TimeThreadLineFunctionMessage
12:34:01.86531DC361ftw1Loading (pid: 25620)
12:34:01.8651F08146ProcessHardwareRecorder::CommandThreadstarting recorder thread
12:34:01.86731DC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X34220000>6|2|1247870977
12:34:01.86731DC48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X3A1F0000>6|2|1247871464
12:34:01.92431DC172DXManager::DetectFound in 0
12:34:01.92431DC209Initialize::GetLocation@ 0X4F80|20352
12:34:01.92431DC209Initialize::GetLocation@ 0X69530|431408
12:34:01.92431DC209Initialize::GetLocation@ 0X20410|132112
12:34:01.92431DC209Initialize::GetLocation@ 0X1DE0|7648
12:34:01.92431DC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:34:01.92431DC209Initialize::GetLocation@ 0XFA158850|-99252144
12:34:01.92431DC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:34:01.92431DC209Initialize::GetLocation@ 0XFA15DE80|-99230080
12:34:01.92431DC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:34:01.92431DC209Initialize::GetLocation@ 0XFA15C5E0|-99236384
12:34:01.92431DC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:34:01.92431DC209Initialize::GetLocation@ 0XFA03A7F0|-100423696
12:34:01.93231DC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X25C10000>6|2|1247871464
12:34:01.95831DC129DXManager::DetectOK
12:34:01.97631DC186DXManager::DetectDone
12:34:01.97631DC215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
12:34:01.97731DC209Initialize::GetLocation@ 0X41000|266240
12:34:01.97731DC209Initialize::GetLocation@ 0X332C0|209600
12:34:01.97731DC209Initialize::GetLocation@ 0X3CB30|248624
12:34:01.97731DC209Initialize::GetLocation@ 0XB72C0|750272
12:34:01.97731DC209Initialize::GetLocation@ 0XB6E10|749072
12:34:01.97731DC209Initialize::GetLocation@ 0XA190|41360
12:34:01.97731DC209Initialize::GetLocation@ 0XB6EB0|749232
12:34:01.97731DC209Initialize::GetLocation@ 0X1AB50|109392
12:34:01.97731DC209Initialize::GetLocation@ 0X1D5A0|120224
12:34:01.97731DC209Initialize::GetLocation@ 0X25BD0|154576
12:34:01.97731DC209Initialize::GetLocation@ 0X113530|1127728
12:34:01.97731DC209Initialize::GetLocation@ 0X112FF0|1126384
12:34:01.97731DC209Initialize::GetLocation@ 0X1AA40|109120
12:34:01.97731DC209Initialize::GetLocation@ 0X1A950|108880
12:34:01.97731DC209Initialize::GetLocation@ 0XCB20|52000
12:34:01.97731DC209Initialize::GetLocation@ 0X47D50|294224
12:34:01.97731DC209Initialize::GetLocation@ 0X9D00|40192
12:34:01.97731DC209Initialize::GetLocation@ 0XCE4B0|844976
12:34:01.97731DC209Initialize::GetLocation@ 0XCEB80|846720
12:34:01.97731DC209Initialize::GetLocation@ 0X9D00|40192
12:34:01.97731DC209Initialize::GetLocation@ 0XCF670|849520
12:34:01.97731DC209Initialize::GetLocation@ 0XCFCD0|851152
12:34:01.99131DC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XDD100000>6|2|1247870977
12:34:02.6731DC83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
12:34:02.6831DC209Initialize::GetLocation@ 0X4040|16448
12:34:02.6831DC209Initialize::GetLocation@ 0X6410|25616
12:34:02.6831DC209Initialize::GetLocation@ 0X65C0|26048
12:34:02.7131DC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XDBE50000>6|2|1247870977
12:34:02.9531DC93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
12:34:02.9531DC110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
12:34:02.9631DC209Initialize::GetLocation@ 0XA5D0|42448
12:34:02.9631DC209Initialize::GetLocation@ 0XD4D0|54480
12:34:02.9631DC209Initialize::GetLocation@ 0XD290|53904
12:34:02.16531DC225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_25620 opened succesfuly
12:34:02.16631DC72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
12:34:02.16631DC256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_25620 close 2147483647 bytes
12:34:02.16631DC297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll]
12:34:02.25231DC385ftw1OWExplorer injected
12:34:02.853594051`anonymous-namespace'::CreateProviderInitialize provider: NET
12:34:02.8535940117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
12:34:02.853594054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
12:34:02.853594051`anonymous-namespace'::CreateProviderInitialize provider: GPU
12:36:32.9664980394ProcessInjector::HandleElevatedProcessFail injection to process [2652] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
12:36:32.9664980333ProcessInjector::HandlePendingProccesssFail to inject pending process |2652|: NVDisplay.Container.exe
12:36:32.9664980394ProcessInjector::HandleElevatedProcessFail injection to process [4972] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
12:36:32.9664980333ProcessInjector::HandlePendingProccesssFail to inject pending process |4972|: nvcontainer.exe
12:36:32.9664980394ProcessInjector::HandleElevatedProcessFail injection to process [23460] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
12:36:32.9664980333ProcessInjector::HandlePendingProccesssFail to inject pending process |23460|: MsMpEng.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [1452] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |1452|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [9084] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |9084|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [12916] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |12916|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [13532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |13532|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [18408] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |18408|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [18956] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |18956|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [20604] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |20604|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [22724] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |22724|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [24324] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |24324|: firefox.exe
12:36:33.9754980394ProcessInjector::HandleElevatedProcessFail injection to process [26164] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
12:36:33.9754980333ProcessInjector::HandlePendingProccesssFail to inject pending process |26164|: node.exe
12:38:08.6434980394ProcessInjector::HandleElevatedProcessFail injection to process [24460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:38:08.6434980333ProcessInjector::HandlePendingProccesssFail to inject pending process |24460|: firefox.exe
12:39:32.2764980394ProcessInjector::HandleElevatedProcessFail injection to process [19092] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:39:32.2764980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19092|: firefox.exe
12:43:22.1694980394ProcessInjector::HandleElevatedProcessFail injection to process [22548] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:43:22.1694980333ProcessInjector::HandlePendingProccesssFail to inject pending process |22548|: firefox.exe
12:48:52.3504980394ProcessInjector::HandleElevatedProcessFail injection to process [9012] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:48:52.3504980333ProcessInjector::HandlePendingProccesssFail to inject pending process |9012|: firefox.exe
12:50:27.2494980394ProcessInjector::HandleElevatedProcessFail injection to process [22168] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:50:27.2494980333ProcessInjector::HandlePendingProccesssFail to inject pending process |22168|: firefox.exe
12:54:32.7074980394ProcessInjector::HandleElevatedProcessFail injection to process [17824] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:54:32.7074980333ProcessInjector::HandlePendingProccesssFail to inject pending process |17824|: firefox.exe
13:03:44.1834980394ProcessInjector::HandleElevatedProcessFail injection to process [10456] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:03:44.1834980333ProcessInjector::HandlePendingProccesssFail to inject pending process |10456|: firefox.exe
13:04:19.5014980394ProcessInjector::HandleElevatedProcessFail injection to process [5488] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
13:04:19.5014980333ProcessInjector::HandlePendingProccesssFail to inject pending process |5488|: WhatsApp.exe
13:04:19.5014980394ProcessInjector::HandleElevatedProcessFail injection to process [15244] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
13:04:19.5014980333ProcessInjector::HandlePendingProccesssFail to inject pending process |15244|: WhatsApp.exe
13:04:21.5154980394ProcessInjector::HandleElevatedProcessFail injection to process [9760] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
13:04:21.5154980333ProcessInjector::HandlePendingProccesssFail to inject pending process |9760|: WhatsApp.exe
13:13:48.9564980394ProcessInjector::HandleElevatedProcessFail injection to process [23240] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:13:48.9564980333ProcessInjector::HandlePendingProccesssFail to inject pending process |23240|: firefox.exe
13:16:11.1694980394ProcessInjector::HandleElevatedProcessFail injection to process [5804] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
13:16:11.1694980333ProcessInjector::HandlePendingProccesssFail to inject pending process |5804|: node.exe
13:19:34.1734980394ProcessInjector::HandleElevatedProcessFail injection to process [13352] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:19:34.1734980333ProcessInjector::HandlePendingProccesssFail to inject pending process |13352|: firefox.exe
13:22:48.1104980394ProcessInjector::HandleElevatedProcessFail injection to process [25332] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:22:48.1104980333ProcessInjector::HandlePendingProccesssFail to inject pending process |25332|: firefox.exe
14:58:49.5714980394ProcessInjector::HandleElevatedProcessFail injection to process [16404] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
