Time | Thread | Line | Function | Message |
12:41:49.826 | 3258 | 361 | ftw1 | Loading (pid: 15480) |
12:41:49.826 | 5F64 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
12:41:49.827 | 3258 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X34220000>6|2|1247870977 |
12:41:49.827 | 3258 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X3A1F0000>6|2|1247871464 |
12:41:49.868 | 3258 | 172 | DXManager::Detect | Found in 0 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0X69530|431408 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0X20410|132112 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
12:41:49.868 | 3258 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0XFA158850|-99252144 |
12:41:49.868 | 3258 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0XFA15DE80|-99230080 |
12:41:49.868 | 3258 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0XFA15C5E0|-99236384 |
12:41:49.868 | 3258 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:41:49.868 | 3258 | 209 | Initialize::GetLocation | @ 0XFA03A7F0|-100423696 |
12:41:49.874 | 3258 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X262F0000>6|2|1247871464 |
12:41:49.898 | 3258 | 129 | DXManager::Detect | OK |
12:41:49.912 | 3258 | 186 | DXManager::Detect | Done |
12:41:49.913 | 3258 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X41000|266240 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X332C0|209600 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X3CB30|248624 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XB72C0|750272 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XB6E10|749072 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XA190|41360 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XB6EB0|749232 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X1AB50|109392 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X1D5A0|120224 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X25BD0|154576 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X113530|1127728 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X112FF0|1126384 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X1AA40|109120 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X1A950|108880 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XCB20|52000 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X47D50|294224 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X9D00|40192 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XCE4B0|844976 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XCEB80|846720 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0X9D00|40192 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XCF670|849520 |
12:41:49.913 | 3258 | 209 | Initialize::GetLocation | @ 0XCFCD0|851152 |
12:41:49.926 | 3258 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0XE0540000>6|2|1247870977 |
12:41:49.979 | 3258 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
12:41:49.979 | 3258 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
12:41:49.979 | 3258 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
12:41:49.979 | 3258 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
12:41:49.980 | 3258 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0XDD700000>6|2|1247870977 |
12:41:49.996 | 3258 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
12:41:49.996 | 3258 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
12:41:49.996 | 3258 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
12:41:49.996 | 3258 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
12:41:49.996 | 3258 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
12:41:50.54 | 3258 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_80_3_15480 opened succesfuly |
12:41:50.54 | 3258 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
12:41:50.54 | 3258 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_80_3_15480 close 2147483647 bytes |
12:41:50.54 | 3258 | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll] |
12:41:50.122 | 3258 | 385 | ftw1 | OWExplorer injected |
12:41:50.685 | 4B74 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
12:41:50.685 | 4B74 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
12:41:50.685 | 4B74 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
12:41:50.685 | 4B74 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
12:41:52.137 | 5028 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [16944] 0x57 |
12:41:52.137 | 5028 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [16944] [t: 22708 w_t_id: 22708]- OverwolfLauncher.exe (elevated True) 0x57 |
12:41:52.140 | 5028 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [16944] 0x57 |
12:41:52.140 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16944] [t: 22708 w_t_id: 22708]- OverwolfLauncher.exe (elevated True) 0x57 |
12:41:52.140 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16944|: OverwolfLauncher.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2652] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2652|: NVDisplay.Container.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2960] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2960|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4384|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4600] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4600|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4972] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4972|: nvcontainer.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5360] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5360|: MsMpEng.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5592] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5592|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9528] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9528|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10048] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10048|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12764] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12764|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16340] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16340|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20124] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20124|: firefox.exe |
12:44:21.401 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25296] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:21.401 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25296|: firefox.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3936] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3936|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4064] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4064|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8444] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8444|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10036] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10036|: firefox.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16348] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16348|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17320] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17320|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17612] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17612|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17668] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17668|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18488] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18488|: Code.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19024] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19024|: node.exe |
12:44:22.397 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25128] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
12:44:22.397 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25128|: Code.exe |
13:36:04.197 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2356] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
13:36:04.197 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2356|: Code.exe |
13:39:37.67 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10832] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
13:39:37.67 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10832|: Code.exe |
13:42:53.822 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18444] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
13:42:53.822 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18444|: Code.exe |
13:44:15.450 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24208] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f |
13:44:15.450 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24208|: node.exe |
13:45:27.70 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4732] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5a4 |
13:45:27.70 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4732|: node.exe |
15:36:31.595 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
15:36:31.595 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20132|: firefox.exe |
15:36:57.888 | 5028 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [15152] 0x57 |
15:36:57.889 | 5028 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [15152] [t: 17596 w_t_id: 17596]- conhost.exe (elevated True) 0x57 |
15:36:58.830 | 5028 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [15152] 0x57 |
15:36:58.830 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15152] [t: 17596 w_t_id: 17596]- conhost.exe (elevated True) 0x57 |
15:36:58.830 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15152|: conhost.exe |
15:39:45.496 | 5028 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [19484] 0x57 |
15:39:45.496 | 5028 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [19484] [t: 7464 w_t_id: 7464]- conhost.exe (elevated True) 0x57 |
15:39:46.417 | 5028 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [19484] 0x57 |
15:39:46.417 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19484] [t: 7464 w_t_id: 7464]- conhost.exe (elevated True) 0x57 |
15:39:46.417 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19484|: conhost.exe |
15:45:16.702 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20304] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
15:45:16.703 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20304|: node.exe |
16:12:14.193 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18748] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
16:12:14.193 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18748|: Code.exe |
16:41:41.57 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15564] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0 |
16:41:41.57 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15564|: fzsftp.exe |
16:41:47.111 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24976] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:41:47.111 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24976|: fzsftp.exe |
16:41:58.199 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11040] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:41:58.199 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11040|: fzsftp.exe |
