TimeThreadLineFunctionMessage
18:13:21.7611850361ftw1Loading (pid: 4620)
18:13:21.7615010146ProcessHardwareRecorder::CommandThreadstarting recorder thread
18:13:21.762185048Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X34220000>6|2|1247870977
18:13:21.763185048Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X3A1F0000>6|2|1247871464
18:13:21.8071850172DXManager::DetectFound in 0
18:13:21.8081850209Initialize::GetLocation@ 0X4F80|20352
18:13:21.8081850209Initialize::GetLocation@ 0X69530|431408
18:13:21.8081850209Initialize::GetLocation@ 0X20410|132112
18:13:21.8081850209Initialize::GetLocation@ 0X1DE0|7648
18:13:21.8081850111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
18:13:21.8081850209Initialize::GetLocation@ 0XFA158850|-99252144
18:13:21.8081850111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
18:13:21.8081850209Initialize::GetLocation@ 0XFA15DE80|-99230080
18:13:21.8081850111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
18:13:21.8081850209Initialize::GetLocation@ 0XFA15C5E0|-99236384
18:13:21.8081850111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
18:13:21.8081850209Initialize::GetLocation@ 0XFA03A7F0|-100423696
18:13:21.816185048Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X26BA0000>6|2|1247871464
18:13:21.8431850129DXManager::DetectOK
18:13:21.8581850186DXManager::DetectDone
18:13:21.8581850215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
18:13:21.8591850209Initialize::GetLocation@ 0X41000|266240
18:13:21.8591850209Initialize::GetLocation@ 0X332C0|209600
18:13:21.8591850209Initialize::GetLocation@ 0X3CB30|248624
18:13:21.8591850209Initialize::GetLocation@ 0XB72C0|750272
18:13:21.8591850209Initialize::GetLocation@ 0XB6E10|749072
18:13:21.8591850209Initialize::GetLocation@ 0XA190|41360
18:13:21.8591850209Initialize::GetLocation@ 0XB6EB0|749232
18:13:21.8591850209Initialize::GetLocation@ 0X1AB50|109392
18:13:21.8591850209Initialize::GetLocation@ 0X1D5A0|120224
18:13:21.8591850209Initialize::GetLocation@ 0X25BD0|154576
18:13:21.8591850209Initialize::GetLocation@ 0X113530|1127728
18:13:21.8591850209Initialize::GetLocation@ 0X112FF0|1126384
18:13:21.8591850209Initialize::GetLocation@ 0X1AA40|109120
18:13:21.8591850209Initialize::GetLocation@ 0X1A950|108880
18:13:21.8591850209Initialize::GetLocation@ 0XCB20|52000
18:13:21.8591850209Initialize::GetLocation@ 0X47D50|294224
18:13:21.8591850209Initialize::GetLocation@ 0X9D00|40192
18:13:21.8591850209Initialize::GetLocation@ 0XCE4B0|844976
18:13:21.8591850209Initialize::GetLocation@ 0XCEB80|846720
18:13:21.8591850209Initialize::GetLocation@ 0X9D00|40192
18:13:21.8591850209Initialize::GetLocation@ 0XCF670|849520
18:13:21.8591850209Initialize::GetLocation@ 0XCFCD0|851152
18:13:21.873185048Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XFAEF0000>6|2|1247870977
18:13:21.919185083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
18:13:21.9191850209Initialize::GetLocation@ 0X4040|16448
18:13:21.9191850209Initialize::GetLocation@ 0X6410|25616
18:13:21.9191850209Initialize::GetLocation@ 0X65C0|26048
18:13:21.944185048Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XF2520000>6|2|1247870977
18:13:21.959185093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
18:13:21.9591850110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
18:13:21.9601850209Initialize::GetLocation@ 0XA5D0|42448
18:13:21.9601850209Initialize::GetLocation@ 0XD4D0|54480
18:13:21.9601850209Initialize::GetLocation@ 0XD290|53904
18:13:22.131850225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_4620 opened succesfuly
18:13:22.13185072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
18:13:22.131850256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_4620 close 2147483647 bytes
18:13:22.131850297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll]
18:13:22.821850385ftw1OWExplorer injected
18:13:22.6111FF051`anonymous-namespace'::CreateProviderInitialize provider: NET
18:13:22.6111FF0117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
18:13:22.6111FF054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
18:13:22.6111FF051`anonymous-namespace'::CreateProviderInitialize provider: GPU
18:13:24.342724421ProcessInjector::DoElevetedInjectionFailed to inject process [2572] 0x57
18:13:24.342724377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [2572] [t: 5144 w_t_id: 5144]- OverwolfLauncher.exe (elevated True) 0x57
18:13:24.392724421ProcessInjector::DoElevetedInjectionFailed to inject process [2572] 0x57
18:13:24.392724394ProcessInjector::HandleElevatedProcessFail injection to process [2572] [t: 5144 w_t_id: 5144]- OverwolfLauncher.exe (elevated True) 0x57
