 16:13:58,642 [root] DEBUG: Loader: Injecting process 21980 (thread 21984) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:58,644 [root] DEBUG: Loader: Injecting process 21872 (thread 21876) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,646 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:58,647 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:58,648 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:58,648 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,658 [lib.api.process] INFO: Injected into 32-bit <Process 21872 MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe>
2026-05-30 16:13:58,659 [lib.api.process] INFO: Injected into 64-bit <Process 21980 dllhost.exe>
2026-05-30 16:13:58,660 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe pid: 21872
2026-05-30 16:13:58,661 [lib.api.process] INFO: Monitor config for process 21872: C:\lpw_albt\dll\21872.ini
2026-05-30 16:13:58,662 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:58,665 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:58,680 [root] DEBUG: Loader: Injecting process 21872 with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,682 [root] DEBUG: 21980: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:58,683 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2026-05-30 16:13:58,684 [root] DEBUG: 21980: Interactive desktop enabled.
2026-05-30 16:13:58,687 [root] DEBUG: 21980: Dropped file limit defaulting to 100.
2026-05-30 16:13:58,692 [root] DEBUG: 21980: Disabling sleep skipping.
2026-05-30 16:13:58,700 [root] DEBUG: 21980: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:58,701 [root] DEBUG: 21872: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:58,707 [root] DEBUG: 21872: Interactive desktop enabled.
2026-05-30 16:13:58,710 [root] DEBUG: 21872: Dropped file limit defaulting to 100.
2026-05-30 16:13:58,715 [root] DEBUG: 21872: Disabling sleep skipping.
2026-05-30 16:13:58,716 [root] DEBUG: 21980: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:58,717 [root] DEBUG: 21872: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:58,718 [root] DEBUG: 21980: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-30 16:13:58,718 [root] DEBUG: 21872: YaraScan: Scanning 0x00460000, size 0x19d58a
2026-05-30 16:13:58,719 [root] DEBUG: 21980: Monitor initialised: 64-bit capemon loaded in process 21980 at 0x00007FFF15C80000, thread 21984, image base 0x00007FF6706B0000, stack from 0x0000002A0F3A4000-0x0000002A0F3B0000
2026-05-30 16:13:58,720 [root] DEBUG: 21980: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-30 16:13:58,730 [root] DEBUG: 21872: Monitor initialised: 32-bit capemon loaded in process 21872 at 0x75180000, thread 22184, image base 0x460000, stack from 0x28a4000-0x28b0000
2026-05-30 16:13:58,731 [root] DEBUG: 21872: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{132FA329-097C-4B4D-AC56-20B4E40CBDB1}\MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe" /update /sessionid "{B5226E54-B20D-4E1A-A6A6-49D22A97E2C5}"
2026-05-30 16:13:58,736 [root] DEBUG: 21980: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:58,763 [root] DEBUG: 21872: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:13:58,775 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:58,778 [root] DEBUG: 21980: set_hooks: Unable to hook LockResource
2026-05-30 16:13:58,781 [root] DEBUG: 21872: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:13:58,782 [root] DEBUG: 21872: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:13:58,785 [root] DEBUG: 21980: Hooked 627 out of 628 functions
2026-05-30 16:13:58,787 [root] DEBUG: 21980: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:58,787 [root] DEBUG: 21872: Hooked 632 out of 632 functions
2026-05-30 16:13:58,797 [root] DEBUG: 21872: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:58,800 [root] DEBUG: 21872: RestoreHeaders: Restored original import table.
2026-05-30 16:13:58,801 [root] INFO: Loaded monitor into process with pid 21872
2026-05-30 16:13:58,802 [root] DEBUG: 21980: RestoreHeaders: Restored original import table.
2026-05-30 16:13:58,809 [root] DEBUG: 21872: caller_dispatch: Added region at 0x02760000 to tracked regions list (ntdll::LdrLoadDll returns to 0x02760037, thread 22184).
2026-05-30 16:13:58,811 [root] DEBUG: 21872: DumpPEsInRange: Scanning range 0x02760000 - 0x02760129.
2026-05-30 16:13:58,812 [root] INFO: Loaded monitor into process with pid 21980
2026-05-30 16:13:58,813 [root] DEBUG: 21872: ScanForDisguisedPE: Size too small: 0x129 bytes
2026-05-30 16:13:58,813 [root] DEBUG: 21980: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6706B1349, thread 21984).
2026-05-30 16:13:58,814 [root] DEBUG: 21980: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-30 16:13:58,816 [root] DEBUG: 21980: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:58,816 [lib.common.results] INFO: Uploading file C:\gbSlmMlCP\CAPE\21872_381784858132030652026 to CAPE\659e424e65166441979b0bbfed2232648288f40c11aa6bb71c8b8e57f2acac61; Size is 297; Max size: 100000000
2026-05-30 16:13:58,818 [root] DEBUG: 21980: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:13:58,819 [root] DEBUG: 21872: DumpMemory: Payload successfully created: C:\gbSlmMlCP\CAPE\21872_381784858132030652026 (size 297 bytes)
2026-05-30 16:13:58,820 [root] DEBUG: 21980: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-30 16:13:58,821 [root] DEBUG: 21872: DumpRegion: Dumped entire allocation from 0x02760000, size 4096 bytes.
2026-05-30 16:13:58,824 [root] DEBUG: 21872: ProcessTrackedRegion: Dumped region at 0x02760000.
2026-05-30 16:13:58,825 [root] DEBUG: 21980: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:13:58,826 [root] DEBUG: 21872: YaraScan: Scanning 0x02760000, size 0x129
2026-05-30 16:13:58,827 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-30 16:13:58,829 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:58,831 [lib.api.process] INFO: Injected into 32-bit <Process 21872 MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe>
2026-05-30 16:13:58,840 [root] DEBUG: 21872: caller_dispatch: Added region at 0x00460000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0046960E, thread 21876).
2026-05-30 16:13:58,843 [root] DEBUG: 21872: YaraScan: Scanning 0x00460000, size 0x19d58a
2026-05-30 16:13:58,844 [lib.common.results] INFO: Uploading file C:\Program Files (x86)\Microsoft\EdgeUpdate\Download\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}\1.3.233.3\MicrosoftEdgeUpdateSetup_X86_1.3.233.3.exe to files\263b2ad561d37cb8561617ee32b604c5a60b0793be9eafcea738b03b539691a0; Size is 1698136; Max size: 100000000
2026-05-30 16:13:58,848 [root] DEBUG: 21980: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-30 16:13:58,857 [root] DEBUG: Error 87 (0x57) - OpenProcessHandler: Error obtaining target process name: The parameter is incorrect.
2026-05-30 16:13:58,857 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4, handle 0x930: Error obtaining target process name
2026-05-30 16:13:58,858 [root] DEBUG: 21872: ProcessImageBase: Main module image at 0x00460000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:58,861 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 124, handle 0x930:
2026-05-30 16:13:58,862 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 384, handle 0x930: C:\Windows\System32\smss.exe
2026-05-30 16:13:58,863 [root] DEBUG: 21872: DLL loaded at 0x75F00000: C:\Windows\System32\shcore (0x87000 bytes).
2026-05-30 16:13:58,864 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 480, handle 0x930: C:\Windows\System32\csrss.exe
2026-05-30 16:13:58,865 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 556, handle 0x930: C:\Windows\System32\wininit.exe
2026-05-30 16:13:58,866 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 576, handle 0x930: C:\Windows\System32\csrss.exe
2026-05-30 16:13:58,869 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 656, handle 0x930: C:\Windows\System32\winlogon.exe
2026-05-30 16:13:58,870 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 676, handle 0x930: C:\Windows\System32\services.exe
2026-05-30 16:13:58,871 [root] DEBUG: 21980: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:13:58,872 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 724, handle 0x930: C:\Windows\System32\lsass.exe
2026-05-30 16:13:58,873 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 832, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,876 [root] DEBUG: 21980: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-30 16:13:58,877 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 860, handle 0x930: C:\Windows\System32\fontdrvhost.exe
2026-05-30 16:13:58,877 [root] DEBUG: 21872: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:13:58,878 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 868, handle 0x930: C:\Windows\System32\fontdrvhost.exe
2026-05-30 16:13:58,880 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 948, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,880 [root] DEBUG: 21872: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-30 16:13:58,881 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1004, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,882 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 472, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,883 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 772, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,884 [root] DEBUG: 21980: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-30 16:13:58,885 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1048, handle 0x930: C:\Windows\System32\dwm.exe
2026-05-30 16:13:58,886 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1096, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,889 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1136, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,894 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1164, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,895 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1268, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,895 [root] DEBUG: 21872: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:13:58,899 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1284, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,904 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1292, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,905 [root] DEBUG: 21872: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:13:58,906 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1308, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,910 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1352, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,911 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1444, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,913 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1596, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,916 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1632, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,922 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1644, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,922 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1664, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,923 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1828, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,925 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1852, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,927 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1860, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,929 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1868, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,933 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1992, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,935 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2020, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,947 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2036, handle 0x930:
2026-05-30 16:13:58,952 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2124, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,953 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2224, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,955 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2240, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,958 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2296, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,959 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2344, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,959 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FC50000: C:\Windows\system32\IconCodecService (0x9000 bytes).
2026-05-30 16:13:58,960 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2456, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,963 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FC50000: C:\Windows\system32\IconCodecService (0x9000 bytes).
2026-05-30 16:13:58,966 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2472, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,966 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2520, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,967 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2696, handle 0x930: C:\Windows\System32\spoolsv.exe
2026-05-30 16:13:58,968 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2724, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,969 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2772, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,969 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2876, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,971 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2896, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,972 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3012, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,973 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3020, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,974 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3040, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,974 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3048, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,975 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3056, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,983 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2292, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,986 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2820, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,990 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3396, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:58,991 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 22160: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-30 16:13:58,993 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3892, handle 0x930: C:\Windows\System32\SearchIndexer.exe
2026-05-30 16:13:58,997 [root] INFO: Announced 64-bit process name: svchost.exe pid: 22160
2026-05-30 16:13:58,999 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3992, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,000 [lib.api.process] INFO: Monitor config for process 22160: C:\lpw_albt\dll\22160.ini
2026-05-30 16:13:59,000 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3500, handle 0x930: C:\Windows\System32\sihost.exe
2026-05-30 16:13:59,001 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3416, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,002 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:59,004 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4148, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,005 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4240, handle 0x930: C:\Windows\System32\taskhostw.exe
2026-05-30 16:13:59,005 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4300, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,006 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4380, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,007 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:59,008 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4484, handle 0x930: C:\Windows\explorer.exe
2026-05-30 16:13:59,008 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4524, handle 0x930: C:\Windows\System32\ctfmon.exe
2026-05-30 16:13:59,009 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4592, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,013 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4788, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,014 [lib.api.process] INFO: Injected into 64-bit <Process 22160 svchost.exe>
2026-05-30 16:13:59,015 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4916, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,016 [root] INFO: Announced 64-bit process name: svchost.exe pid: 22160
2026-05-30 16:13:59,016 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5200, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,016 [lib.api.process] INFO: Monitor config for process 22160: C:\lpw_albt\dll\22160.ini
2026-05-30 16:13:59,017 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5260, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,017 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:59,018 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5544, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,019 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5624, handle 0x930: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-30 16:13:59,020 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5688, handle 0x930: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:13:59,021 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5800, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,022 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5892, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,023 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6008, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,023 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:59,026 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6136, handle 0x930: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-30 16:13:59,028 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5948, handle 0x930: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:13:59,031 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6436, handle 0x930: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:13:59,032 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6616, handle 0x930: C:\Windows\System32\taskhostw.exe
2026-05-30 16:13:59,033 [root] DEBUG: Loader: Injecting process 22160 (thread 22148) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:59,034 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6996, handle 0x930: C:\Windows\System32\smartscreen.exe
2026-05-30 16:13:59,034 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:59,035 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7052, handle 0x930: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-30 16:13:59,035 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:59,037 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7088, handle 0x930: C:\Windows\System32\SecurityHealthService.exe
2026-05-30 16:13:59,038 [lib.api.process] INFO: Injected into 64-bit <Process 22160 svchost.exe>
2026-05-30 16:13:59,038 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6284, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,039 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3976, handle 0x930: C:\Windows\System32\conhost.exe
2026-05-30 16:13:59,042 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5128, handle 0x930: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:13:59,044 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6768, handle 0x930: C:\Program Files (x86)\Steam\steam.exe
2026-05-30 16:13:59,046 [root] INFO: Announced 64-bit process name: svchost.exe pid: 22160
2026-05-30 16:13:59,046 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6400, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,047 [lib.api.process] INFO: Monitor config for process 22160: C:\lpw_albt\dll\22160.ini
2026-05-30 16:13:59,048 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6356, handle 0x930: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-30 16:13:59,048 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:59,049 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6360, handle 0x930: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:13:59,050 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6392, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,051 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2160, handle 0x930: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:13:59,051 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6512, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,052 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6504, handle 0x930: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:13:59,054 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7444, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,054 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:13:59,054 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7544, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,055 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7844, handle 0x930: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:13:59,056 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8100, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,062 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8340, handle 0x930: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:13:59,064 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8108, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,065 [root] DEBUG: Loader: Injecting process 22160 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:59,066 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3820, handle 0x930: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:13:59,066 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 22148, handle 0x124
2026-05-30 16:13:59,067 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:13:59,068 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8044, handle 0x930: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-30 16:13:59,068 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:13:59,069 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1740, handle 0x930: C:\Windows\System32\dllhost.exe
2026-05-30 16:13:59,070 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1316, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,073 [lib.api.process] INFO: Injected into 64-bit <Process 22160 svchost.exe>
2026-05-30 16:13:59,073 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3404, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,074 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5364, handle 0x930: C:\Windows\System32\SgrmBroker.exe
2026-05-30 16:13:59,075 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6640, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,076 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2580, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,077 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6028, handle 0x930: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-30 16:13:59,082 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 6188, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,083 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7840, handle 0x930: C:\Windows\System32\taskhostw.exe
2026-05-30 16:13:59,084 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1084, handle 0x930: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
2026-05-30 16:13:59,091 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2168, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,092 [root] DEBUG: 22160: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:59,092 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 4556, handle 0x930: C:\Windows\System32\CompatTelRunner.exe
2026-05-30 16:13:59,095 [root] DEBUG: 22160: Interactive desktop enabled.
2026-05-30 16:13:59,096 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1464, handle 0x930: C:\Windows\System32\sppsvc.exe
2026-05-30 16:13:59,097 [root] DEBUG: 22160: Dropped file limit defaulting to 100.
2026-05-30 16:13:59,098 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8480, handle 0x930: C:\Windows\servicing\TrustedInstaller.exe
2026-05-30 16:13:59,099 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1572, handle 0x930: C:\Windows\System32\conhost.exe
2026-05-30 16:13:59,100 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1028, handle 0x930: C:\Windows\System32\backgroundTaskHost.exe
2026-05-30 16:13:59,100 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 9208, handle 0x930: C:\Windows\System32\backgroundTaskHost.exe
2026-05-30 16:13:59,101 [root] DEBUG: 22160: Disabling sleep skipping.