14:58:49.5714980333ProcessInjector::HandlePendingProccesssFail to inject pending process |16404|: node.exe
15:42:10.5144980394ProcessInjector::HandleElevatedProcessFail injection to process [4996] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
15:42:10.5144980333ProcessInjector::HandlePendingProccesssFail to inject pending process |4996|: firefox.exe
15:42:11.5394980394ProcessInjector::HandleElevatedProcessFail injection to process [10416] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
15:42:11.5394980333ProcessInjector::HandlePendingProccesssFail to inject pending process |10416|: firefox.exe
15:47:01.2114980421ProcessInjector::DoElevetedInjectionFailed to inject process [21528] 0x57
15:47:01.2114980377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [21528] [t: 14780 w_t_id: 14780]- ConEmuC64.exe (elevated True) 0x57
15:47:02.2214980421ProcessInjector::DoElevetedInjectionFailed to inject process [21528] 0x57
15:47:02.2214980394ProcessInjector::HandleElevatedProcessFail injection to process [21528] [t: 14780 w_t_id: 14780]- ConEmuC64.exe (elevated True) 0x57
15:47:02.2214980333ProcessInjector::HandlePendingProccesssFail to inject pending process |21528|: ConEmuC64.exe
15:52:43.4304980394ProcessInjector::HandleElevatedProcessFail injection to process [21632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
15:52:43.4304980333ProcessInjector::HandlePendingProccesssFail to inject pending process |21632|: firefox.exe
16:05:25.7724980394ProcessInjector::HandleElevatedProcessFail injection to process [3932] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
16:05:25.7724980333ProcessInjector::HandlePendingProccesssFail to inject pending process |3932|: software_reporter_tool.exe
16:05:25.7724980394ProcessInjector::HandleElevatedProcessFail injection to process [11028] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
16:05:25.7724980333ProcessInjector::HandlePendingProccesssFail to inject pending process |11028|: software_reporter_tool.exe
16:05:25.7724980394ProcessInjector::HandleElevatedProcessFail injection to process [21420] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
16:05:25.7724980333ProcessInjector::HandlePendingProccesssFail to inject pending process |21420|: software_reporter_tool.exe
17:09:28.7794980394ProcessInjector::HandleElevatedProcessFail injection to process [22444] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
17:09:28.7794980333ProcessInjector::HandlePendingProccesssFail to inject pending process |22444|: firefox.exe
17:15:43.3024980394ProcessInjector::HandleElevatedProcessFail injection to process [19252] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
17:15:43.3024980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19252|: firefox.exe
17:15:44.3004980394ProcessInjector::HandleElevatedProcessFail injection to process [24036] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
17:15:44.3004980333ProcessInjector::HandlePendingProccesssFail to inject pending process |24036|: firefox.exe
17:16:28.7104980394ProcessInjector::HandleElevatedProcessFail injection to process [19912] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
17:16:28.7104980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19912|: firefox.exe
17:24:58.3634980394ProcessInjector::HandleElevatedProcessFail injection to process [21684] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
17:24:58.3634980333ProcessInjector::HandlePendingProccesssFail to inject pending process |21684|: firefox.exe
17:31:52.3994980394ProcessInjector::HandleElevatedProcessFail injection to process [2184] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
17:31:52.3994980333ProcessInjector::HandlePendingProccesssFail to inject pending process |2184|: firefox.exe
18:29:34.3714980394ProcessInjector::HandleElevatedProcessFail injection to process [7384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:29:34.3714980333ProcessInjector::HandlePendingProccesssFail to inject pending process |7384|: firefox.exe
18:31:01.2054980394ProcessInjector::HandleElevatedProcessFail injection to process [1048] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:31:01.2054980333ProcessInjector::HandlePendingProccesssFail to inject pending process |1048|: firefox.exe
18:36:32.2594980394ProcessInjector::HandleElevatedProcessFail injection to process [8452] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
18:36:32.2594980333ProcessInjector::HandlePendingProccesssFail to inject pending process |8452|: firefox.exe
18:36:36.2854980394ProcessInjector::HandleElevatedProcessFail injection to process [9208] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
18:36:36.2864980333ProcessInjector::HandlePendingProccesssFail to inject pending process |9208|: firefox.exe
18:45:24.2994980394ProcessInjector::HandleElevatedProcessFail injection to process [9872] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x578
18:45:24.2994980333ProcessInjector::HandlePendingProccesssFail to inject pending process |9872|: openvpn.exe