16:42:08.293 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17464] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:08.293 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17464|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2372] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2372|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3020] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3020|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8528] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8528|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10416] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10416|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10456] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10456|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13028] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13028|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22256] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22256|: fzsftp.exe |
16:42:20.380 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23472] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
16:42:20.380 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23472|: fzsftp.exe |
16:45:28.27 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20760] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
16:45:28.27 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20760|: init |
16:45:28.27 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20788] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
16:45:28.27 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20788|: init |
16:45:28.27 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25284] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f |
16:45:28.27 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25284|: bash |
16:45:44.126 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3824] [t: 0 w_t_id: 0]- gzip (elevated True) 0x1f |
16:45:44.126 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3824|: gzip |
16:45:44.126 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6668] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
16:45:44.126 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6668|: init |
16:45:44.126 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11024] [t: 0 w_t_id: 0]- mysql.exe (elevated True) 0x1f |
16:45:44.126 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11024|: mysql.exe |
16:49:28.27 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16264] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f |
16:49:28.27 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16264|: fzsftp.exe |
16:55:19.865 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4768] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f |
16:55:19.865 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4768|: node.exe |
17:17:49.786 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9284] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
17:17:49.786 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9284|: init |
17:17:49.786 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13768] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f |
17:17:49.786 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13768|: bash |
17:19:46.601 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18936] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f |
17:19:46.601 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18936|: node.exe |
19:04:09.144 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24136] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f |
19:04:09.144 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24136|: openvpn.exe |
19:04:35.423 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16288] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f |
19:04:35.423 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16288|: bash |
19:04:45.520 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9380] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f |
19:04:45.520 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9380|: ssh |
19:04:45.520 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11544] [t: 0 w_t_id: 0]- rsync (elevated True) 0x1f |
19:04:45.520 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11544|: rsync |
19:20:31.35 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23460] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f |
19:20:31.35 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23460|: MsMpEng.exe |
19:30:44.348 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17324] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x578 |
19:30:44.348 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17324|: node.exe |
19:30:44.348 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19956] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x578 |
19:30:44.348 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19956|: node.exe |
19:30:45.351 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23768] [t: 0 w_t_id: 0]- electron.exe (elevated True) 0x578 |
19:30:45.351 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23768|: electron.exe |
19:35:29.881 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12272] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578 |
19:35:29.881 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12272|: firefox.exe |
19:41:55.399 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [272] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
19:41:55.399 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |272|: node.exe |
19:41:55.399 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18712] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
19:41:55.399 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18712|: node.exe |
19:41:56.414 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5596] [t: 0 w_t_id: 0]- electron.exe (elevated True) 0x0 |
19:41:56.414 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5596|: electron.exe |
19:41:56.414 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18900] [t: 0 w_t_id: 0]- electron.exe (elevated True) 0x0 |
19:41:56.414 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18900|: electron.exe |
19:44:32.871 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15380] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
19:44:32.871 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15380|: software_reporter_tool.exe |
19:44:32.871 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20544] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
19:44:32.871 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20544|: software_reporter_tool.exe |
19:44:33.885 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17392] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
19:44:33.885 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17392|: software_reporter_tool.exe |
19:49:28.637 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16164] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
19:49:28.637 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16164|: firefox.exe |
19:58:08.86 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11940] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
19:58:08.86 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11940|: Code.exe |
21:00:16.303 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22768] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
21:00:16.303 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22768|: firefox.exe |
21:21:51.255 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
21:21:51.255 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24532|: firefox.exe |
21:21:52.254 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11188] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
21:21:52.254 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11188|: firefox.exe |
21:21:54.277 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24840] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x5 |
21:21:54.277 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24840|: plugin-container.exe |
22:22:25.449 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20804] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
22:22:25.449 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20804|: Code.exe |
22:39:31.286 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17300] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
22:39:31.286 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17300|: firefox.exe |
22:55:18.653 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15656] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
22:55:18.653 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15656|: firefox.exe |
23:50:59.285 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11200] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
23:50:59.285 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11200|: Code.exe |
00:01:50.761 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10992] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
00:01:50.761 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10992|: firefox.exe |
00:01:52.787 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24928] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
00:01:52.787 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24928|: firefox.exe |
00:46:23.371 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25888] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
00:46:23.371 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25888|: firefox.exe |
00:46:24.374 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6308] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
00:46:24.374 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6308|: firefox.exe |
01:00:18.978 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17896] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578 |
01:00:18.978 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17896|: firefox.exe |
01:20:42.876 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20804] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578 |
01:20:42.876 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20804|: firefox.exe |
01:32:14.637 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21364] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f |
01:32:14.637 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21364|: openvpn.exe |
01:33:00.956 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9748] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
01:33:00.956 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9748|: firefox.exe |
01:33:01.968 | 5028 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21400] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
01:33:01.968 | 5028 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21400|: firefox.exe |
02:34:01.536 | 3258 | 66 | ProcessesMonitor::Stop | stopping PM... |
02:34:01.537 | 4B74 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
02:34:01.540 | 3258 | 479 | ProcessInjector::Unhook | unhook running process |