2026-05-30 16:13:59,105 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7528, handle 0x930: C:\Windows\System32\backgroundTaskHost.exe
2026-05-30 16:13:59,106 [root] DEBUG: 22160: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:59,106 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 1408, handle 0x930: C:\Windows\System32\notepad.exe
2026-05-30 16:13:59,107 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2676, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,108 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3256, handle 0x930: C:\Windows\System32\SppExtComObj.Exe
2026-05-30 16:13:59,114 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 3276, handle 0x930: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-30 16:13:59,115 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5244, handle 0x930: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:13:59,116 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8240, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,118 [root] DEBUG: 22160: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:13:59,119 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8332, handle 0x930: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:13:59,119 [root] DEBUG: 22160: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-30 16:13:59,120 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 2888, handle 0x930: C:\Windows\System32\CompatTelRunner.exe
2026-05-30 16:13:59,121 [root] DEBUG: 22160: Monitor initialised: 64-bit capemon loaded in process 22160 at 0x00007FFF15C80000, thread 22148, image base 0x00007FF7BF220000, stack from 0x0000009A3BB74000-0x0000009A3BB80000
2026-05-30 16:13:59,121 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 5928, handle 0x930: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:13:59,122 [root] DEBUG: 22160: Commandline: C:\Windows\system32\svchost.exe -k WbioSvcGroup -s WbioSrvc
2026-05-30 16:13:59,123 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7948, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,124 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 968, handle 0x930: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-30 16:13:59,126 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8528, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,127 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 7080, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,128 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 9716, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,129 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 9892, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,130 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 9920, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,131 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 9956, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,135 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 10116, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,137 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 10144, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,138 [root] DEBUG: 22160: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:13:59,139 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 10796, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,143 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 11116, handle 0x930: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-30 16:13:59,146 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 11216, handle 0x930: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:13:59,150 [root] INFO: Process with pid 5740 has terminated
2026-05-30 16:13:59,153 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 10596, handle 0x930: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-30 16:13:59,154 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 8936, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,159 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 13088, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,161 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 13496, handle 0x930: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\OneDrive.Sync.Service.exe
2026-05-30 16:13:59,162 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 14728, handle 0x930: C:\Windows\System32\CompatTelRunner.exe
2026-05-30 16:13:59,163 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:13:59,165 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 15272, handle 0x930: C:\Windows\System32\svchost.exe
2026-05-30 16:13:59,168 [root] DEBUG: 22160: set_hooks: Unable to hook LockResource
2026-05-30 16:13:59,169 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 14860, handle 0x930: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-30 16:13:59,170 [root] DEBUG: 20980: OpenProcessHandler: Injection info created for process 21980, handle 0x930: C:\Windows\System32\dllhost.exe
2026-05-30 16:13:59,178 [root] DEBUG: 22160: Hooked 627 out of 628 functions
2026-05-30 16:13:59,178 [root] DEBUG: 20980: CreateProcessHandler: Injection info set for new process 23104: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-30 16:13:59,179 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 23104
2026-05-30 16:13:59,180 [root] DEBUG: 22160: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:59,180 [lib.api.process] INFO: Monitor config for process 23104: C:\lpw_albt\dll\23104.ini
2026-05-30 16:13:59,186 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:13:59,186 [root] DEBUG: 22160: RestoreHeaders: Restored original import table.
2026-05-30 16:13:59,187 [root] INFO: Loaded monitor into process with pid 22160
2026-05-30 16:13:59,190 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:13:59,191 [root] DEBUG: 22160: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 22148).
2026-05-30 16:13:59,192 [root] DEBUG: 22160: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-30 16:13:59,193 [root] DEBUG: 22160: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:59,205 [root] DEBUG: Loader: Injecting process 23104 (thread 23108) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:59,207 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:13:59,209 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:13:59,211 [lib.api.process] INFO: Injected into 32-bit <Process 23104 MicrosoftEdgeUpdate.exe>
2026-05-30 16:13:59,222 [root] DEBUG: 23104: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:13:59,223 [root] DEBUG: 23104: Interactive desktop enabled.
2026-05-30 16:13:59,225 [root] DEBUG: 23104: Dropped file limit defaulting to 100.
2026-05-30 16:13:59,229 [root] DEBUG: 23104: Disabling sleep skipping.
2026-05-30 16:13:59,231 [root] DEBUG: 23104: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:13:59,232 [root] DEBUG: 23104: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:13:59,234 [root] DEBUG: 23104: Monitor initialised: 32-bit capemon loaded in process 23104 at 0x75180000, thread 23108, image base 0x150000, stack from 0x2dc5000-0x2dd0000
2026-05-30 16:13:59,234 [root] DEBUG: 23104: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4yMzMuMyIgc2hlbGxfdmVyc2lvbj0iMS4zLjIzMy4zIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0I1MjI2RTU0LUIyMEQtNEUxQS1BNkE2LTQ5RDIyQTk3RTJDNX0iIHVzZXJpZD0ie0Y5MjVFQ0UxLTFDRjQtNDQzQS04N0ZCLTRGNzU4MUJFMDhFMn0iIGluc3RhbGxzb3VyY2U9InNjaGVkdWxlciIgcmVxdWVzdGlkPSJ7NDUzNTE0MjAtQTA3RC00QzY0LUJFRjYtMkVCMDIxM
2026-05-30 16:13:59,263 [root] DEBUG: 23104: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:13:59,268 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-30 16:13:59,280 [root] DEBUG: 23104: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:13:59,281 [root] DEBUG: 23104: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:13:59,286 [root] DEBUG: 23104: Hooked 632 out of 632 functions
2026-05-30 16:13:59,287 [root] DEBUG: 23104: Syscall hook installed, syscall logging level 1
2026-05-30 16:13:59,292 [root] DEBUG: 23104: RestoreHeaders: Restored original import table.
2026-05-30 16:13:59,292 [root] INFO: Loaded monitor into process with pid 23104
2026-05-30 16:13:59,293 [root] DEBUG: 23104: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 23108).
2026-05-30 16:13:59,294 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57010000: c:\windows\system32\ncrypt (0x27000 bytes).
2026-05-30 16:13:59,295 [root] DEBUG: 23104: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:13:59,295 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-30 16:13:59,296 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57470000: c:\windows\system32\UMPDC (0x12000 bytes).
2026-05-30 16:13:59,296 [root] DEBUG: 23104: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:13:59,297 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-30 16:13:59,297 [root] DEBUG: 22160: DLL loaded at 0x00007FFF13640000: c:\windows\system32\wbiosrvc (0xde000 bytes).
2026-05-30 16:13:59,298 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdate.exe
2026-05-30 16:13:59,301 [root] DEBUG: 23104: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:13:59,302 [root] DEBUG: 23104: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:13:59,304 [root] DEBUG: 23104: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-30 16:13:59,308 [root] DEBUG: 23104: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-30 16:13:59,309 [root] DEBUG: 23104: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-30 16:13:59,310 [root] DEBUG: 23104: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-30 16:13:59,310 [root] DEBUG: 23104: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-30 16:13:59,312 [root] DEBUG: 23104: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-30 16:13:59,313 [root] DEBUG: 23104: DLL loaded at 0x6AEB0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-30 16:13:59,319 [root] DEBUG: 23104: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:13:59,320 [root] DEBUG: 23104: DLL loaded at 0x73910000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:13:59,326 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\CopilotUpdate.exe
2026-05-30 16:13:59,327 [root] DEBUG: 23104: DLL loaded at 0x73890000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:13:59,328 [root] DEBUG: 22160: DLL loaded at 0x00007FFF56FD0000: c:\windows\system32\NTASN1 (0x3b000 bytes).
2026-05-30 16:13:59,328 [root] DEBUG: 23104: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-30 16:13:59,329 [root] DEBUG: 23104: DLL loaded at 0x74070000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:13:59,330 [root] DEBUG: 23104: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:13:59,330 [root] DEBUG: 23104: DLL loaded at 0x73800000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:13:59,331 [root] DEBUG: 23104: DLL loaded at 0x73820000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:13:59,332 [root] DEBUG: 23104: DLL loaded at 0x738E0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:13:59,333 [root] DEBUG: 23104: DLL loaded at 0x73FE0000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:13:59,335 [root] DEBUG: 23104: DLL loaded at 0x741A0000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:13:59,339 [root] DEBUG: 23104: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:13:59,340 [root] DEBUG: 23104: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-30 16:13:59,341 [root] DEBUG: 23104: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-30 16:13:59,346 [root] DEBUG: 23104: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-30 16:13:59,359 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-30 16:13:59,372 [root] DEBUG: 23104: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:13:59,373 [root] DEBUG: 23104: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-30 16:13:59,377 [root] DEBUG: 23104: DLL loaded at 0x6AE60000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-30 16:13:59,397 [root] DEBUG: 22160: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-30 16:13:59,403 [root] DEBUG: 23104: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\Iphlpapi (0x32000 bytes).
2026-05-30 16:13:59,404 [root] DEBUG: 23104: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-30 16:13:59,405 [root] DEBUG: 23104: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-30 16:13:59,407 [root] DEBUG: 23104: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:13:59,408 [root] DEBUG: 23104: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:13:59,460 [root] DEBUG: 23104: DLL loaded at 0x73FE0000: C:\Windows\SYSTEM32\diagnosticdataquery (0xc000 bytes).
2026-05-30 16:13:59,463 [root] DEBUG: 23104: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-30 16:13:59,466 [root] DEBUG: 23104: DLL loaded at 0x73A00000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-30 16:13:59,476 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdate.dll
2026-05-30 16:13:59,482 [root] DEBUG: 23104: DLL loaded at 0x74000000: C:\Windows\System32\netprofm (0x32000 bytes).
2026-05-30 16:13:59,488 [root] DEBUG: 23104: DLL loaded at 0x73FF0000: C:\Windows\System32\npmproxy (0xa000 bytes).
2026-05-30 16:13:59,509 [root] DEBUG: 23104: DLL loaded at 0x73960000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0xe000 bytes).
2026-05-30 16:13:59,512 [root] DEBUG: 23104: caller_dispatch: Added region at 0x73960000 to tracked regions list (ntdll::NtQueryInformationToken returns to 0x739671A7, thread 23108).
2026-05-30 16:13:59,513 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdateBroker.exe
2026-05-30 16:13:59,514 [root] DEBUG: 23104: ProcessTrackedRegion: Region at 0x73960000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient.dll is in known range, skipping
2026-05-30 16:13:59,518 [root] DEBUG: 22160: DLL loaded at 0x00007FFF47940000: C:\Windows\SYSTEM32\winbio (0x31000 bytes).
2026-05-30 16:13:59,519 [root] DEBUG: 22160: DLL loaded at 0x00007FFF3E240000: C:\Windows\SYSTEM32\winbioext (0xf000 bytes).
2026-05-30 16:13:59,531 [root] DEBUG: 23104: DLL loaded at 0x74220000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-30 16:13:59,533 [root] DEBUG: 23104: DLL loaded at 0x73940000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-30 16:13:59,538 [root] DEBUG: 23104: DLL loaded at 0x75490000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-30 16:13:59,539 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdateOnDemand.exe
2026-05-30 16:13:59,547 [root] DEBUG: 22160: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-30 16:13:59,548 [root] DEBUG: 22160: DLL loaded at 0x00007FFF4FA10000: c:\windows\system32\tbs (0x1b000 bytes).
2026-05-30 16:13:59,558 [root] DEBUG: 23104: DLL loaded at 0x748D0000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-30 16:13:59,559 [root] DEBUG: 23104: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-30 16:13:59,561 [root] DEBUG: 23104: DLL loaded at 0x748C0000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-30 16:13:59,564 [root] DEBUG: 23104: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-30 16:13:59,566 [root] DEBUG: 23104: DLL loaded at 0x74210000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-30 16:13:59,568 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe
2026-05-30 16:13:59,577 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-30 16:13:59,579 [root] DEBUG: 22160: DLL loaded at 0x00007FFF572F0000: c:\windows\system32\DEVOBJ (0x33000 bytes).
2026-05-30 16:13:59,585 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-30 16:13:59,594 [root] DEBUG: 23104: DLL loaded at 0x74120000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-30 16:13:59,615 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeComRegisterShellARM64.exe
2026-05-30 16:13:59,619 [root] DEBUG: 23104: DLL loaded at 0x740A0000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-30 16:13:59,674 [root] DEBUG: 23104: DLL loaded at 0x74200000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-30 16:13:59,675 [root] DEBUG: 23104: DLL loaded at 0x741A0000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:13:59,677 [root] DEBUG: 23104: DLL loaded at 0x74070000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:13:59,679 [root] DEBUG: 23104: DLL loaded at 0x74050000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-30 16:13:59,680 [root] DEBUG: 23104: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-30 16:13:59,682 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psmachine.dll
2026-05-30 16:13:59,687 [root] DEBUG: 22160: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-30 16:13:59,688 [root] DEBUG: 22160: DLL loaded at 0x00007FFF169F0000: C:\Windows\system32\DEVRTL (0x14000 bytes).
2026-05-30 16:13:59,689 [root] DEBUG: 22160: DLL loaded at 0x00007FFEE50D0000: C:\Windows\system32\NEWDEV (0x53000 bytes).
2026-05-30 16:13:59,690 [root] DEBUG: 22160: DLL loaded at 0x00007FFF13590000: C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\FACEBOOTSTRAPADAPTER (0xa2000 bytes).
2026-05-30 16:13:59,710 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psmachine_64.dll
2026-05-30 16:13:59,736 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psmachine_arm64.dll
2026-05-30 16:13:59,739 [root] DEBUG: 22160: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:13:59,765 [root] DEBUG: 22160: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:13:59,768 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psuser.dll
2026-05-30 16:13:59,770 [root] DEBUG: 22160: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:13:59,771 [root] DEBUG: 22160: DLL loaded at 0x00007FFF48630000: C:\Windows\System32\Windows.Devices.Enumeration (0x87000 bytes).
2026-05-30 16:13:59,798 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psuser_64.dll
2026-05-30 16:13:59,801 [root] DEBUG: 22160: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-30 16:13:59,828 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psuser_arm64.dll
2026-05-30 16:13:59,830 [root] DEBUG: 22160: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-30 16:13:59,836 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\NOTICE.TXT
2026-05-30 16:13:59,839 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\EdgeUpdate.dat
2026-05-30 16:13:59,852 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdateCore.exe
2026-05-30 16:13:59,880 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_am.dll
2026-05-30 16:13:59,904 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ar.dll
2026-05-30 16:13:59,916 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bg.dll
2026-05-30 16:13:59,921 [root] DEBUG: 22160: DLL loaded at 0x00007FFF48420000: C:\Windows\System32\MSWB7 (0x46000 bytes).
2026-05-30 16:13:59,924 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bn.dll
2026-05-30 16:13:59,943 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ca.dll
2026-05-30 16:13:59,956 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_cs.dll
2026-05-30 16:13:59,968 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_da.dll
2026-05-30 16:13:59,983 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_de.dll
2026-05-30 16:14:00,002 [root] DEBUG: 23104: DLL loaded at 0x74040000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-05-30 16:14:00,003 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_el.dll
2026-05-30 16:14:00,009 [root] INFO: Added new file to list with pid 23104 and path C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log
2026-05-30 16:14:00,011 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_en.dll
2026-05-30 16:14:00,014 [root] DEBUG: 23104: NtTerminateProcess hook: Attempting to dump process 23104
2026-05-30 16:14:00,018 [root] DEBUG: 23104: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:00,028 [root] INFO: Process with pid 23104 has terminated
2026-05-30 16:14:00,044 [root] DEBUG: 20980: NtTerminateProcess hook: Attempting to dump process 20980
2026-05-30 16:14:00,046 [root] DEBUG: 20980: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:00,053 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_en-GB.dll
2026-05-30 16:14:00,053 [root] DEBUG: 22160: DLL loaded at 0x00007FFF48210000: C:\Windows\System32\DevDispItemProvider (0x20000 bytes).
2026-05-30 16:14:00,054 [root] INFO: Process with pid 20980 has terminated
2026-05-30 16:14:00,065 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_es.dll
2026-05-30 16:14:00,069 [root] DEBUG: 22160: DLL loaded at 0x00007FFF1EF30000: C:\Windows\System32\Windows.Media (0x726000 bytes).
2026-05-30 16:14:00,073 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_es-419.dll
2026-05-30 16:14:00,089 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_et.dll
2026-05-30 16:14:00,104 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fa.dll
2026-05-30 16:14:00,114 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fi.dll
2026-05-30 16:14:00,127 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fil.dll
2026-05-30 16:14:00,128 [root] DEBUG: 22160: DLL loaded at 0x00007FFF3BA10000: C:\Windows\system32\MFPlat (0x1bb000 bytes).
2026-05-30 16:14:00,129 [root] DEBUG: 22160: DLL loaded at 0x00007FFF134F0000: C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\NUIVOICEWBSADAPTERS (0x93000 bytes).
2026-05-30 16:14:00,142 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fr.dll
2026-05-30 16:14:00,144 [root] DEBUG: 22160: DLL loaded at 0x00007FFF3B9D0000: C:\Windows\system32\RTWorkQ (0x34000 bytes).
2026-05-30 16:14:00,151 [root] DEBUG: 22160: DLL loaded at 0x0000027113FE0000: C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\WINBIOSTORAGEADAPTER (0x1f000 bytes).
2026-05-30 16:14:00,156 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_gu.dll
2026-05-30 16:14:00,165 [root] DEBUG: 22160: DLL loaded at 0x00007FFF57350000: C:\Windows\system32\DPAPI (0xa000 bytes).
2026-05-30 16:14:00,169 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_hi.dll
2026-05-30 16:14:00,182 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_hr.dll
2026-05-30 16:14:00,196 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_hu.dll
2026-05-30 16:14:00,213 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_id.dll
2026-05-30 16:14:00,238 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_is.dll
2026-05-30 16:14:00,252 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_it.dll
2026-05-30 16:14:00,259 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_iw.dll
2026-05-30 16:14:00,267 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ja.dll
2026-05-30 16:14:00,280 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_kn.dll
2026-05-30 16:14:00,307 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ko.dll
2026-05-30 16:14:00,319 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lt.dll
2026-05-30 16:14:00,328 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lv.dll
2026-05-30 16:14:00,360 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ml.dll
2026-05-30 16:14:00,370 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mr.dll
2026-05-30 16:14:00,380 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ms.dll
2026-05-30 16:14:00,387 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_nb.dll
2026-05-30 16:14:00,402 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_nl.dll
2026-05-30 16:14:00,423 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pl.dll
2026-05-30 16:14:00,433 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pt-BR.dll
2026-05-30 16:14:00,440 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pt-PT.dll
2026-05-30 16:14:00,446 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ro.dll
2026-05-30 16:14:00,452 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ru.dll
2026-05-30 16:14:00,460 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sk.dll
2026-05-30 16:14:00,493 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sl.dll
2026-05-30 16:14:00,503 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sr.dll
2026-05-30 16:14:00,515 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sv.dll
2026-05-30 16:14:00,530 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ta.dll
2026-05-30 16:14:00,543 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_te.dll
2026-05-30 16:14:00,561 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_th.dll
2026-05-30 16:14:00,601 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_tr.dll
2026-05-30 16:14:00,672 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_uk.dll
2026-05-30 16:14:00,703 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ur.dll
2026-05-30 16:14:00,723 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_vi.dll
2026-05-30 16:14:00,733 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_zh-CN.dll
2026-05-30 16:14:00,752 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_zh-TW.dll
2026-05-30 16:14:00,768 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_af.dll
2026-05-30 16:14:00,788 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_as.dll
2026-05-30 16:14:00,799 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_az.dll
2026-05-30 16:14:00,816 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bn-IN.dll
2026-05-30 16:14:00,830 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bs.dll
2026-05-30 16:14:00,846 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ca-Es-VALENCIA.dll
2026-05-30 16:14:00,869 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_cy.dll
2026-05-30 16:14:00,882 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_eu.dll
2026-05-30 16:14:00,894 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fr-CA.dll
2026-05-30 16:14:00,908 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ga.dll
2026-05-30 16:14:00,914 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_gd.dll
2026-05-30 16:14:00,927 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_gl.dll
2026-05-30 16:14:00,941 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ka.dll
2026-05-30 16:14:00,961 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_kk.dll
2026-05-30 16:14:00,990 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_km.dll
2026-05-30 16:14:01,012 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_kok.dll
2026-05-30 16:14:01,026 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lb.dll
2026-05-30 16:14:01,040 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lo.dll
2026-05-30 16:14:01,054 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mi.dll
2026-05-30 16:14:01,072 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mk.dll
2026-05-30 16:14:01,087 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mt.dll
2026-05-30 16:14:01,105 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ne.dll
2026-05-30 16:14:01,125 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_nn.dll
2026-05-30 16:14:01,140 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_or.dll
2026-05-30 16:14:01,156 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pa.dll
2026-05-30 16:14:01,168 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_quz.dll
2026-05-30 16:14:01,185 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sq.dll
2026-05-30 16:14:01,214 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sr-Cyrl-BA.dll
2026-05-30 16:14:01,223 [root] INFO: Added new file to list with pid 21872 and path C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sr-Cyrl-RS.dll
2026-05-30 16:14:01,241 [root] DEBUG: 21872: Dropped file limit reached.
2026-05-30 16:14:01,265 [root] DEBUG: 21872: DLL loaded at 0x74A00000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-05-30 16:14:01,271 [root] DEBUG: 21872: CreateProcessHandler: Injection info set for new process 24116: C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdate.exe, ImageBase: 0x00870000
2026-05-30 16:14:01,272 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 24116
2026-05-30 16:14:01,273 [lib.api.process] INFO: Monitor config for process 24116: C:\lpw_albt\dll\24116.ini
2026-05-30 16:14:01,277 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:02,221 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:14:02,227 [root] DEBUG: Loader: Injecting process 24116 (thread 24120) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:02,227 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:02,228 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:02,230 [lib.api.process] INFO: Injected into 32-bit <Process 24116 MicrosoftEdgeUpdate.exe>
2026-05-30 16:14:02,240 [root] DEBUG: 21872: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-30 16:14:02,250 [root] DEBUG: 24116: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:02,252 [root] DEBUG: 24116: Interactive desktop enabled.
2026-05-30 16:14:02,253 [root] DEBUG: 24116: Dropped file limit defaulting to 100.
2026-05-30 16:14:02,255 [root] DEBUG: 24116: Disabling sleep skipping.
2026-05-30 16:14:02,257 [root] DEBUG: 24116: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:02,258 [root] DEBUG: 24116: YaraScan: Scanning 0x00870000, size 0x34228
2026-05-30 16:14:02,262 [root] DEBUG: 24116: Monitor initialised: 32-bit capemon loaded in process 24116 at 0x75180000, thread 24120, image base 0x870000, stack from 0x3354000-0x3360000
2026-05-30 16:14:02,264 [root] DEBUG: 24116: Commandline: "C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdate.exe" /update /sessionid "{B5226E54-B20D-4E1A-A6A6-49D22A97E2C5}"
2026-05-30 16:14:02,297 [root] DEBUG: 24116: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:14:02,320 [root] DEBUG: 24116: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:14:02,321 [root] DEBUG: 24116: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:14:02,327 [root] DEBUG: 24116: Hooked 632 out of 632 functions
2026-05-30 16:14:02,329 [root] DEBUG: 24116: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:02,333 [root] DEBUG: 24116: RestoreHeaders: Restored original import table.
2026-05-30 16:14:02,334 [root] INFO: Loaded monitor into process with pid 24116
2026-05-30 16:14:02,336 [root] DEBUG: 24116: caller_dispatch: Added region at 0x00870000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0087D9CE, thread 24120).
2026-05-30 16:14:02,337 [root] DEBUG: 24116: YaraScan: Scanning 0x00870000, size 0x34228
2026-05-30 16:14:02,339 [root] DEBUG: 24116: ProcessImageBase: Main module image at 0x00870000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:02,343 [root] DEBUG: 24116: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:14:02,344 [root] DEBUG: 24116: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:14:02,346 [root] DEBUG: 24116: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-30 16:14:02,355 [root] DEBUG: 24116: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-30 16:14:02,356 [root] DEBUG: 24116: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-30 16:14:02,357 [root] DEBUG: 24116: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-30 16:14:02,358 [root] DEBUG: 24116: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-30 16:14:02,359 [root] DEBUG: 24116: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-30 16:14:02,361 [root] DEBUG: 24116: DLL loaded at 0x73D50000: C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdate (0x241000 bytes).
2026-05-30 16:14:02,367 [root] DEBUG: 24116: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:02,368 [root] DEBUG: 24116: DLL loaded at 0x755E0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:02,377 [root] DEBUG: 24116: DLL loaded at 0x75560000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:02,379 [root] DEBUG: 24116: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-30 16:14:02,381 [root] DEBUG: 24116: DLL loaded at 0x754C0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:02,382 [root] DEBUG: 24116: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:02,384 [root] DEBUG: 24116: DLL loaded at 0x754A0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:02,385 [root] DEBUG: 24116: DLL loaded at 0x754F0000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:02,386 [root] DEBUG: 24116: DLL loaded at 0x755B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:02,388 [root] DEBUG: 24116: DLL loaded at 0x75490000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:02,390 [root] DEBUG: 24116: DLL loaded at 0x75150000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:02,396 [root] DEBUG: 24116: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:02,397 [root] DEBUG: 24116: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-30 16:14:02,399 [root] DEBUG: 24116: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-30 16:14:02,406 [root] DEBUG: 24116: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-30 16:14:02,454 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 24500: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:14:02,455 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 24500
2026-05-30 16:14:02,456 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 24500
2026-05-30 16:14:03,736 [root] DEBUG: 24116: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:14:03,738 [root] DEBUG: 24116: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-30 16:14:03,778 [root] DEBUG: 24116: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-30 16:14:03,782 [root] DEBUG: 24116: DLL loaded at 0x74250000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-30 16:14:03,908 [root] DEBUG: 24116: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2026-05-30 16:14:03,909 [root] DEBUG: 24116: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-30 16:14:03,918 [root] INFO: Process with pid 21980 has terminated
2026-05-30 16:14:03,919 [root] DEBUG: 21980: NtTerminateProcess hook: Attempting to dump process 21980
2026-05-30 16:14:03,920 [root] DEBUG: 21980: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:03,953 [root] INFO: Process with pid 1084 has terminated
2026-05-30 16:14:03,955 [root] DEBUG: Error 87 (0x57) - OpenProcessHandler: Error obtaining target process name: The parameter is incorrect.
2026-05-30 16:14:03,957 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4, handle 0x370: Error obtaining target process name
2026-05-30 16:14:03,962 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 124, handle 0x364:
2026-05-30 16:14:03,964 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 384, handle 0x364: C:\Windows\System32\smss.exe
2026-05-30 16:14:03,966 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 480, handle 0x364: C:\Windows\System32\csrss.exe
2026-05-30 16:14:03,968 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 556, handle 0x34c: C:\Windows\System32\wininit.exe
2026-05-30 16:14:03,971 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 576, handle 0x34c: C:\Windows\System32\csrss.exe
2026-05-30 16:14:03,973 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 656, handle 0x348: C:\Windows\System32\winlogon.exe
2026-05-30 16:14:03,974 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 676, handle 0x348: C:\Windows\System32\services.exe
2026-05-30 16:14:03,976 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 724, handle 0x348: C:\Windows\System32\lsass.exe
2026-05-30 16:14:03,978 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 832, handle 0x348: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,980 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 860, handle 0x348: C:\Windows\System32\fontdrvhost.exe
2026-05-30 16:14:03,982 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 868, handle 0x348: C:\Windows\System32\fontdrvhost.exe
2026-05-30 16:14:03,983 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 948, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,985 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1004, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,986 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 472, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,988 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 772, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,989 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1048, handle 0x38c: C:\Windows\System32\dwm.exe
2026-05-30 16:14:03,993 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1096, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,995 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1136, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,997 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1164, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:03,999 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1268, handle 0x380: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,000 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1284, handle 0x380: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,001 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1292, handle 0x358: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,003 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1308, handle 0x358: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,005 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1352, handle 0x358: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,006 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1444, handle 0x358: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,007 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1596, handle 0x358: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,010 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1632, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,012 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1644, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,013 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1664, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,015 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1828, handle 0x37c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,016 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1852, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,018 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1860, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,020 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1868, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,023 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1992, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,026 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2020, handle 0x380: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,029 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2036, handle 0x380:
2026-05-30 16:14:04,031 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2124, handle 0x380: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,033 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2224, handle 0x380: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,035 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2240, handle 0x380: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,036 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2296, handle 0x398: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,038 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2344, handle 0x398: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,042 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2456, handle 0x398: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,044 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2472, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,046 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2520, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,048 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2696, handle 0x388: C:\Windows\System32\spoolsv.exe
2026-05-30 16:14:04,049 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2724, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,051 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2772, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,054 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2876, handle 0x390: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,058 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2896, handle 0x34c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,059 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3012, handle 0x34c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,060 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3020, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,062 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3040, handle 0x3a4: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,064 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3048, handle 0x398: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,065 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3056, handle 0x398: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,066 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2292, handle 0x394: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,069 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2820, handle 0x394: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,073 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3396, handle 0x394: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,075 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3892, handle 0x37c: C:\Windows\System32\SearchIndexer.exe
2026-05-30 16:14:04,076 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3992, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,077 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3500, handle 0x35c: C:\Windows\System32\sihost.exe
2026-05-30 16:14:04,078 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3416, handle 0x35c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,079 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4148, handle 0x37c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,081 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4240, handle 0x370: C:\Windows\System32\taskhostw.exe
2026-05-30 16:14:04,082 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4300, handle 0x3a0: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,084 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4380, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,085 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4484, handle 0x3a0: C:\Windows\explorer.exe
2026-05-30 16:14:04,089 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4524, handle 0x39c: C:\Windows\System32\ctfmon.exe
2026-05-30 16:14:04,091 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4592, handle 0x368: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,092 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4788, handle 0x38c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,094 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4916, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,097 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5200, handle 0x390: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,100 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5260, handle 0x368: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,104 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5544, handle 0x368: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,106 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5624, handle 0x39c: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-30 16:14:04,108 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5688, handle 0x39c: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:14:04,109 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5800, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,111 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5892, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,112 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6008, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,115 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6136, handle 0x39c: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-30 16:14:04,116 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5948, handle 0x384: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:14:04,119 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6436, handle 0x368: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:14:04,121 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6616, handle 0x3a0: C:\Windows\System32\taskhostw.exe
2026-05-30 16:14:04,122 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6996, handle 0x3a0: C:\Windows\System32\smartscreen.exe
2026-05-30 16:14:04,124 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7052, handle 0x3a0: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-30 16:14:04,126 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7088, handle 0x384: C:\Windows\System32\SecurityHealthService.exe
2026-05-30 16:14:04,128 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6284, handle 0x384: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,130 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3976, handle 0x370: C:\Windows\System32\conhost.exe
2026-05-30 16:14:04,132 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5128, handle 0x388: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:14:04,134 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6768, handle 0x3a4: C:\Program Files (x86)\Steam\steam.exe
2026-05-30 16:14:04,136 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6400, handle 0x368: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,137 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6356, handle 0x368: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-30 16:14:04,139 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6360, handle 0x378: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:14:04,140 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6392, handle 0x378: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,142 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2160, handle 0x3ac: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:14:04,144 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6512, handle 0x3ac: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,145 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6504, handle 0x3a0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:14:04,146 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7444, handle 0x378: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,148 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7544, handle 0x3ac: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,152 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7844, handle 0x3a0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:14:04,153 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8100, handle 0x378: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,154 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8340, handle 0x388: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-30 16:14:04,156 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8108, handle 0x388: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,158 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3820, handle 0x354: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-30 16:14:04,161 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8044, handle 0x384: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-30 16:14:04,163 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1740, handle 0x378: C:\Windows\System32\dllhost.exe
2026-05-30 16:14:04,166 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1316, handle 0x378: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,180 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 24588: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:14:04,184 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 24588
2026-05-30 16:14:04,186 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 24588
2026-05-30 16:14:04,190 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3404, handle 0x348: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,192 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5364, handle 0x384: C:\Windows\System32\SgrmBroker.exe
2026-05-30 16:14:04,194 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6640, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,198 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2580, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,199 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6028, handle 0x39c: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-30 16:14:04,201 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 6188, handle 0x348: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,204 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7840, handle 0x39c: C:\Windows\System32\taskhostw.exe
2026-05-30 16:14:04,206 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2168, handle 0x39c: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,208 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 4556, handle 0x348: C:\Windows\System32\CompatTelRunner.exe
2026-05-30 16:14:04,210 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1464, handle 0x3b8: C:\Windows\System32\sppsvc.exe
2026-05-30 16:14:04,214 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8480, handle 0x3b8: C:\Windows\servicing\TrustedInstaller.exe
2026-05-30 16:14:04,217 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1572, handle 0x3b0: C:\Windows\System32\conhost.exe
2026-05-30 16:14:04,219 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1028, handle 0x384: C:\Windows\System32\backgroundTaskHost.exe
2026-05-30 16:14:04,220 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 1408, handle 0x3cc: C:\Windows\System32\notepad.exe
2026-05-30 16:14:04,223 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2676, handle 0x3cc: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,232 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3256, handle 0x3dc: C:\Windows\System32\SppExtComObj.Exe
2026-05-30 16:14:04,237 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 3276, handle 0x3dc: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-30 16:14:04,244 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5244, handle 0x3cc: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:14:04,248 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8240, handle 0x3cc: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,251 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8332, handle 0x3e8: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:14:04,253 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 2888, handle 0x3e8: C:\Windows\System32\CompatTelRunner.exe
2026-05-30 16:14:04,255 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 5928, handle 0x3e4: C:\Windows\System32\RuntimeBroker.exe
2026-05-30 16:14:04,257 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7948, handle 0x3f8: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,261 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 968, handle 0x3f8: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-30 16:14:04,263 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8528, handle 0x384: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,265 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 7080, handle 0x3e4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,267 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 9716, handle 0x3e4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,270 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 9892, handle 0x3c0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,271 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 9920, handle 0x3c0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,273 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 9956, handle 0x384: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,275 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 10116, handle 0x3b0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,278 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 10796, handle 0x3b8: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,279 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 11116, handle 0x3b8: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-30 16:14:04,281 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 11216, handle 0x3b8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,282 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 10596, handle 0x348: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-30 16:14:04,284 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 8936, handle 0x348: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,286 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 13088, handle 0x348: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,287 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 13496, handle 0x3c8: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\OneDrive.Sync.Service.exe
2026-05-30 16:14:04,288 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 15272, handle 0x3ec: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,293 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 14860, handle 0x3ec: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-30 16:14:04,294 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 21872, handle 0x3e4: C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{132FA329-097C-4B4D-AC56-20B4E40CBDB1}\MicrosoftEdgeUpdateSetup_X86_1.3.237.7.exe
2026-05-30 16:14:04,296 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 22160, handle 0x3e4: C:\Windows\System32\svchost.exe
2026-05-30 16:14:04,297 [root] DEBUG: 24116: OpenProcessHandler: Injection info created for process 24500, handle 0x3f4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-30 16:14:04,347 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdate.exe
2026-05-30 16:14:04,350 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\CopilotUpdate.exe
2026-05-30 16:14:04,359 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdate.dll
2026-05-30 16:14:04,362 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdateCore.exe
2026-05-30 16:14:04,365 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe
2026-05-30 16:14:04,382 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\MicrosoftEdgeComRegisterShellARM64.exe
2026-05-30 16:14:04,386 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\NOTICE.TXT
2026-05-30 16:14:04,388 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\EdgeUpdate.dat
2026-05-30 16:14:04,391 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_af.dll
2026-05-30 16:14:04,393 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_am.dll
2026-05-30 16:14:04,400 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ar.dll
2026-05-30 16:14:04,404 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_as.dll
2026-05-30 16:14:04,407 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_az.dll
2026-05-30 16:14:04,408 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bg.dll
2026-05-30 16:14:04,410 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bn.dll
2026-05-30 16:14:04,415 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bn-IN.dll
2026-05-30 16:14:04,418 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_bs.dll
2026-05-30 16:14:04,441 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ca.dll
2026-05-30 16:14:04,443 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ca-Es-VALENCIA.dll
2026-05-30 16:14:04,451 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_cs.dll
2026-05-30 16:14:04,454 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_cy.dll
2026-05-30 16:14:04,458 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_da.dll
2026-05-30 16:14:04,461 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_de.dll
2026-05-30 16:14:04,466 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_el.dll
2026-05-30 16:14:04,468 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_en.dll
2026-05-30 16:14:04,472 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_en-GB.dll
2026-05-30 16:14:04,475 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_es.dll
2026-05-30 16:14:04,481 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_es-419.dll
2026-05-30 16:14:04,484 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_et.dll
2026-05-30 16:14:04,489 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_eu.dll
2026-05-30 16:14:04,512 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fa.dll
2026-05-30 16:14:04,515 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fi.dll
2026-05-30 16:14:04,520 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fil.dll
2026-05-30 16:14:04,522 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fr.dll
2026-05-30 16:14:04,528 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_fr-CA.dll
2026-05-30 16:14:04,532 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ga.dll
2026-05-30 16:14:04,536 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_gd.dll
2026-05-30 16:14:04,550 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_gl.dll
2026-05-30 16:14:04,553 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_gu.dll
2026-05-30 16:14:04,574 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_hi.dll
2026-05-30 16:14:04,577 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_hr.dll
2026-05-30 16:14:04,582 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_hu.dll
2026-05-30 16:14:04,585 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_id.dll
2026-05-30 16:14:04,590 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_is.dll
2026-05-30 16:14:04,593 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_it.dll
2026-05-30 16:14:04,596 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_iw.dll
2026-05-30 16:14:04,607 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ja.dll
2026-05-30 16:14:04,611 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ka.dll
2026-05-30 16:14:04,614 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_kk.dll
2026-05-30 16:14:04,616 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_km.dll
2026-05-30 16:14:04,620 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_kn.dll
2026-05-30 16:14:04,623 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ko.dll
2026-05-30 16:14:04,625 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_kok.dll
2026-05-30 16:14:04,627 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lb.dll
2026-05-30 16:14:04,630 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lo.dll
2026-05-30 16:14:04,632 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lt.dll
2026-05-30 16:14:04,636 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_lv.dll
2026-05-30 16:14:04,639 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mi.dll
2026-05-30 16:14:04,650 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mk.dll
2026-05-30 16:14:04,653 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ml.dll
2026-05-30 16:14:04,673 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mr.dll
2026-05-30 16:14:04,678 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ms.dll
2026-05-30 16:14:04,681 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_mt.dll
2026-05-30 16:14:04,683 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_nb.dll
2026-05-30 16:14:04,685 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ne.dll
2026-05-30 16:14:04,691 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_nl.dll
2026-05-30 16:14:04,693 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_nn.dll
2026-05-30 16:14:04,705 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_or.dll
2026-05-30 16:14:04,706 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pa.dll
2026-05-30 16:14:04,708 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pl.dll
2026-05-30 16:14:04,711 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pt-BR.dll
2026-05-30 16:14:04,713 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_pt-PT.dll
2026-05-30 16:14:04,719 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_quz.dll
2026-05-30 16:14:04,721 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ro.dll
2026-05-30 16:14:04,723 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ru.dll
2026-05-30 16:14:04,743 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sk.dll
2026-05-30 16:14:04,746 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sl.dll
2026-05-30 16:14:04,752 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sq.dll
2026-05-30 16:14:04,774 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sr.dll
2026-05-30 16:14:04,777 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sr-Cyrl-BA.dll
2026-05-30 16:14:04,779 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sr-Cyrl-RS.dll
2026-05-30 16:14:04,783 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_sv.dll
2026-05-30 16:14:04,786 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ta.dll
2026-05-30 16:14:04,788 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_te.dll
2026-05-30 16:14:04,791 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_th.dll
2026-05-30 16:14:04,796 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_tr.dll
2026-05-30 16:14:04,813 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_uk.dll
2026-05-30 16:14:04,831 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_ur.dll
2026-05-30 16:14:04,833 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_vi.dll
2026-05-30 16:14:04,836 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_zh-CN.dll
2026-05-30 16:14:04,838 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\msedgeupdateres_zh-TW.dll
2026-05-30 16:14:04,839 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psuser.dll
2026-05-30 16:14:04,841 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psuser_64.dll
2026-05-30 16:14:04,843 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psuser_arm64.dll
2026-05-30 16:14:04,845 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psmachine.dll
2026-05-30 16:14:04,854 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psmachine_64.dll
2026-05-30 16:14:04,857 [root] INFO: Added pid 24116 for C:\Program Files (x86)\Microsoft\Temp\EU87A0.tmp\psmachine_arm64.dll
2026-05-30 16:14:04,903 [root] DEBUG: 24116: DLL loaded at 0x74A00000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-05-30 16:14:04,908 [root] DEBUG: 24116: CreateProcessHandler: Injection info set for new process 25304: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-30 16:14:04,909 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 25304
2026-05-30 16:14:04,909 [lib.api.process] INFO: Monitor config for process 25304: C:\lpw_albt\dll\25304.ini
2026-05-30 16:14:04,911 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:04,915 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:14:04,922 [root] DEBUG: Loader: Injecting process 25304 (thread 25308) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:04,923 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:04,924 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:04,926 [lib.api.process] INFO: Injected into 32-bit <Process 25304 MicrosoftEdgeUpdate.exe>
2026-05-30 16:14:04,929 [root] DEBUG: 24116: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-30 16:14:04,943 [root] DEBUG: 25304: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:04,945 [root] DEBUG: 25304: Interactive desktop enabled.
2026-05-30 16:14:04,946 [root] DEBUG: 25304: Dropped file limit defaulting to 100.
2026-05-30 16:14:04,951 [root] DEBUG: 25304: Disabling sleep skipping.
2026-05-30 16:14:04,953 [root] DEBUG: 25304: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:04,954 [root] DEBUG: 25304: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:14:04,956 [root] DEBUG: 25304: Monitor initialised: 32-bit capemon loaded in process 25304 at 0x75180000, thread 25308, image base 0x150000, stack from 0x2af5000-0x2b00000
2026-05-30 16:14:04,956 [root] DEBUG: 25304: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc
2026-05-30 16:14:05,004 [root] DEBUG: 25304: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:14:05,027 [root] DEBUG: 25304: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:14:05,028 [root] DEBUG: 25304: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:14:05,034 [root] DEBUG: 25304: Hooked 632 out of 632 functions
2026-05-30 16:14:05,036 [root] DEBUG: 25304: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:05,042 [root] DEBUG: 25304: RestoreHeaders: Restored original import table.
2026-05-30 16:14:05,046 [root] INFO: Loaded monitor into process with pid 25304
2026-05-30 16:14:05,048 [root] DEBUG: 25304: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 25308).
2026-05-30 16:14:05,049 [root] DEBUG: 25304: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:14:05,051 [root] DEBUG: 25304: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:05,060 [root] DEBUG: 25304: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:14:05,061 [root] DEBUG: 25304: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:14:05,062 [root] DEBUG: 25304: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-30 16:14:05,067 [root] DEBUG: 25304: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-30 16:14:05,069 [root] DEBUG: 25304: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-30 16:14:05,071 [root] DEBUG: 25304: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-30 16:14:05,072 [root] DEBUG: 25304: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-30 16:14:05,073 [root] DEBUG: 25304: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-30 16:14:05,076 [root] DEBUG: 25304: DLL loaded at 0x73D50000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\msedgeupdate (0x241000 bytes).
2026-05-30 16:14:05,087 [root] DEBUG: 25304: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:05,089 [root] DEBUG: 25304: DLL loaded at 0x755E0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:05,099 [root] DEBUG: 25304: DLL loaded at 0x75560000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:05,102 [root] DEBUG: 25304: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-30 16:14:05,104 [root] DEBUG: 25304: DLL loaded at 0x754C0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:05,107 [root] DEBUG: 25304: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:05,109 [root] DEBUG: 25304: DLL loaded at 0x754A0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:05,109 [root] DEBUG: 25304: DLL loaded at 0x754F0000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:05,111 [root] DEBUG: 25304: DLL loaded at 0x755B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:05,114 [root] DEBUG: 25304: DLL loaded at 0x75490000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:05,118 [root] DEBUG: 25304: DLL loaded at 0x75150000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:05,124 [root] DEBUG: 25304: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:05,125 [root] DEBUG: 25304: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-30 16:14:05,127 [root] DEBUG: 25304: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-30 16:14:05,138 [root] DEBUG: 25304: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-30 16:14:05,300 [root] DEBUG: 25304: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:14:05,301 [root] DEBUG: 25304: NtTerminateProcess hook: Attempting to dump process 25304
2026-05-30 16:14:05,303 [root] DEBUG: 25304: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:05,309 [root] INFO: Process with pid 25304 has terminated
2026-05-30 16:14:05,370 [root] DEBUG: 24116: DLL loaded at 0x755C0000: C:\Windows\System32\taskschd (0x7d000 bytes).
2026-05-30 16:14:05,451 [root] DEBUG: 24116: CreateProcessHandler: Injection info set for new process 25340: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-30 16:14:05,453 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 25340
2026-05-30 16:14:05,454 [lib.api.process] INFO: Monitor config for process 25340: C:\lpw_albt\dll\25340.ini
2026-05-30 16:14:05,456 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:05,463 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:14:05,471 [root] DEBUG: Loader: Injecting process 25340 (thread 25336) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:05,472 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:05,473 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:05,475 [lib.api.process] INFO: Injected into 32-bit <Process 25340 MicrosoftEdgeUpdate.exe>
2026-05-30 16:14:05,491 [root] DEBUG: 25340: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:05,493 [root] DEBUG: 25340: Interactive desktop enabled.
2026-05-30 16:14:05,494 [root] DEBUG: 25340: Dropped file limit defaulting to 100.
2026-05-30 16:14:05,498 [root] DEBUG: 25340: Disabling sleep skipping.
2026-05-30 16:14:05,500 [root] DEBUG: 25340: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:05,501 [root] DEBUG: 25340: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:14:05,503 [root] DEBUG: 25340: Monitor initialised: 32-bit capemon loaded in process 25340 at 0x75180000, thread 25336, image base 0x150000, stack from 0x29c4000-0x29d0000
2026-05-30 16:14:05,504 [root] DEBUG: 25340: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver
2026-05-30 16:14:05,547 [root] DEBUG: 25340: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:14:05,575 [root] DEBUG: 25340: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:14:05,577 [root] DEBUG: 25340: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:14:05,585 [root] DEBUG: 25340: Hooked 632 out of 632 functions
2026-05-30 16:14:05,590 [root] DEBUG: 25340: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:05,595 [root] DEBUG: 25340: RestoreHeaders: Restored original import table.
2026-05-30 16:14:05,596 [root] INFO: Loaded monitor into process with pid 25340
2026-05-30 16:14:05,598 [root] DEBUG: 25340: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 25336).
2026-05-30 16:14:05,599 [root] DEBUG: 25340: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:14:05,604 [root] DEBUG: 25340: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:05,611 [root] DEBUG: 25340: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:14:05,614 [root] DEBUG: 25340: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:14:05,615 [root] DEBUG: 25340: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-30 16:14:05,621 [root] DEBUG: 25340: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-30 16:14:05,622 [root] DEBUG: 25340: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-30 16:14:05,623 [root] DEBUG: 25340: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-30 16:14:05,625 [root] DEBUG: 25340: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-30 16:14:05,628 [root] DEBUG: 25340: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-30 16:14:05,629 [root] DEBUG: 25340: DLL loaded at 0x73D50000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\msedgeupdate (0x241000 bytes).
2026-05-30 16:14:05,641 [root] DEBUG: 25340: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:05,642 [root] DEBUG: 25340: DLL loaded at 0x75560000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:05,657 [root] DEBUG: 25340: DLL loaded at 0x754E0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:05,661 [root] DEBUG: 25340: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-30 16:14:05,663 [root] DEBUG: 25340: DLL loaded at 0x75150000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:05,666 [root] DEBUG: 25340: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:05,671 [root] DEBUG: 25340: DLL loaded at 0x75130000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:05,672 [root] DEBUG: 25340: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:05,675 [root] DEBUG: 25340: DLL loaded at 0x75530000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:05,690 [root] DEBUG: 25340: DLL loaded at 0x75120000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:05,697 [root] DEBUG: 25340: DLL loaded at 0x750F0000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:05,709 [root] DEBUG: 25340: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:05,714 [root] DEBUG: 25340: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-30 16:14:05,716 [root] DEBUG: 25340: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-30 16:14:05,725 [root] DEBUG: 25340: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-30 16:14:06,173 [root] DEBUG: 4484: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-30 16:14:06,465 [root] DEBUG: 25340: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:14:06,468 [root] DEBUG: 25340: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-30 16:14:06,471 [root] DEBUG: 25340: CreateProcessHandler: Injection info set for new process 25920: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\MicrosoftEdgeUpdateComRegisterShell64.exe, ImageBase: 0x00000000
2026-05-30 16:14:06,473 [root] INFO: Announced 64-bit process name: MicrosoftEdgeUpdateComRegisterShell64.exe pid: 25920
2026-05-30 16:14:06,474 [lib.api.process] INFO: Monitor config for process 25920: C:\lpw_albt\dll\25920.ini
2026-05-30 16:14:06,476 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:07,022 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-30 16:14:07,024 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-30 16:14:07,083 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE131000, size: 0x1000.
2026-05-30 16:14:07,102 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE121000, size: 0x1000.
2026-05-30 16:14:07,106 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE101000, size: 0x1000.
2026-05-30 16:14:07,119 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE0F1000, size: 0x1000.
2026-05-30 16:14:07,159 [root] DEBUG: 4484: DLL loaded at 0x00007FFF42BF0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-30 16:14:07,161 [root] DEBUG: 4484: DLL loaded at 0x00007FFF42BF0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-30 16:14:07,200 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 26164: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF7C7E10000
2026-05-30 16:14:07,202 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 26164
2026-05-30 16:14:07,203 [lib.api.process] INFO: Monitor config for process 26164: C:\lpw_albt\dll\26164.ini
2026-05-30 16:14:07,206 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:07,214 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:07,218 [root] DEBUG: Loader: Injecting process 26164 (thread 26168) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,221 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:07,223 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,225 [lib.api.process] INFO: Injected into 64-bit <Process 26164 CHXSmartScreen.exe>
2026-05-30 16:14:07,231 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 26164
2026-05-30 16:14:07,233 [lib.api.process] INFO: Monitor config for process 26164: C:\lpw_albt\dll\26164.ini
2026-05-30 16:14:07,246 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:07,253 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:07,259 [root] DEBUG: Loader: Injecting process 26164 (thread 26168) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,262 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:07,263 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,265 [lib.api.process] INFO: Injected into 64-bit <Process 26164 CHXSmartScreen.exe>
2026-05-30 16:14:07,271 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 26164
2026-05-30 16:14:07,272 [lib.api.process] INFO: Monitor config for process 26164: C:\lpw_albt\dll\26164.ini
2026-05-30 16:14:07,273 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:07,280 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:07,290 [root] DEBUG: Loader: Injecting process 26164 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,291 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 26168, handle 0x120
2026-05-30 16:14:07,292 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:14:07,293 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,295 [lib.api.process] INFO: Injected into 64-bit <Process 26164 CHXSmartScreen.exe>
2026-05-30 16:14:07,555 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:07,563 [root] DEBUG: Loader: Injecting process 25920 (thread 25924) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,564 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:07,567 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:07,569 [lib.api.process] INFO: Injected into 64-bit <Process 25920 MicrosoftEdgeUpdateComRegisterShell64.exe>
2026-05-30 16:14:07,578 [root] DEBUG: 25340: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-30 16:14:07,685 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 26436, handle 0x174c: C:\Windows\System32\rundll32.exe
2026-05-30 16:14:07,887 [root] DEBUG: 25920: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:07,888 [root] DEBUG: 25920: Interactive desktop enabled.
2026-05-30 16:14:07,890 [root] DEBUG: 25920: Dropped file limit defaulting to 100.
2026-05-30 16:14:07,893 [root] DEBUG: 25920: Disabling sleep skipping.
2026-05-30 16:14:07,895 [root] DEBUG: 25920: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:07,909 [root] DEBUG: 25920: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:14:07,910 [root] DEBUG: 25920: YaraScan: Scanning 0x00007FF782B90000, size 0x3ca3e
2026-05-30 16:14:07,912 [root] DEBUG: 25920: Monitor initialised: 64-bit capemon loaded in process 25920 at 0x00007FFF15C80000, thread 25924, image base 0x00007FF782B90000, stack from 0x0000006D9FB24000-0x0000006D9FB30000
2026-05-30 16:14:07,913 [root] DEBUG: 25920: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\MicrosoftEdgeUpdateComRegisterShell64.exe"
2026-05-30 16:14:07,931 [root] DEBUG: 25920: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:14:07,959 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:14:07,960 [root] DEBUG: 25920: set_hooks: Unable to hook LockResource
2026-05-30 16:14:07,966 [root] DEBUG: 25920: Hooked 627 out of 628 functions
2026-05-30 16:14:07,970 [root] DEBUG: 25920: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:07,975 [root] DEBUG: 25920: RestoreHeaders: Restored original import table.
2026-05-30 16:14:07,976 [root] INFO: Loaded monitor into process with pid 25920
2026-05-30 16:14:07,978 [root] DEBUG: 25920: caller_dispatch: Added region at 0x00007FF782B90000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00007FF782B9AA7B, thread 25924).
2026-05-30 16:14:07,979 [root] DEBUG: 25920: YaraScan: Scanning 0x00007FF782B90000, size 0x3ca3e
2026-05-30 16:14:07,982 [root] DEBUG: 25920: ProcessImageBase: Main module image at 0x00007FF782B90000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:07,991 [root] DEBUG: 25920: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:14:08,478 [root] DEBUG: 25920: DLL loaded at 0x0000016F0F420000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\psmachine_64 (0x6c000 bytes).
2026-05-30 16:14:08,484 [root] DEBUG: 25920: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-30 16:14:08,485 [root] DEBUG: 25920: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-30 16:14:08,490 [root] DEBUG: 25920: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-30 16:14:08,556 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE0F0000.
2026-05-30 16:14:08,572 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:08,576 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE100000.
2026-05-30 16:14:08,578 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:08,583 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-30 16:14:08,584 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:08,585 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-30 16:14:08,586 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:08,623 [root] DEBUG: 25920: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-30 16:14:08,704 [root] DEBUG: 25920: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-30 16:14:08,710 [root] DEBUG: 25920: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:14:08,746 [root] DEBUG: 25920: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-30 16:14:08,748 [root] DEBUG: 25920: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-30 16:14:08,938 [root] DEBUG: 25920: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-30 16:14:09,086 [root] DEBUG: 25920: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:14:09,088 [root] DEBUG: 25920: NtTerminateProcess hook: Attempting to dump process 25920
2026-05-30 16:14:09,090 [root] DEBUG: 25920: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:09,134 [root] INFO: Process with pid 25920 has terminated
2026-05-30 16:14:09,144 [root] DEBUG: 25340: DLL loaded at 0x75560000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\psmachine (0x58000 bytes).
2026-05-30 16:14:09,151 [root] DEBUG: 25340: DLL loaded at 0x75500000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:09,159 [root] DEBUG: 25340: DLL loaded at 0x75480000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:09,160 [root] DEBUG: 25340: DLL loaded at 0x750E0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:09,162 [root] DEBUG: 25340: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:09,165 [root] DEBUG: 25340: DLL loaded at 0x750C0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:09,166 [root] DEBUG: 25340: DLL loaded at 0x75110000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:09,167 [root] DEBUG: 25340: DLL loaded at 0x754D0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:09,169 [root] DEBUG: 25340: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:09,172 [root] DEBUG: 25340: DLL loaded at 0x74920000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:09,177 [root] DEBUG: 25340: caller_dispatch: Added region at 0x75110000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x7514510A, thread 25336).
2026-05-30 16:14:09,178 [root] DEBUG: 25340: caller_dispatch: Scanning calling region at 0x75110000...
2026-05-30 16:14:09,179 [root] DEBUG: 25340: ProcessTrackedRegion: Region at 0x75110000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\dmcmnutils.dll is in known range, skipping
2026-05-30 16:14:09,182 [root] DEBUG: 25340: caller_dispatch: Added region at 0x754D0000 to tracked regions list (ntdll::NtCreateMutant returns to 0x754DA2F5, thread 25336).
2026-05-30 16:14:09,184 [root] DEBUG: 25340: ProcessTrackedRegion: Region at 0x754D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\omadmapi.dll is in known range, skipping
2026-05-30 16:14:09,264 [root] DEBUG: 25340: CreateProcessHandler: Injection info set for new process 26800: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\MicrosoftEdgeUpdateComRegisterShell64.exe, ImageBase: 0x00000000
2026-05-30 16:14:09,267 [root] INFO: Announced 64-bit process name: MicrosoftEdgeUpdateComRegisterShell64.exe pid: 26800
2026-05-30 16:14:09,269 [lib.api.process] INFO: Monitor config for process 26800: C:\lpw_albt\dll\26800.ini
2026-05-30 16:14:09,269 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:10,111 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-30 16:14:10,113 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5948, handle 0x2700: Error obtaining target process name
2026-05-30 16:14:10,189 [root] DEBUG: 4484: api-cap: NtQueryValueKey hook disabled due to count: 5001
2026-05-30 16:14:10,190 [root] DEBUG: 4484: api-cap: NtQueryValueKey hook disabled due to count: 5001
2026-05-30 16:14:10,191 [root] DEBUG: 4484: api-cap: NtQueryValueKey hook disabled due to count: 5002
2026-05-30 16:14:10,481 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:10,486 [root] DEBUG: Loader: Injecting process 26800 (thread 26804) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:10,487 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:10,487 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:10,489 [lib.api.process] INFO: Injected into 64-bit <Process 26800 MicrosoftEdgeUpdateComRegisterShell64.exe>
2026-05-30 16:14:10,497 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 27004: C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileCoAuth.exe, ImageBase: 0x00007FF61DD70000
2026-05-30 16:14:10,499 [root] INFO: Announced 64-bit process name: FileCoAuth.exe pid: 27004
2026-05-30 16:14:10,500 [lib.api.process] INFO: Monitor config for process 27004: C:\lpw_albt\dll\27004.ini
2026-05-30 16:14:10,502 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:10,511 [root] DEBUG: 26800: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:10,512 [root] DEBUG: 26800: Interactive desktop enabled.
2026-05-30 16:14:10,514 [root] DEBUG: 26800: Dropped file limit defaulting to 100.
2026-05-30 16:14:10,516 [root] DEBUG: 26800: Disabling sleep skipping.
