Time | Thread | Line | Function | Message |
10:31:07.895 | 18C4 | 361 | ftw1 | Loading (pid: 8984) |
10:31:07.897 | 18C4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X58560000>6|2|1203373203 |
10:31:07.897 | 18C4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X59FB0000>6|2|1203373081 |
10:31:07.913 | 2A70 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
10:31:08.60 | 18C4 | 172 | DXManager::Detect | Found in 0 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0X4660|18016 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0X661F0|418288 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0X1350|4944 |
10:31:08.67 | 18C4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0XFE6D3020|-26398688 |
10:31:08.67 | 18C4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0XFE6D8060|-26378144 |
10:31:08.67 | 18C4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0XFE6CE620|-26417632 |
10:31:08.67 | 18C4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
10:31:08.67 | 18C4 | 209 | Initialize::GetLocation | @ 0XFE5BAA80|-27547008 |
10:31:08.332 | 18C4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X2B0B0000>6|2|1203373142 |
10:31:08.449 | 18C4 | 129 | DXManager::Detect | OK |
10:31:08.630 | 18C4 | 186 | DXManager::Detect | Done |
10:31:08.631 | 18C4 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X5880|22656 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XF280|62080 |
10:31:08.631 | 18C4 | 209 | Initialize::GetLocation | @ 0XF430|62512 |
10:31:08.667 | 18C4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X2AD80000>6|2|1203372033 |
10:31:08.679 | 18C4 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
10:31:08.679 | 18C4 | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
10:31:08.679 | 18C4 | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
10:31:08.679 | 18C4 | 209 | Initialize::GetLocation | @ 0X6180|24960 |
10:31:08.681 | 18C4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X22E80000>6|2|1203372033 |
10:31:08.690 | 18C4 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
10:31:08.691 | 18C4 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
10:31:08.691 | 18C4 | 209 | Initialize::GetLocation | @ 0X10000|65536 |
10:31:08.691 | 18C4 | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
10:31:08.691 | 18C4 | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
10:31:08.743 | 18C4 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_8984 opened succesfuly |
10:31:08.743 | 18C4 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
10:31:08.743 | 18C4 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_8984 close 2147483647 bytes |
10:31:08.743 | 18C4 | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.162.0.7\OWExplorer.dll] |
10:31:08.757 | 18C4 | 385 | ftw1 | OWExplorer injected |
10:31:09.828 | 2E48 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
10:31:09.828 | 2E48 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
10:31:09.828 | 2E48 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
10:31:09.828 | 2E48 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
10:31:09.857 | 4C80 | 629 | ProcessInjector::InjectProcess | process |vpnagent.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |com.docker.service| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |nassvc.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |mysqld.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |tv_w32.exe| missing h |
10:31:09.858 | 4C80 | 629 | ProcessInjector::InjectProcess | process |tv_x64.exe| missing h |
10:31:10.35 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
10:31:10.78 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
10:31:12.971 | 4C80 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
10:32:39.26 | 4C80 | 629 | ProcessInjector::InjectProcess | process |CCUpdate.exe| missing h |
10:32:39.26 | 4C80 | 629 | ProcessInjector::InjectProcess | process |VSIXAutoUpdate.exe| missing h |
10:32:40.27 | 4C80 | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
10:32:40.27 | 4C80 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
10:32:42.28 | 4C80 | 629 | ProcessInjector::InjectProcess | process |VSHiveStub.exe| missing h |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [316] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |316|: Teams.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2968] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2968|: vpnagent.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3652] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3652|: com.docker.service |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3720] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3720|: gameinputsvc.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3984] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3984|: nassvc.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4024] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4024|: MsMpEng.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4044] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4044|: httpd.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4464] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4464|: mysqld.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5204] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5204|: DropboxUpdate.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6440] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6440|: Teams.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6484] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6484|: GoogleCrashHandler64.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7992] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7992|: httpd.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11064] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11064|: gameinputsvc.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11136] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11136|: tv_w32.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11244] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11244|: GoogleCrashHandler.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14364] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14364|: tv_x64.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14488] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14488|: GoogleUpdate.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17712] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17712|: Teams.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19748] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19748|: Teams.exe |
10:33:40.35 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24548] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0 |
10:33:40.35 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24548|: MicrosoftEdgeUpdate.exe |
10:33:41.36 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9576] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0 |
10:33:41.36 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9576|: com.docker.backend.exe |
10:33:41.36 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14552] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x0 |
10:33:41.36 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14552|: docker-mutagen.exe |
10:34:03.48 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [840] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
10:34:03.48 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |840|: Teams.exe |
10:34:03.48 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3956] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0 |
10:34:03.48 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3956|: vpnkit-bridge.exe |
10:34:14.51 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16188] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0 |
10:34:14.51 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16188|: vpnkit.exe |
10:34:16.55 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21652] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0 |
10:34:16.55 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21652|: com.docker.proxy.exe |
10:35:41.140 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
10:35:42.98 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
10:42:06.187 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23728] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x578 |
10:42:06.187 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23728|: Teams.exe |
10:57:28.336 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15908] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x578 |
10:57:28.337 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15908|: Teams.exe |
11:02:12.606 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22120] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:12.606 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22120|: Code.exe |
11:02:12.606 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22224] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:12.606 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22224|: Code.exe |
11:02:15.610 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2804] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:15.610 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2804|: Code.exe |
11:02:15.610 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16876] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:15.610 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16876|: Code.exe |
11:02:17.611 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18704] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:17.611 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18704|: Code.exe |
11:02:17.611 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24256] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:17.612 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24256|: Code.exe |