18:46:05.7144980394ProcessInjector::HandleElevatedProcessFail injection to process [888] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
18:46:05.7144980333ProcessInjector::HandlePendingProccesssFail to inject pending process |888|: fzsftp.exe
18:47:12.3284980394ProcessInjector::HandleElevatedProcessFail injection to process [3948] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f
18:47:12.3284980333ProcessInjector::HandlePendingProccesssFail to inject pending process |3948|: fzsftp.exe
18:48:57.3104980394ProcessInjector::HandleElevatedProcessFail injection to process [11720] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
18:48:57.3104980333ProcessInjector::HandlePendingProccesssFail to inject pending process |11720|: init
18:48:57.3104980394ProcessInjector::HandleElevatedProcessFail injection to process [13272] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
18:48:57.3104980333ProcessInjector::HandlePendingProccesssFail to inject pending process |13272|: init
18:48:57.3104980394ProcessInjector::HandleElevatedProcessFail injection to process [24264] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
18:48:57.3104980333ProcessInjector::HandlePendingProccesssFail to inject pending process |24264|: bash
18:50:12.114980394ProcessInjector::HandleElevatedProcessFail injection to process [19980] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:50:12.114980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19980|: firefox.exe
18:54:47.5064980394ProcessInjector::HandleElevatedProcessFail injection to process [15516] [t: 0 w_t_id: 0]- git-bash.exe (elevated True) 0x1f
18:54:47.5064980333ProcessInjector::HandlePendingProccesssFail to inject pending process |15516|: git-bash.exe
18:54:47.5064980394ProcessInjector::HandleElevatedProcessFail injection to process [19788] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x1f
18:54:47.5064980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19788|: bash.exe
18:55:40.424980394ProcessInjector::HandleElevatedProcessFail injection to process [6496] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
18:55:40.424980333ProcessInjector::HandlePendingProccesssFail to inject pending process |6496|: node.exe
19:28:36.534980394ProcessInjector::HandleElevatedProcessFail injection to process [25636] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x1f
19:28:36.534980333ProcessInjector::HandlePendingProccesssFail to inject pending process |25636|: WhatsApp.exe
20:18:35.2044980394ProcessInjector::HandleElevatedProcessFail injection to process [2480] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:18:35.2044980333ProcessInjector::HandlePendingProccesssFail to inject pending process |2480|: firefox.exe
20:19:17.5924980394ProcessInjector::HandleElevatedProcessFail injection to process [11544] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f
20:19:17.5924980333ProcessInjector::HandlePendingProccesssFail to inject pending process |11544|: fzsftp.exe
20:20:57.5354980394ProcessInjector::HandleElevatedProcessFail injection to process [4712] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:20:57.5354980333ProcessInjector::HandlePendingProccesssFail to inject pending process |4712|: firefox.exe
20:24:33.5674980394ProcessInjector::HandleElevatedProcessFail injection to process [15960] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:24:33.5674980333ProcessInjector::HandlePendingProccesssFail to inject pending process |15960|: firefox.exe
20:27:21.1254980394ProcessInjector::HandleElevatedProcessFail injection to process [17412] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:27:21.1254980333ProcessInjector::HandlePendingProccesssFail to inject pending process |17412|: firefox.exe
20:29:17.1794980394ProcessInjector::HandleElevatedProcessFail injection to process [16200] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:29:17.1794980333ProcessInjector::HandlePendingProccesssFail to inject pending process |16200|: firefox.exe
21:20:30.2114980394ProcessInjector::HandleElevatedProcessFail injection to process [23024] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:20:30.2114980333ProcessInjector::HandlePendingProccesssFail to inject pending process |23024|: firefox.exe
21:20:32.2394980394ProcessInjector::HandleElevatedProcessFail injection to process [19904] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:20:32.2394980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19904|: firefox.exe
21:21:08.5904980394ProcessInjector::HandleElevatedProcessFail injection to process [16572] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:21:08.5904980333ProcessInjector::HandlePendingProccesssFail to inject pending process |16572|: firefox.exe
21:22:10.354980394ProcessInjector::HandleElevatedProcessFail injection to process [25424] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
21:22:10.354980333ProcessInjector::HandlePendingProccesssFail to inject pending process |25424|: node.exe
21:22:24.1374980394ProcessInjector::HandleElevatedProcessFail injection to process [20612] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:24.1374980333ProcessInjector::HandlePendingProccesssFail to inject pending process |20612|: Code.exe
21:22:24.1374980394ProcessInjector::HandleElevatedProcessFail injection to process [24852] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:24.1374980333ProcessInjector::HandlePendingProccesssFail to inject pending process |24852|: Code.exe
21:22:26.1534980394ProcessInjector::HandleElevatedProcessFail injection to process [12804] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:26.1534980333ProcessInjector::HandlePendingProccesssFail to inject pending process |12804|: Code.exe
21:22:27.1694980394ProcessInjector::HandleElevatedProcessFail injection to process [12968] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:27.1694980333ProcessInjector::HandlePendingProccesssFail to inject pending process |12968|: Code.exe
21:22:28.1764980394ProcessInjector::HandleElevatedProcessFail injection to process [1004] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:28.1764980333ProcessInjector::HandlePendingProccesssFail to inject pending process |1004|: Code.exe
21:22:28.1764980394ProcessInjector::HandleElevatedProcessFail injection to process [5436] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:28.1764980333ProcessInjector::HandlePendingProccesssFail to inject pending process |5436|: Code.exe
21:22:28.1764980394ProcessInjector::HandleElevatedProcessFail injection to process [13860] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:28.1764980333ProcessInjector::HandlePendingProccesssFail to inject pending process |13860|: Code.exe
21:22:32.1974980394ProcessInjector::HandleElevatedProcessFail injection to process [20056] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:22:32.1974980333ProcessInjector::HandlePendingProccesssFail to inject pending process |20056|: Code.exe
21:31:30.9874980394ProcessInjector::HandleElevatedProcessFail injection to process [10344] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
21:31:30.9874980333ProcessInjector::HandlePendingProccesssFail to inject pending process |10344|: bash
21:31:30.9874980394ProcessInjector::HandleElevatedProcessFail injection to process [18384] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
21:31:30.9874980333ProcessInjector::HandlePendingProccesssFail to inject pending process |18384|: init
21:31:37.484980394ProcessInjector::HandleElevatedProcessFail injection to process [19112] [t: 0 w_t_id: 0]- redis-cli (elevated True) 0x1f
21:31:37.484980333ProcessInjector::HandlePendingProccesssFail to inject pending process |19112|: redis-cli
21:58:11.214980394ProcessInjector::HandleElevatedProcessFail injection to process [11532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
21:58:11.214980333ProcessInjector::HandlePendingProccesssFail to inject pending process |11532|: firefox.exe
22:16:19.2724980421ProcessInjector::DoElevetedInjectionFailed to inject process [7600] 0x57
22:16:19.2724980377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [7600] [t: 24940 w_t_id: 24940]- conhost.exe (elevated True) 0x57
22:16:20.2044980421ProcessInjector::DoElevetedInjectionFailed to inject process [7600] 0x57
22:16:20.2044980394ProcessInjector::HandleElevatedProcessFail injection to process [7600] [t: 24940 w_t_id: 24940]- conhost.exe (elevated True) 0x57
22:16:20.2054980333ProcessInjector::HandlePendingProccesssFail to inject pending process |7600|: conhost.exe
22:19:13.5654980421ProcessInjector::DoElevetedInjectionFailed to inject process [9920] 0x57
22:19:13.5654980377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [9920] [t: 14792 w_t_id: 14792]- conhost.exe (elevated True) 0x57
22:19:14.5324980421ProcessInjector::DoElevetedInjectionFailed to inject process [9920] 0x57
22:19:14.5324980394ProcessInjector::HandleElevatedProcessFail injection to process [9920] [t: 14792 w_t_id: 14792]- conhost.exe (elevated True) 0x57
22:19:14.5324980333ProcessInjector::HandlePendingProccesssFail to inject pending process |9920|: conhost.exe
22:21:34.8124980421ProcessInjector::DoElevetedInjectionFailed to inject process [25864] 0x57
22:21:34.8124980377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [25864] [t: 15060 w_t_id: 15060]- conhost.exe (elevated True) 0x57
22:21:35.7494980421ProcessInjector::DoElevetedInjectionFailed to inject process [25864] 0x57
22:21:35.7504980394ProcessInjector::HandleElevatedProcessFail injection to process [25864] [t: 15060 w_t_id: 15060]- conhost.exe (elevated True) 0x57
22:21:35.7504980333ProcessInjector::HandlePendingProccesssFail to inject pending process |25864|: conhost.exe
22:30:50.4444980394ProcessInjector::HandleElevatedProcessFail injection to process [3192] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
22:30:50.4444980333ProcessInjector::HandlePendingProccesssFail to inject pending process |3192|: Code.exe