2026-05-30 16:14:10,518 [root] DEBUG: 26800: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:10,537 [root] DEBUG: 26800: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:14:10,538 [root] DEBUG: 26800: YaraScan: Scanning 0x00007FF782B90000, size 0x3ca3e
2026-05-30 16:14:10,543 [root] DEBUG: 26800: Monitor initialised: 64-bit capemon loaded in process 26800 at 0x00007FFF15C80000, thread 26804, image base 0x00007FF782B90000, stack from 0x000000BCB0EF4000-0x000000BCB0F00000
2026-05-30 16:14:10,543 [root] DEBUG: 26800: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\MicrosoftEdgeUpdateComRegisterShell64.exe"
2026-05-30 16:14:10,566 [root] DEBUG: 26800: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:14:10,598 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:14:10,599 [root] DEBUG: 26800: set_hooks: Unable to hook LockResource
2026-05-30 16:14:10,609 [root] DEBUG: 26800: Hooked 627 out of 628 functions
2026-05-30 16:14:10,613 [root] DEBUG: 26800: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:10,627 [root] DEBUG: 26800: RestoreHeaders: Restored original import table.
2026-05-30 16:14:10,628 [root] INFO: Loaded monitor into process with pid 26800
2026-05-30 16:14:10,630 [root] DEBUG: 26800: caller_dispatch: Added region at 0x00007FF782B90000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00007FF782B9AA7B, thread 26804).
2026-05-30 16:14:10,632 [root] DEBUG: 26800: YaraScan: Scanning 0x00007FF782B90000, size 0x3ca3e
2026-05-30 16:14:10,637 [root] DEBUG: 26800: ProcessImageBase: Main module image at 0x00007FF782B90000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:10,655 [root] DEBUG: 26800: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:14:10,659 [root] DEBUG: 26800: DLL loaded at 0x00000264F9C80000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\psmachine_64 (0x6c000 bytes).
2026-05-30 16:14:10,665 [root] DEBUG: 26800: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-30 16:14:10,667 [root] DEBUG: 26800: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-30 16:14:10,673 [root] DEBUG: 26800: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-30 16:14:10,675 [root] DEBUG: 26800: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-30 16:14:10,680 [root] DEBUG: 26800: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-30 16:14:10,687 [root] DEBUG: 26800: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:14:10,695 [root] DEBUG: 26800: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-30 16:14:10,697 [root] DEBUG: 26800: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-30 16:14:10,711 [root] DEBUG: 26800: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-30 16:14:10,805 [root] DEBUG: 26800: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:14:10,807 [root] DEBUG: 26800: NtTerminateProcess hook: Attempting to dump process 26800
2026-05-30 16:14:10,809 [root] DEBUG: 26800: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:10,824 [root] INFO: Process with pid 26800 has terminated
2026-05-30 16:14:10,829 [root] DEBUG: 25340: DLL loaded at 0x75560000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\psmachine (0x58000 bytes).
2026-05-30 16:14:10,834 [root] DEBUG: 25340: DLL loaded at 0x75500000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:10,845 [root] DEBUG: 25340: DLL loaded at 0x75480000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:10,846 [root] DEBUG: 25340: DLL loaded at 0x750E0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:10,847 [root] DEBUG: 25340: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:10,849 [root] DEBUG: 25340: DLL loaded at 0x750C0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:10,850 [root] DEBUG: 25340: DLL loaded at 0x75110000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:10,851 [root] DEBUG: 25340: DLL loaded at 0x754D0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:10,855 [root] DEBUG: 25340: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:10,858 [root] DEBUG: 25340: DLL loaded at 0x74920000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:10,952 [root] DEBUG: 25340: CreateProcessHandler: Injection info set for new process 27244: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\MicrosoftEdgeUpdateComRegisterShell64.exe, ImageBase: 0x00000000
2026-05-30 16:14:10,954 [root] INFO: Announced 64-bit process name: MicrosoftEdgeUpdateComRegisterShell64.exe pid: 27244
2026-05-30 16:14:10,955 [lib.api.process] INFO: Monitor config for process 27244: C:\lpw_albt\dll\27244.ini
2026-05-30 16:14:10,958 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:11,923 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:14:11,923 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_atomic_wait.dll
2026-05-30 16:14:11,924 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:14:11,924 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:14:11,925 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_1.dll
2026-05-30 16:14:11,925 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:14:11,926 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-30 16:14:12,026 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:12,031 [root] DEBUG: Loader: Injecting process 27004 (thread 27008) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,032 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:12,033 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,036 [lib.api.process] INFO: Injected into 64-bit <Process 27004 FileCoAuth.exe>
2026-05-30 16:14:12,039 [root] INFO: Announced 64-bit process name: FileCoAuth.exe pid: 27004
2026-05-30 16:14:12,041 [lib.api.process] INFO: Monitor config for process 27004: C:\lpw_albt\dll\27004.ini
2026-05-30 16:14:12,042 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:12,281 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-30 16:14:12,283 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-30 16:14:12,290 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 27380: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF743EB0000
2026-05-30 16:14:12,292 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 27380
2026-05-30 16:14:12,293 [lib.api.process] INFO: Monitor config for process 27380: C:\lpw_albt\dll\27380.ini
2026-05-30 16:14:12,295 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:12,303 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:12,308 [root] DEBUG: Loader: Injecting process 27380 (thread 27384) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,310 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:12,311 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,312 [lib.api.process] INFO: Injected into 64-bit <Process 27380 SecurityHealthHost.exe>
2026-05-30 16:14:12,317 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 27380
2026-05-30 16:14:12,318 [lib.api.process] INFO: Monitor config for process 27380: C:\lpw_albt\dll\27380.ini
2026-05-30 16:14:12,319 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:12,324 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:12,329 [root] DEBUG: Loader: Injecting process 27380 (thread 27384) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,331 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:14:12,332 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,334 [lib.api.process] INFO: Injected into 64-bit <Process 27380 SecurityHealthHost.exe>
2026-05-30 16:14:12,343 [root] DEBUG: 27380: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:12,345 [root] DEBUG: 27380: Interactive desktop enabled.
2026-05-30 16:14:12,346 [root] DEBUG: 27380: Dropped file limit defaulting to 100.
2026-05-30 16:14:12,349 [root] DEBUG: 27380: Disabling sleep skipping.
2026-05-30 16:14:12,351 [root] DEBUG: 27380: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:12,363 [root] DEBUG: 27380: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:14:12,365 [root] DEBUG: 27380: YaraScan: Scanning 0x00007FF743EB0000, size 0x19174
2026-05-30 16:14:12,368 [root] DEBUG: 27380: Monitor initialised: 64-bit capemon loaded in process 27380 at 0x00007FFF15C80000, thread 27384, image base 0x00007FF743EB0000, stack from 0x000000DEFA874000-0x000000DEFA880000
2026-05-30 16:14:12,369 [root] DEBUG: 27380: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-30 16:14:12,386 [root] DEBUG: 27380: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:14:12,408 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:14:12,410 [root] DEBUG: 27380: set_hooks: Unable to hook LockResource
2026-05-30 16:14:12,415 [root] DEBUG: 27380: Hooked 627 out of 628 functions
2026-05-30 16:14:12,417 [root] DEBUG: 27380: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:12,422 [root] DEBUG: 27380: RestoreHeaders: Restored original import table.
2026-05-30 16:14:12,424 [root] INFO: Loaded monitor into process with pid 27380
2026-05-30 16:14:12,426 [root] DEBUG: 27380: caller_dispatch: Added region at 0x00007FF743EB0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF743EBD3B2, thread 27384).
2026-05-30 16:14:12,428 [root] DEBUG: 27380: YaraScan: Scanning 0x00007FF743EB0000, size 0x19174
2026-05-30 16:14:12,430 [root] DEBUG: 27380: ProcessImageBase: Main module image at 0x00007FF743EB0000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:12,433 [root] DEBUG: 27380: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:14:12,434 [root] DEBUG: 27380: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-30 16:14:12,437 [root] DEBUG: 27380: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-30 16:14:12,463 [root] DEBUG: 27380: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-30 16:14:12,465 [root] DEBUG: 27380: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-30 16:14:12,467 [root] DEBUG: 27380: DLL loaded at 0x0000025F6D590000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-30 16:14:12,543 [root] DEBUG: 27380: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-30 16:14:12,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:12,576 [root] DEBUG: 27380: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-30 16:14:12,577 [root] DEBUG: Loader: Injecting process 27244 (thread 27248) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,579 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:12,581 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:12,582 [lib.api.process] INFO: Injected into 64-bit <Process 27244 MicrosoftEdgeUpdateComRegisterShell64.exe>
2026-05-30 16:14:12,590 [root] DEBUG: 27244: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:12,592 [root] DEBUG: 27244: Interactive desktop enabled.
2026-05-30 16:14:12,594 [root] DEBUG: 27244: Dropped file limit defaulting to 100.
2026-05-30 16:14:12,598 [root] DEBUG: 27244: Disabling sleep skipping.
2026-05-30 16:14:12,600 [root] DEBUG: 27244: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:12,613 [root] DEBUG: 27244: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:14:12,613 [root] DEBUG: 27244: YaraScan: Scanning 0x00007FF782B90000, size 0x3ca3e
2026-05-30 16:14:12,616 [root] DEBUG: 27244: Monitor initialised: 64-bit capemon loaded in process 27244 at 0x00007FFF15C80000, thread 27248, image base 0x00007FF782B90000, stack from 0x000000C8BE2F4000-0x000000C8BE300000
2026-05-30 16:14:12,617 [root] DEBUG: 27244: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\MicrosoftEdgeUpdateComRegisterShell64.exe"
2026-05-30 16:14:12,632 [root] DEBUG: 27244: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:14:12,659 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:14:12,661 [root] DEBUG: 27244: set_hooks: Unable to hook LockResource
2026-05-30 16:14:12,667 [root] DEBUG: 27244: Hooked 627 out of 628 functions
2026-05-30 16:14:12,670 [root] DEBUG: 27244: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:12,676 [root] DEBUG: 27244: RestoreHeaders: Restored original import table.
2026-05-30 16:14:12,677 [root] INFO: Loaded monitor into process with pid 27244
2026-05-30 16:14:12,678 [root] DEBUG: 27244: caller_dispatch: Added region at 0x00007FF782B90000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00007FF782B9AA7B, thread 27248).
2026-05-30 16:14:12,679 [root] DEBUG: 27244: YaraScan: Scanning 0x00007FF782B90000, size 0x3ca3e
2026-05-30 16:14:12,682 [root] DEBUG: 27244: ProcessImageBase: Main module image at 0x00007FF782B90000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:12,690 [root] DEBUG: 27244: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:14:12,693 [root] DEBUG: 27244: DLL loaded at 0x00007FFF18120000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\psmachine_64 (0x6c000 bytes).
2026-05-30 16:14:12,695 [root] DEBUG: 27244: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-30 16:14:12,697 [root] DEBUG: 27244: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-30 16:14:12,701 [root] DEBUG: 27244: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-30 16:14:12,703 [root] DEBUG: 27244: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-30 16:14:12,711 [root] DEBUG: 27244: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-30 16:14:12,713 [root] DEBUG: 27244: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-30 16:14:12,717 [root] DEBUG: 27244: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-30 16:14:12,719 [root] DEBUG: 27244: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-30 16:14:12,732 [root] DEBUG: 27244: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-30 16:14:12,739 [root] DEBUG: 27380: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-30 16:14:12,740 [root] DEBUG: 27380: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-30 16:14:12,741 [root] DEBUG: 27380: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-30 16:14:12,742 [root] DEBUG: 27380: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-30 16:14:12,744 [root] DEBUG: 27380: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-30 16:14:12,745 [root] DEBUG: 27380: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-30 16:14:12,815 [root] DEBUG: 27380: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-30 16:14:12,829 [root] DEBUG: 27380: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-30 16:14:12,909 [root] DEBUG: 27380: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-30 16:14:12,991 [root] DEBUG: 27380: NtTerminateProcess hook: Attempting to dump process 27380
2026-05-30 16:14:12,992 [root] DEBUG: 27380: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:13,000 [root] INFO: Process with pid 27380 has terminated
2026-05-30 16:14:13,006 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-30 16:14:13,012 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE120000.
2026-05-30 16:14:13,015 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-30 16:14:13,018 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:13,020 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-30 16:14:13,021 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:13,033 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-30 16:14:13,035 [root] DEBUG: 4484: api-cap: LdrpCallInitRoutine hook disabled due to count: 5000
2026-05-30 16:14:13,037 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE120000.
2026-05-30 16:14:13,042 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-30 16:14:13,043 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:13,046 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-30 16:14:13,047 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-30 16:14:13,048 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 27328: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF7100A0000
2026-05-30 16:14:13,050 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 27328
2026-05-30 16:14:13,051 [lib.api.process] INFO: Monitor config for process 27328: C:\lpw_albt\dll\27328.ini
2026-05-30 16:14:13,053 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:13,128 [root] DEBUG: 27244: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-30 16:14:13,131 [root] DEBUG: 27244: NtTerminateProcess hook: Attempting to dump process 27244
2026-05-30 16:14:13,134 [root] DEBUG: 27244: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:13,148 [root] INFO: Process with pid 27244 has terminated
2026-05-30 16:14:13,153 [root] DEBUG: 25340: DLL loaded at 0x75560000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\psmachine (0x58000 bytes).
2026-05-30 16:14:13,158 [root] DEBUG: 25340: DLL loaded at 0x75500000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:13,166 [root] DEBUG: 25340: DLL loaded at 0x75480000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:13,168 [root] DEBUG: 25340: DLL loaded at 0x750E0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:13,170 [root] DEBUG: 25340: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:13,172 [root] DEBUG: 25340: DLL loaded at 0x750C0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:13,175 [root] DEBUG: 25340: DLL loaded at 0x75110000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:13,176 [root] DEBUG: 25340: DLL loaded at 0x754D0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:13,184 [root] DEBUG: 25340: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:13,187 [root] DEBUG: 25340: DLL loaded at 0x74920000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:13,299 [root] DEBUG: 25340: NtTerminateProcess hook: Attempting to dump process 25340
2026-05-30 16:14:13,303 [root] DEBUG: 25340: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:13,309 [root] INFO: Process with pid 25340 has terminated
2026-05-30 16:14:13,434 [root] DEBUG: 24116: DLL loaded at 0x75560000: C:\Windows\System32\SystemSettings.DataModel (0x57000 bytes).
2026-05-30 16:14:13,436 [root] DEBUG: 24116: caller_dispatch: Added region at 0x75560000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x755A5FD8, thread 24120).
2026-05-30 16:14:13,438 [root] DEBUG: 24116: ProcessTrackedRegion: Region at 0x75560000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\SystemSettings.DataModel.dll is in known range, skipping
2026-05-30 16:14:13,444 [root] DEBUG: 24116: DLL loaded at 0x75530000: C:\Windows\SYSTEM32\USERENV (0x25000 bytes).
2026-05-30 16:14:13,465 [root] DEBUG: 24116: DLL loaded at 0x73990000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x3ba000 bytes).
2026-05-30 16:14:13,477 [root] DEBUG: 24116: DLL loaded at 0x77270000: C:\Windows\System32\CFGMGR32 (0x3b000 bytes).
2026-05-30 16:14:13,485 [root] DEBUG: 24116: DLL loaded at 0x754A0000: C:\Windows\System32\StructuredQuery (0x81000 bytes).
2026-05-30 16:14:13,489 [root] DEBUG: 24116: caller_dispatch: Added region at 0x754A0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x754B4950, thread 26504).
2026-05-30 16:14:13,491 [root] DEBUG: 24116: ProcessTrackedRegion: Region at 0x754A0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\StructuredQuery.dll is in known range, skipping
2026-05-30 16:14:13,500 [root] DEBUG: 24116: DLL loaded at 0x750B0000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2026-05-30 16:14:13,505 [root] DEBUG: 24116: DLL loaded at 0x740E0000: C:\Windows\System32\Windows.StateRepositoryPS (0x93000 bytes).
2026-05-30 16:14:13,517 [root] DEBUG: 24116: DLL loaded at 0x74040000: C:\Windows\system32\Windows.Storage.Search (0x9d000 bytes).
2026-05-30 16:14:13,530 [root] DEBUG: 24116: CreateProcessHandler: Injection info set for new process 25392: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-30 16:14:13,532 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 25392
2026-05-30 16:14:13,534 [lib.api.process] INFO: Monitor config for process 25392: C:\lpw_albt\dll\25392.ini
2026-05-30 16:14:13,536 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:13,546 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\xzFcTOhk.dll, loader C:\lpw_albt\bin\MAKNElR.exe
2026-05-30 16:14:13,555 [root] DEBUG: Loader: Injecting process 25392 (thread 4132) with C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:13,557 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:13,558 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\xzFcTOhk.dll.
2026-05-30 16:14:13,561 [lib.api.process] INFO: Injected into 32-bit <Process 25392 MicrosoftEdgeUpdate.exe>
2026-05-30 16:14:13,573 [root] DEBUG: 25392: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:13,574 [root] DEBUG: 25392: Interactive desktop enabled.
2026-05-30 16:14:13,575 [root] DEBUG: 25392: Dropped file limit defaulting to 100.
2026-05-30 16:14:13,581 [root] DEBUG: 25392: Disabling sleep skipping.
2026-05-30 16:14:13,584 [root] DEBUG: 25392: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:13,587 [root] DEBUG: 25392: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:14:13,589 [root] DEBUG: 25392: Monitor initialised: 32-bit capemon loaded in process 25392 at 0x75180000, thread 4132, image base 0x150000, stack from 0x2b34000-0x2b40000
2026-05-30 16:14:13,592 [root] DEBUG: 25392: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4yMzcuNyIgc2hlbGxfdmVyc2lvbj0iMS4zLjIzMy4zIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0I1MjI2RTU0LUIyMEQtNEUxQS1BNkE2LTQ5RDIyQTk3RTJDNX0iIHVzZXJpZD0ie0Y5MjVFQ0UxLTFDRjQtNDQzQS04N0ZCLTRGNzU4MUJFMDhFMn0iIGluc3RhbGxzb3VyY2U9InNlbGZ1cGRhdGUiIHJlcXVlc3RpZD0ie0YxQzEzNjgzLUYwQkQtNDExOS05QTk1LUIzMjdGN
2026-05-30 16:14:13,611 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-30 16:14:13,613 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_atomic_wait.dll
2026-05-30 16:14:13,613 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-30 16:14:13,614 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-30 16:14:13,614 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_1.dll
2026-05-30 16:14:13,615 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-30 16:14:13,615 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-30 16:14:13,635 [root] DEBUG: 25392: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-30 16:14:13,660 [root] DEBUG: 25392: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-30 16:14:13,662 [root] DEBUG: 25392: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-30 16:14:13,671 [root] DEBUG: 25392: Hooked 632 out of 632 functions
2026-05-30 16:14:13,673 [root] DEBUG: 25392: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:13,679 [root] DEBUG: 25392: RestoreHeaders: Restored original import table.
2026-05-30 16:14:13,682 [root] INFO: Loaded monitor into process with pid 25392
2026-05-30 16:14:13,684 [root] DEBUG: 25392: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 4132).
2026-05-30 16:14:13,686 [root] DEBUG: 25392: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-30 16:14:13,689 [root] DEBUG: 25392: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-30 16:14:13,696 [root] DEBUG: 25392: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-30 16:14:13,697 [root] DEBUG: 25392: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-30 16:14:13,700 [root] DEBUG: 25392: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-30 16:14:13,704 [root] DEBUG: 25392: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-30 16:14:13,706 [root] DEBUG: 25392: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-30 16:14:13,711 [root] DEBUG: 25392: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-30 16:14:13,715 [root] DEBUG: 25392: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-30 16:14:13,716 [root] DEBUG: 25392: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-30 16:14:13,717 [root] DEBUG: 25392: DLL loaded at 0x73D50000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.237.7\msedgeupdate (0x241000 bytes).
2026-05-30 16:14:13,718 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:13,726 [root] DEBUG: Loader: Injecting process 27004 (thread 27008) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:13,727 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:14:13,730 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:13,731 [root] DEBUG: 25392: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:13,733 [lib.api.process] INFO: Injected into 64-bit <Process 27004 FileCoAuth.exe>
2026-05-30 16:14:13,733 [root] DEBUG: 25392: DLL loaded at 0x748F0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-30 16:14:13,762 [root] DEBUG: 25392: DLL loaded at 0x74200000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-30 16:14:13,763 [root] DEBUG: 27004: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-30 16:14:13,764 [root] DEBUG: 27004: Interactive desktop enabled.
2026-05-30 16:14:13,765 [root] DEBUG: 25392: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-30 16:14:13,767 [root] DEBUG: 27004: Dropped file limit defaulting to 100.
2026-05-30 16:14:13,772 [root] DEBUG: 27004: Disabling sleep skipping.
2026-05-30 16:14:13,776 [root] DEBUG: 27004: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-30 16:14:13,777 [root] DEBUG: 25392: DLL loaded at 0x748C0000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:13,779 [root] DEBUG: 25392: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-30 16:14:13,780 [root] DEBUG: 25392: DLL loaded at 0x741B0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-30 16:14:13,782 [root] DEBUG: 25392: DLL loaded at 0x73920000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-30 16:14:13,784 [root] DEBUG: 25392: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-30 16:14:13,787 [root] DEBUG: 25392: DLL loaded at 0x741A0000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-30 16:14:13,790 [root] DEBUG: 27004: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-30 16:14:13,792 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FF61DD70000, size 0x23fad2
2026-05-30 16:14:13,794 [root] DEBUG: 25392: DLL loaded at 0x74010000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:13,804 [root] DEBUG: 25392: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-30 16:14:13,809 [root] DEBUG: 25392: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-30 16:14:13,811 [root] DEBUG: 27004: Monitor initialised: 64-bit capemon loaded in process 27004 at 0x00007FFF15C80000, thread 27008, image base 0x00007FF61DD70000, stack from 0x0000009217EF4000-0x0000009217F00000
2026-05-30 16:14:13,813 [root] DEBUG: 25392: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-30 16:14:13,814 [root] DEBUG: 27004: Commandline: "C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileCoAuth.exe" -Embedding
2026-05-30 16:14:13,816 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\LoggingPlatform.DLL
2026-05-30 16:14:13,817 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncSessions.dll
2026-05-30 16:14:13,818 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncHost.DLL
2026-05-30 16:14:13,822 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\Telemetry.dll
2026-05-30 16:14:13,825 [root] DEBUG: 25392: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-30 16:14:13,826 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncFS.DLL
2026-05-30 16:14:13,828 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\VCRUNTIME140_1.dll
2026-05-30 16:14:13,830 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\MSVCP140.dll
2026-05-30 16:14:13,832 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\VCRUNTIME140.dll
2026-05-30 16:14:13,834 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncEvents.dll
2026-05-30 16:14:13,835 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\UpdateRingSettings.dll
2026-05-30 16:14:13,838 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\MSVCP140_ATOMIC_WAIT.dll
2026-05-30 16:14:13,839 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\adal.dll
2026-05-30 16:14:13,841 [root] DEBUG: 27004: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileSyncSqlite3.dll
2026-05-30 16:14:13,860 [root] DEBUG: 27004: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-30 16:14:13,885 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-30 16:14:13,886 [root] DEBUG: 27004: set_hooks: Unable to hook LockResource
2026-05-30 16:14:13,894 [root] DEBUG: 27004: Hooked 627 out of 628 functions
2026-05-30 16:14:13,909 [root] DEBUG: 27004: Syscall hook installed, syscall logging level 1
2026-05-30 16:14:13,916 [root] DEBUG: 27004: RestoreHeaders: Restored original import table.
2026-05-30 16:14:13,917 [root] INFO: Loaded monitor into process with pid 27004
2026-05-30 16:14:13,920 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FFF18950000, size 0x1d2d1
2026-05-30 16:14:13,923 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FFF3F6A0000, size 0xa136
2026-05-30 16:14:13,927 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FFF141F0000, size 0x87804
2026-05-30 16:14:13,933 [root] DEBUG: 27004: caller_dispatch: Added region at 0x00007FFF141F0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x00007FFF14225311, thread 27008).
2026-05-30 16:14:13,935 [root] DEBUG: 27004: caller_dispatch: Scanning calling region at 0x00007FFF141F0000...
2026-05-30 16:14:13,937 [root] DEBUG: 27004: ProcessTrackedRegion: Region at 0x00007FFF141F0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\msvcp140.dll appears unmodified, skipping
2026-05-30 16:14:13,939 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FFF133E0000, size 0xaf16e
2026-05-30 16:14:13,944 [root] DEBUG: 25392: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-30 16:14:13,947 [root] DEBUG: 25392: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-30 16:14:13,947 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FFF133E0000, size 0xaf16e
2026-05-30 16:14:13,956 [root] DEBUG: 25392: DLL loaded at 0x74900000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-30 16:14:13,956 [root] DEBUG: 27004: YaraScan: Scanning 0x00007FFF133E0000, size 0xaf16e
2026-05-30 16:14:13,962 [root] DEBUG: 27004: caller_dispatch: Added region at 0x00007FFF133E0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FFF1344DD5F, thread 27008).
2026-05-30 16:14:13,963 [root] DEBUG: 27004: caller_dispatch: Scanning calling region at 0x00007FFF133E0000...
2026-05-30 16:14:13,965 [root] DEBUG: 27004: ProcessTrackedRegion: Region at 0x00007FFF133E0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\LoggingPlatform.dll appears unmodified, skipping
2026-05-30 16:14:13,969 [root] DEBUG: 25392: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\Iphlpapi (0x32000 bytes).
2026-05-30 16:14:13,971 [root] DEBUG: 25392: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-30 16:14:13,974 [root] DEBUG: 25392: DLL loaded at 0x75480000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-30 16:14:13,981 [root] DEBUG: 25392: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:14:13,983 [root] DEBUG: 25392: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-30 16:14:13,986 [root] DEBUG: 25392: DLL loaded at 0x75470000: C:\Windows\SYSTEM32\diagnosticdataquery (0xc000 bytes).
2026-05-30 16:14:13,989 [root] DEBUG: 25392: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-30 16:14:13,997 [root] DEBUG: 25392: DLL loaded at 0x74250000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-30 16:14:14,012 [root] DEBUG: 25392: DLL loaded at 0x748C0000: C:\Windows\System32\netprofm (0x32000 bytes).
2026-05-30 16:14:14,035 [root] DEBUG: 25392: DLL loaded at 0x74240000: C:\Windows\System32\npmproxy (0xa000 bytes).
2026-05-30 16:14:14,064 [root] DEBUG: 25392: DLL loaded at 0x74230000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0xe000 bytes).
2026-05-30 16:14:14,088 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 28224, handle 0x2568: C:\Windows\System32\WerFault.exe
2026-05-30 16:14:14,092 [root] DEBUG: 25392: DLL loaded at 0x738C0000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-30 16:14:14,097 [root] DEBUG: 25392: DLL loaded at 0x74210000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-30 16:14:14,118 [root] DEBUG: 25392: DLL loaded at 0x74210000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-30 16:14:14,252 [root] DEBUG: 25392: DLL loaded at 0x73840000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-30 16:14:14,254 [root] DEBUG: 25392: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-30 16:14:14,256 [root] DEBUG: 25392: DLL loaded at 0x74200000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-30 16:14:14,265 [root] DEBUG: 25392: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-30 16:14:14,268 [root] DEBUG: 25392: DLL loaded at 0x741C0000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-30 16:14:14,271 [root] DEBUG: 25392: DLL loaded at 0x73FE0000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-30 16:14:14,315 [root] DEBUG: 25392: DLL loaded at 0x737C0000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-30 16:14:14,339 [root] DEBUG: 25392: DLL loaded at 0x741B0000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-30 16:14:14,340 [root] DEBUG: 25392: DLL loaded at 0x73790000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-30 16:14:14,343 [root] DEBUG: 25392: DLL loaded at 0x73760000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-30 16:14:14,346 [root] DEBUG: 25392: DLL loaded at 0x73740000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-30 16:14:14,349 [root] DEBUG: 25392: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-30 16:14:14,585 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:14,591 [root] DEBUG: Loader: Injecting process 27328 (thread 27324) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:14,593 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:14,594 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:14,596 [lib.api.process] INFO: Injected into 64-bit <Process 27328 ShellExperienceHost.exe>
2026-05-30 16:14:14,598 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 27328
2026-05-30 16:14:14,599 [lib.api.process] INFO: Monitor config for process 27328: C:\lpw_albt\dll\27328.ini
2026-05-30 16:14:14,600 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:14,673 [root] DEBUG: 25392: DLL loaded at 0x741A0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-05-30 16:14:14,688 [root] DEBUG: 25392: NtTerminateProcess hook: Attempting to dump process 25392
2026-05-30 16:14:14,690 [root] DEBUG: 25392: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:14,699 [root] INFO: Process with pid 25392 has terminated
2026-05-30 16:14:14,713 [root] DEBUG: 24116: Dropped file limit reached.
2026-05-30 16:14:14,716 [root] DEBUG: 24116: NtTerminateProcess hook: Attempting to dump process 24116
2026-05-30 16:14:14,718 [root] DEBUG: 24116: DoProcessDump: Code modification detected, dumping Imagebase at 0x00870000.
2026-05-30 16:14:14,720 [root] DEBUG: 24116: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-05-30 16:14:14,720 [root] DEBUG: 24116: DumpProcess: Instantiating PeParser with address: 0x00870000.
2026-05-30 16:14:14,723 [root] DEBUG: 24116: DumpProcess: Module entry point VA is 0x0087B8C0.
2026-05-30 16:14:14,760 [lib.common.results] INFO: Uploading file C:\gbSlmMlCP\CAPE\24116_1057604014142030652026 to procdump\16590d8634e0ed29229ff604f3b72b8ba3fe328e9fb0ee28de159f8757623b7a; Size is 199680; Max size: 100000000
2026-05-30 16:14:14,767 [root] DEBUG: 24116: DumpProcess: Module image dump success - dump size 0x30c00.