11:02:18.607 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2812] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:18.607 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2812|: Code.exe |
11:02:18.607 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16752] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:18.607 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16752|: Code.exe |
11:02:19.610 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [92] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:19.610 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |92|: Code.exe |
11:02:24.609 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7928] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
11:02:24.609 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7928|: Code.exe |
11:02:26.607 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11588] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
11:02:26.607 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11588|: rg.exe |
11:02:26.607 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15100] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
11:02:26.607 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15100|: rg.exe |
11:02:26.607 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24348] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
11:02:26.607 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24348|: rg.exe |
11:05:29.643 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20908] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
11:05:29.643 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20908|: Teams.exe |
11:11:29.743 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7232] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
11:11:29.743 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7232|: Teams.exe |
11:14:35.766 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23104] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
11:14:35.766 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23104|: Teams.exe |
11:18:02.816 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
11:18:36.807 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15668] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
11:18:36.807 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15668|: Teams.exe |
11:22:10.848 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
11:26:25.900 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23400] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
11:26:25.900 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23400|: Teams.exe |
11:35:07.53 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3368] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
11:35:07.53 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3368|: Teams.exe |
11:42:23.246 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16280] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
11:42:23.246 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16280|: Teams.exe |
12:02:30.382 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [868] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
12:02:30.383 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |868|: Teams.exe |
12:05:13.420 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
12:07:07.406 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1952] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
12:07:07.406 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1952|: Teams.exe |
12:11:11.437 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16036] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
12:11:11.437 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16036|: Teams.exe |
12:18:02.474 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
12:41:55.598 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15660] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
12:41:55.598 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15660|: Teams.exe |
13:18:03.86 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
13:23:21.392 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23852] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
13:23:21.392 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23852|: Teams.exe |
13:26:20.589 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15416] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
13:26:20.589 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15416|: node.exe |
13:26:20.589 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19716] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
13:26:20.589 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19716|: node.exe |
13:27:22.594 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2136] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
13:27:22.594 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2136|: Teams.exe |
13:35:22.715 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18468] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
13:35:22.715 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18468|: Teams.exe |
13:41:23.824 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19948] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
13:41:23.824 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19948|: Teams.exe |
13:47:24.858 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3556] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
13:47:24.858 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3556|: Teams.exe |
13:51:24.927 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13716] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
13:51:24.927 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13716|: Teams.exe |
13:57:25.975 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20452] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
13:57:25.975 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20452|: Teams.exe |
14:05:26.236 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14752] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
14:05:26.236 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14752|: Teams.exe |
14:11:26.796 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19368] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
14:11:26.796 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19368|: Teams.exe |
14:18:02.830 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
14:32:39.488 | 4C80 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
14:35:44.704 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
14:35:47.696 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
14:38:50.855 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16500] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
14:38:50.855 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16500|: Teams.exe |
14:42:32.968 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19944] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
14:42:32.968 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19944|: Teams.exe |
14:49:51.368 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
14:52:04.372 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14556] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
14:52:04.372 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14556|: Teams.exe |
15:05:13.835 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
15:06:06.835 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22112] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:06:06.835 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22112|: Teams.exe |
15:12:06.998 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5932] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:12:06.998 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5932|: Teams.exe |
15:18:03.110 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
15:22:11.181 | 4C80 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:27:29.278 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11340] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:27:29.278 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11340|: Teams.exe |
15:32:39.334 | 4C80 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:35:29.346 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20748] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:35:29.346 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20748|: Teams.exe |
15:41:30.449 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13580] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:41:30.449 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13580|: Teams.exe |
15:47:30.561 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15584] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:47:30.561 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15584|: Teams.exe |
15:49:51.597 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:50:21.623 | 4C80 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:52:06.710 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1132] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:52:06.710 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1132|: Teams.exe |
16:05:14.731 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:05:14.731 | 4C80 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:07:58.890 | 4C80 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1756] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:07:58.890 | 4C80 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1756|: Teams.exe |
16:15:44.85 | 18C4 | 66 | ProcessesMonitor::Stop | stopping PM... |
16:15:44.85 | 2E48 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
16:15:44.104 | 18C4 | 526 | ProcessInjector::Unhook | unhook running process |
16:15:50.230 | 18C4 | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |