Time | Thread | Line | Function | Message |
13:38:31.190 | 35E8 | 361 | ftw1 | Loading (pid: 3416) |
13:38:31.192 | 35E8 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X58560000>6|2|1203373203 |
13:38:31.192 | 35E8 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X59FB0000>6|2|1203373081 |
13:38:31.198 | 4524 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
13:38:31.370 | 35E8 | 172 | DXManager::Detect | Found in 0 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0X4660|18016 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0X661F0|418288 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0X1350|4944 |
13:38:31.370 | 35E8 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0XFE6D3020|-26398688 |
13:38:31.370 | 35E8 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0XFE6D8060|-26378144 |
13:38:31.370 | 35E8 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0XFE6CE620|-26417632 |
13:38:31.370 | 35E8 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
13:38:31.370 | 35E8 | 209 | Initialize::GetLocation | @ 0XFE5BAA80|-27547008 |
13:38:31.436 | 35E8 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X2DE50000>6|2|1203373142 |
13:38:31.528 | 35E8 | 129 | DXManager::Detect | OK |
13:38:31.606 | 35E8 | 186 | DXManager::Detect | Done |
13:38:31.607 | 35E8 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X5880|22656 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XF280|62080 |
13:38:31.608 | 35E8 | 209 | Initialize::GetLocation | @ 0XF430|62512 |
13:38:31.639 | 35E8 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X339E0000>6|2|1203372033 |
13:38:31.654 | 35E8 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
13:38:31.654 | 35E8 | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
13:38:31.654 | 35E8 | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
13:38:31.654 | 35E8 | 209 | Initialize::GetLocation | @ 0X6180|24960 |
13:38:31.656 | 35E8 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X21BA0000>6|2|1203372033 |
13:38:31.667 | 35E8 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
13:38:31.667 | 35E8 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
13:38:31.668 | 35E8 | 209 | Initialize::GetLocation | @ 0X10000|65536 |
13:38:31.668 | 35E8 | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
13:38:31.668 | 35E8 | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
13:38:31.720 | 35E8 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_3416 opened succesfuly |
13:38:31.720 | 35E8 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
13:38:31.720 | 35E8 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_3416 close 2147483647 bytes |
13:38:31.720 | 35E8 | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.162.0.8\OWExplorer.dll] |
13:38:31.892 | 35E8 | 385 | ftw1 | OWExplorer injected |
13:38:32.467 | 53AC | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
13:38:32.468 | 53AC | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
13:38:32.468 | 53AC | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
13:38:32.468 | 53AC | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |vpnagent.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |com.docker.service| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |nassvc.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |mysqld.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |tv_w32.exe| missing h |
13:38:32.485 | 5EBC | 629 | ProcessInjector::InjectProcess | process |tv_x64.exe| missing h |
13:40:03.43 | 5EBC | 629 | ProcessInjector::InjectProcess | process |VSIXAutoUpdate.exe| missing h |
13:40:03.43 | 5EBC | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
13:41:03.49 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2968] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x0 |
13:41:03.49 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2968|: vpnagent.exe |
13:41:03.49 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3652] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0 |
13:41:03.49 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3652|: com.docker.service |
13:41:03.49 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3720] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
13:41:03.49 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3720|: gameinputsvc.exe |
13:41:03.49 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3984] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x0 |
13:41:03.49 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3984|: nassvc.exe |
13:41:03.49 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4024] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
13:41:03.49 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4024|: MsMpEng.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4044] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4044|: httpd.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4464] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4464|: mysqld.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5204] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5204|: DropboxUpdate.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6484] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6484|: GoogleCrashHandler64.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7992] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7992|: httpd.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8444] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8444|: tv_w32.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11244] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11244|: GoogleCrashHandler.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11644] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11644|: MicrosoftEdgeUpdate.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14088] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14088|: Teams.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15320] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15320|: gameinputsvc.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17744] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17744|: tv_x64.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20272] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20272|: Teams.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20800] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20800|: Teams.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22024] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22024|: Teams.exe |
13:41:03.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23172] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0 |
13:41:03.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23172|: GoogleUpdate.exe |
13:41:07.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13696] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x0 |
13:41:07.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13696|: docker-mutagen.exe |
13:41:07.50 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19552] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0 |
13:41:07.50 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19552|: com.docker.backend.exe |
13:41:19.58 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10556] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:41:19.58 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10556|: Teams.exe |
13:41:31.63 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5556] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0 |
13:41:31.63 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5556|: vpnkit-bridge.exe |
13:41:37.66 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [676] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0 |
13:41:37.66 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |676|: vpnkit.exe |
13:41:39.64 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23216] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0 |
13:41:39.64 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23216|: com.docker.proxy.exe |
13:43:12.164 | 5EBC | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:43:13.307 | 5EBC | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:44:16.166 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4352] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:44:16.166 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4352|: Teams.exe |
13:47:03.177 | 5EBC | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
13:49:51.192 | 5EBC | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
13:54:17.222 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12460] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:54:17.222 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12460|: Teams.exe |
13:58:18.271 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23040] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
13:58:18.271 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23040|: Teams.exe |
14:03:29.87 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13080] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:29.87 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13080|: Code.exe |
14:03:29.87 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22900] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:29.87 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22900|: Code.exe |
14:03:31.86 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15888] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:31.86 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15888|: Code.exe |
14:03:32.88 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13488] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:32.88 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13488|: Code.exe |
14:03:32.88 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21152] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:32.89 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21152|: Code.exe |
14:03:33.90 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17528] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:33.90 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17528|: Code.exe |
14:03:42.89 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6884] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:42.89 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6884|: Code.exe |
14:03:42.89 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16856] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:42.89 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16856|: Code.exe |
14:03:42.89 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19988] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:42.89 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19988|: Code.exe |
14:03:42.89 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22632] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
14:03:42.89 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22632|: Code.exe |
14:03:43.86 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11944] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
14:03:43.86 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11944|: rg.exe |
14:03:43.86 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12668] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
14:03:43.86 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12668|: rg.exe |
14:03:43.86 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14960] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
14:03:43.86 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14960|: rg.exe |
14:03:43.86 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15844] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5 |
14:03:43.86 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15844|: rg.exe |
14:14:39.781 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14256] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
14:14:39.781 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14256|: Teams.exe |
14:18:03.296 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
14:19:49.623 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1140] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
14:19:49.623 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1140|: node.exe |
14:19:49.623 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5112] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
14:19:49.623 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5112|: node.exe |
14:20:21.683 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9144] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
14:20:21.683 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9144|: Teams.exe |
14:39:48.423 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16788] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
14:39:48.424 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16788|: Teams.exe |
14:50:29.549 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23456] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
14:50:29.549 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23456|: Teams.exe |
14:54:38.653 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18672] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
14:54:38.653 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18672|: Teams.exe |
14:57:10.666 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12332] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
14:57:10.666 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12332|: Teams.exe |
15:02:11.686 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17176] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:02:11.686 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17176|: Teams.exe |
15:04:05.700 | 5EBC | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
15:07:00.749 | 5EBC | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
15:07:00.749 | 5EBC | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
15:08:20.748 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6956] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:08:20.748 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6956|: Teams.exe |
15:13:22.778 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12448] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:13:22.778 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12448|: Teams.exe |
15:18:02.834 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
15:19:54.846 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4836] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:19:54.847 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4836|: Teams.exe |
15:22:10.856 | 5EBC | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:24:57.865 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7120] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:24:57.865 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7120|: Teams.exe |
15:27:57.881 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24160] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:27:57.881 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24160|: Teams.exe |
15:33:59.5 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24340] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:33:59.5 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24340|: Teams.exe |
15:40:00.119 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22908] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:40:00.119 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22908|: Teams.exe |
15:46:00.223 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16160] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:46:00.223 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16160|: Teams.exe |
15:49:51.240 | 5EBC | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:50:40.259 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19612] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:50:40.259 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19612|: Teams.exe |
15:55:20.329 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7608] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
15:55:20.329 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7608|: Teams.exe |
16:00:38.378 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20652] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:00:38.378 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20652|: Teams.exe |
16:09:27.452 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16156] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:09:27.452 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16156|: Teams.exe |
16:15:28.534 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14568] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:15:28.534 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14568|: Teams.exe |
16:18:02.544 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:19:03.557 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16964] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:19:03.557 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16964|: Teams.exe |
16:29:50.639 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20792] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:29:50.639 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20792|: Teams.exe |
16:40:35.819 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11000] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:40:35.819 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11000|: Teams.exe |
16:45:07.873 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14800] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:45:07.873 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14800|: Teams.exe |
16:49:13.892 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8816] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:49:13.892 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8816|: Teams.exe |
16:55:43.904 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24172] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:55:43.904 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24172|: Teams.exe |
16:59:57.907 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14044] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:59:57.907 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14044|: Teams.exe |
17:03:36.926 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15924] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:03:36.926 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15924|: Teams.exe |
17:09:36.965 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18168] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:09:36.965 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18168|: Teams.exe |
17:18:02.946 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
17:25:55.999 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21696] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:25:55.999 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21696|: Teams.exe |
17:29:56.11 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19272] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:29:56.11 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19272|: Teams.exe |
17:34:37.6 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14632] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:34:37.6 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14632|: Teams.exe |
17:43:11.951 | 5EBC | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
17:44:36.970 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23568] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
17:44:36.970 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23568|: Teams.exe |
18:00:59.254 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16352] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:00:59.255 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16352|: Teams.exe |
18:05:00.283 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1820] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:05:00.283 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1820|: Teams.exe |
18:10:09.346 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19824] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:10:09.346 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19824|: Teams.exe |
18:10:47.346 | 5EBC | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
18:16:10.418 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14060] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:16:10.418 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14060|: Teams.exe |
18:18:03.448 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
18:22:10.508 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6960] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:22:10.508 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6960|: Teams.exe |
18:28:11.529 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23132] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:28:11.529 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23132|: Teams.exe |
18:33:07.777 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8628] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:33:07.777 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8628|: node.exe |
18:33:07.777 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22480] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:33:07.777 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22480|: node.exe |
18:34:12.829 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11516] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:34:12.829 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11516|: Teams.exe |
18:38:53.154 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14776] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:38:53.154 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14776|: Teams.exe |
18:49:34.518 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17208] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:49:34.518 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17208|: Teams.exe |
18:49:51.520 | 5EBC | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
19:00:49.609 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11328] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
19:00:49.609 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11328|: Teams.exe |
19:03:12.640 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
19:03:12.640 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
19:06:56.644 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1720] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
19:06:56.644 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1720|: Teams.exe |
19:10:56.646 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19532] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
19:10:56.646 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19532|: Teams.exe |
19:18:02.673 | 5EBC | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
19:22:11.717 | 5EBC | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
19:32:18.431 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23008] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
19:32:18.431 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23008|: Code.exe |
19:32:59.524 | 5EBC | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18836] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:32:59.524 | 5EBC | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18836|: Teams.exe |