2026-05-30 16:14:14,779 [root] INFO: Process with pid 24116 has terminated
2026-05-30 16:14:14,808 [root] DEBUG: 21872: NtTerminateProcess hook: Attempting to dump process 21872
2026-05-30 16:14:14,810 [root] DEBUG: 21872: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-30 16:14:14,818 [root] INFO: Process with pid 21872 has terminated
2026-05-30 16:14:16,167 [root] INFO: Process with pid 27004 appears to have terminated
2026-05-30 16:14:17,002 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:17,010 [root] DEBUG: Loader: Injecting process 27328 (thread 27324) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:17,013 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:17,015 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:17,018 [lib.api.process] INFO: Injected into 64-bit <Process 27328 ShellExperienceHost.exe>
2026-05-30 16:14:17,024 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 27328
2026-05-30 16:14:17,025 [lib.api.process] INFO: Monitor config for process 27328: C:\lpw_albt\dll\27328.ini
2026-05-30 16:14:17,028 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:17,285 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56140000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-30 16:14:17,293 [root] DEBUG: 8528: DLL loaded at 0x00007FFF56170000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-30 16:14:17,297 [root] DEBUG: 8528: DLL loaded at 0x00007FFF182B0000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-30 16:14:17,324 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4F4B0000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-30 16:14:17,463 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 28184: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:14:17,465 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 28184
2026-05-30 16:14:17,467 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 28184
2026-05-30 16:14:17,632 [root] DEBUG: 8528: DLL loaded at 0x00007FFF18060000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-30 16:14:18,128 [root] DEBUG: 8528: DLL loaded at 0x00007FFF4F4D0000: C:\Windows\System32\BitsProxy (0x16000 bytes).
2026-05-30 16:14:19,039 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:19,045 [root] DEBUG: Loader: Injecting process 27328 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:19,047 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 27324, handle 0x120
2026-05-30 16:14:19,048 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-30 16:14:19,051 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:19,053 [lib.api.process] INFO: Injected into 64-bit <Process 27328 ShellExperienceHost.exe>
2026-05-30 16:14:21,724 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 3976 (handle 0x2e38): 0x00007FF7BF860000.
2026-05-30 16:14:21,729 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 3976, handle 0x2e38: C:\Windows\System32\conhost.exe
2026-05-30 16:14:26,077 [root] DEBUG: 4484: api-cap: NtWaitForSingleObject hook disabled due to count: 5000
2026-05-30 16:14:29,425 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24496: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-30 16:14:29,428 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24496
2026-05-30 16:14:29,429 [lib.api.process] INFO: Monitor config for process 24496: C:\lpw_albt\dll\24496.ini
2026-05-30 16:14:29,433 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,446 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,457 [root] DEBUG: Loader: Injecting process 24496 (thread 24492) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,463 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,467 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,471 [lib.api.process] INFO: Injected into 64-bit <Process 24496 dllhost.exe>
2026-05-30 16:14:29,476 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24496
2026-05-30 16:14:29,477 [lib.api.process] INFO: Monitor config for process 24496: C:\lpw_albt\dll\24496.ini
2026-05-30 16:14:29,480 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,489 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,500 [root] DEBUG: Loader: Injecting process 24496 (thread 24492) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,505 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,506 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,513 [lib.api.process] INFO: Injected into 64-bit <Process 24496 dllhost.exe>
2026-05-30 16:14:29,519 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 21748: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-30 16:14:29,521 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21748
2026-05-30 16:14:29,524 [lib.api.process] INFO: Monitor config for process 21748: C:\lpw_albt\dll\21748.ini
2026-05-30 16:14:29,527 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,541 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,549 [root] DEBUG: Loader: Injecting process 21748 (thread 29168) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,553 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,555 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,558 [lib.api.process] INFO: Injected into 64-bit <Process 21748 dllhost.exe>
2026-05-30 16:14:29,564 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21748
2026-05-30 16:14:29,567 [lib.api.process] INFO: Monitor config for process 21748: C:\lpw_albt\dll\21748.ini
2026-05-30 16:14:29,569 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,582 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,589 [root] DEBUG: Loader: Injecting process 21748 (thread 29168) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,594 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,596 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,598 [lib.api.process] INFO: Injected into 64-bit <Process 21748 dllhost.exe>
2026-05-30 16:14:29,606 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 29452: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-30 16:14:29,608 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 29452
2026-05-30 16:14:29,611 [lib.api.process] INFO: Monitor config for process 29452: C:\lpw_albt\dll\29452.ini
2026-05-30 16:14:29,615 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,622 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,633 [root] DEBUG: Loader: Injecting process 29452 (thread 1976) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,637 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,642 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,645 [lib.api.process] INFO: Injected into 64-bit <Process 29452 dllhost.exe>
2026-05-30 16:14:29,649 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 29452
2026-05-30 16:14:29,654 [lib.api.process] INFO: Monitor config for process 29452: C:\lpw_albt\dll\29452.ini
2026-05-30 16:14:29,658 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,665 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,671 [root] DEBUG: Loader: Injecting process 29452 (thread 1976) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,673 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,675 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,679 [lib.api.process] INFO: Injected into 64-bit <Process 29452 dllhost.exe>
2026-05-30 16:14:29,686 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10136: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-30 16:14:29,690 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10136
2026-05-30 16:14:29,692 [lib.api.process] INFO: Monitor config for process 10136: C:\lpw_albt\dll\10136.ini
2026-05-30 16:14:29,696 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,705 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,716 [root] DEBUG: Loader: Injecting process 10136 (thread 9128) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,717 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,721 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,724 [lib.api.process] INFO: Injected into 64-bit <Process 10136 dllhost.exe>
2026-05-30 16:14:29,729 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10136
2026-05-30 16:14:29,732 [lib.api.process] INFO: Monitor config for process 10136: C:\lpw_albt\dll\10136.ini
2026-05-30 16:14:29,733 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:29,746 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:29,754 [root] DEBUG: Loader: Injecting process 10136 (thread 9128) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,756 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-30 16:14:29,759 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:29,764 [lib.api.process] INFO: Injected into 64-bit <Process 10136 dllhost.exe>
2026-05-30 16:14:30,141 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5624 (handle 0x2e40): 0x00007FF659080000.
2026-05-30 16:14:30,537 [root] INFO: Process with pid 7840 has terminated
2026-05-30 16:14:30,609 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-30 16:14:30,875 [root] DEBUG: 8528: CreateProcessHandler: Injection info set for new process 29840: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-30 16:14:30,877 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 29840
2026-05-30 16:14:30,880 [root] DEBUG: 8528: ProcessMessage: Skipping monitoring process 29840
2026-05-30 16:14:31,620 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 29984: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-30 16:14:31,624 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 29988
2026-05-30 16:14:31,625 [root] INFO: Announced 64-bit process name: svchost.exe pid: 29984
2026-05-30 16:14:31,627 [lib.api.process] INFO: Monitor config for process 29984: C:\lpw_albt\dll\29984.ini
2026-05-30 16:14:31,629 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:31,635 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:31,643 [root] DEBUG: Loader: Injecting process 29984 (thread 29988) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:31,668 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\29984.ini to system path C:\29984.ini
2026-05-30 16:14:31,676 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 29984 C:\lpw_albt\dll\RRWCoUiC.dll
2026-05-30 16:14:31,678 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:31,689 [lib.api.process] INFO: Injected into 64-bit <Process 29984 svchost.exe>
2026-05-30 16:14:31,699 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 29988
2026-05-30 16:14:31,702 [root] INFO: Announced 64-bit process name: svchost.exe pid: 29984
2026-05-30 16:14:31,704 [lib.api.process] INFO: Monitor config for process 29984: C:\lpw_albt\dll\29984.ini
2026-05-30 16:14:31,711 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:31,722 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:31,732 [root] DEBUG: Loader: Injecting process 29984 (thread 29988) with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:31,735 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\29984.ini to system path C:\29984.ini
2026-05-30 16:14:31,741 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 29984 C:\lpw_albt\dll\RRWCoUiC.dll
2026-05-30 16:14:31,742 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:31,749 [lib.api.process] INFO: Injected into 64-bit <Process 29984 svchost.exe>
2026-05-30 16:14:31,752 [root] INFO: Announced 64-bit process name: svchost.exe pid: 29984
2026-05-30 16:14:31,753 [lib.api.process] INFO: Monitor config for process 29984: C:\lpw_albt\dll\29984.ini
2026-05-30 16:14:31,754 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-30 16:14:31,766 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\RRWCoUiC.dll, loader C:\lpw_albt\bin\zXvJpkPd.exe
2026-05-30 16:14:31,773 [root] DEBUG: Loader: Injecting process 29984 with C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:31,776 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\29984.ini to system path C:\29984.ini
2026-05-30 16:14:31,780 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 29984 C:\lpw_albt\dll\RRWCoUiC.dll
2026-05-30 16:14:31,783 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\RRWCoUiC.dll.
2026-05-30 16:14:31,790 [lib.api.process] INFO: Injected into 64-bit <Process 29984 svchost.exe>
2026-05-30 16:14:31,813 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 30424, handle 0x2e40: C:\Windows\System32\WerFault.exe
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-30 16:12:52 | 2026-05-30 16:14:43 | none |
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (20980) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (23104) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (24116) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (24116) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (25392) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 48.215.115.201 [VT] | unknown | - |
| Y | 74.125.200.188 [VT] | unknown | - |
| Y | 142.251.42.110 [VT] | unknown | - |
| N | 142.250.207.14 [VT] | unknown | - |
| N | 142.250.195.163 [VT] | unknown | - |
| Y | 104.29.138.175 [VT] | unknown | - |
| Y | 104.29.139.163 [VT] | unknown | - |
| Y | 104.29.138.199 [VT] | unknown | - |
| Y | 104.29.139.110 [VT] | unknown | - |
| Y | 104.29.139.123 [VT] | unknown | - |
| Y | 104.29.141.87 [VT] | unknown | - |
| Y | 104.29.140.192 [VT] | unknown | - |
| Y | 104.29.145.242 [VT] | unknown | - |
| Y | 104.29.145.243 [VT] | unknown | - |
| Y | 104.29.140.191 [VT] | unknown | - |
| Y | 104.29.132.168 [VT] | unknown | - |
| Y | 104.29.132.49 [VT] | unknown | - |
| Y | 104.29.157.228 [VT] | unknown | - |
| Y | 104.29.136.159 [VT] | unknown | - |
| Y | 104.29.138.128 [VT] | unknown | - |
| Y | 104.29.141.21 [VT] | unknown | - |
| Y | 104.29.141.166 [VT] | unknown | - |
| Y | 104.29.142.73 [VT] | unknown | - |
| Y | 104.29.142.56 [VT] | unknown | - |
| Y | 104.29.140.188 [VT] | unknown | - |
| Y | 104.29.149.147 [VT] | unknown | - |
| Y | 104.29.149.132 [VT] | unknown | - |
| Y | 104.29.149.152 [VT] | unknown | - |
| Y | 104.29.149.129 [VT] | unknown | - |
| Y | 104.29.149.146 [VT] | unknown | - |
| N | 162.159.138.234 [VT] | unknown | - |
| Y | 172.64.154.167 [VT] | unknown | - |
| N | 142.250.183.33 [VT] | unknown | - |
| N | 142.250.4.84 [VT] | unknown | - |
| N | 52.110.12.14 [VT] | unknown | - |
| N | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 146.75.119.82 [VT] | unknown | - |
| N | 23.209.183.176 [VT] | unknown | - |
| N | 205.196.6.133 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 149.135.84.72 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 34.126.226.51 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| N | 162.159.129.233 [VT] | unknown | - |
| N | 162.159.137.232 [VT] | unknown | - |
| N | 162.159.134.233 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 142.250.195.227 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Y | 104.115.81.8 [VT] | unknown | - |
| N | 23.202.165.215 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| N | 199.232.215.52 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-udp.steamserver.net [VT] |
CNAME udp.ipv6check.akadns.net
[VT]
AAAA 2404:3fc0:1:102::670a:7d36 [VT] AAAA 2404:3fc0:1:102::670a:7d37 [VT] AAAA 2404:3fc0:1:100::670a:7d06 [VT] AAAA 2404:3fc0:1:100::42 [VT] AAAA 2404:3fc0:1:102::670a:7d38 [VT] CNAME syd.udp.ipv6check.akadns.net [VT] AAAA 2404:3fc0:1:100::670a:7d08 [VT] AAAA 2404:3fc0:1:102::670a:7d35 [VT] AAAA 2404:3fc0:1:100::32 [VT] |
|
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.155
[VT]
A 149.135.84.160 [VT] |
23.56.110.24 [VT] |
| cdn.onenote.net [VT] |
CNAME e1553.dspg.akamaiedge.net
[VT]
A 23.202.165.215 [VT] CNAME cdn.onenote.net.edgekey.net [VT] |
23.210.64.56 [VT] |
| c.pki.goog [VT] |
A 142.250.195.227
[VT]
CNAME pki-goog.l.google.com [VT] |
172.217.25.163 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.134.234 [VT] |
| discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.134.233 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.135.232 [VT] |
| cdn.discordapp.com [VT] | 162.159.133.233 [VT] | |
| updates.discord.com [VT] | 162.159.135.232 [VT] | |
| stable.dl2.discordapp.net [VT] | A 34.126.226.51 [VT] | 34.126.226.51 [VT] |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| res.public.onecdn.static.microsoft [VT] |
CNAME res-1.public.onecdn.static.microsoft
[VT]
CNAME res-ocdi-public.trafficmanager.net [VT] CNAME res-ocdi-stls-prod.edgesuite.net [VT] A 149.135.84.72 [VT] A 149.135.84.202 [VT] |
23.211.125.104 [VT] |
| cmp2-sea1.steamserver.net [VT] | A 205.196.6.133 [VT] | 205.196.6.133 [VT] |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| clientconfig.akamai.steamstatic.com [VT] |
A 23.209.183.106
[VT]
A 23.209.183.176 [VT] |
23.211.125.111 [VT] |
| shared.steamstatic.com [VT] |
A 199.232.215.52
[VT]
A 199.232.211.52 [VT] CNAME shared.valve.map.fastly.net [VT] |
199.232.211.52 [VT] |
| config.svc.cloud.microsoft [VT] |
CNAME prod.configsvc1.live.com.akadns.net
[VT]
A 52.110.12.14 [VT] A 52.110.12.19 [VT] CNAME asia.configsvc1.live.com.akadns.net [VT] A 52.110.12.16 [VT] CNAME atm.office.mira.tm.svc.cloud.microsoft [VT] A 52.110.12.24 [VT] CNAME config-prod-weightedww.trafficmanager.net [VT] |
52.110.12.3 [VT] |
| www.gstatic.com [VT] | A 142.250.195.163 [VT] | 142.250.195.99 [VT] |
| accounts.google.com [VT] | A 142.250.4.84 [VT] | 142.251.10.84 [VT] |
| clients2.googleusercontent.com [VT] |
CNAME googlehosted.l.googleusercontent.com
[VT]
A 142.250.183.33 [VT] |
172.217.25.161 [VT] |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.129.235 [VT] |
| play.google.com [VT] | A 142.250.207.14 [VT] | 142.250.195.110 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.