18:13:24.392724333ProcessInjector::HandlePendingProccesssFail to inject pending process |2572|: OverwolfLauncher.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [2420] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |2420|: node.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [2652] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |2652|: NVDisplay.Container.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [3452] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |3452|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [4972] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |4972|: nvcontainer.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [5360] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |5360|: MsMpEng.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [6376] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |6376|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [10164] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |10164|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [12448] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |12448|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [14864] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |14864|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [16204] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |16204|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [18792] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |18792|: firefox.exe
18:15:53.4682724394ProcessInjector::HandleElevatedProcessFail injection to process [23144] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:53.4682724333ProcessInjector::HandlePendingProccesssFail to inject pending process |23144|: firefox.exe
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [1916] [t: 0 w_t_id: 0]- init (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |1916|: init
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [10004] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |10004|: fzsftp.exe
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [10776] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |10776|: firefox.exe
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [11668] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |11668|: fzsftp.exe
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [17120] [t: 0 w_t_id: 0]- ssh (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |17120|: ssh
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [19132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19132|: firefox.exe
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [20576] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |20576|: firefox.exe
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [21840] [t: 0 w_t_id: 0]- bash (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21840|: bash
18:15:54.4822724394ProcessInjector::HandleElevatedProcessFail injection to process [22004] [t: 0 w_t_id: 0]- init (elevated True) 0x57
18:15:54.4822724333ProcessInjector::HandlePendingProccesssFail to inject pending process |22004|: init
18:18:59.1932724394ProcessInjector::HandleElevatedProcessFail injection to process [18240] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x57
18:18:59.1932724333ProcessInjector::HandlePendingProccesssFail to inject pending process |18240|: fzsftp.exe
18:19:05.2382724394ProcessInjector::HandleElevatedProcessFail injection to process [6536] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x57
18:19:05.2382724333ProcessInjector::HandlePendingProccesssFail to inject pending process |6536|: fzsftp.exe
18:21:30.2652724394ProcessInjector::HandleElevatedProcessFail injection to process [17932] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x57
18:21:30.2652724333ProcessInjector::HandlePendingProccesssFail to inject pending process |17932|: java.exe
18:30:49.4122724394ProcessInjector::HandleElevatedProcessFail injection to process [17316] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
18:30:49.4122724333ProcessInjector::HandlePendingProccesssFail to inject pending process |17316|: fzsftp.exe
18:31:09.6142724394ProcessInjector::HandleElevatedProcessFail injection to process [11048] [t: 0 w_t_id: 0]- init (elevated True) 0x0
18:31:09.6142724333ProcessInjector::HandlePendingProccesssFail to inject pending process |11048|: init
18:31:09.6142724394ProcessInjector::HandleElevatedProcessFail injection to process [21012] [t: 0 w_t_id: 0]- bash (elevated True) 0x0
18:31:09.6142724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21012|: bash
18:32:51.4872724394ProcessInjector::HandleElevatedProcessFail injection to process [23464] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:32:51.4872724333ProcessInjector::HandlePendingProccesssFail to inject pending process |23464|: firefox.exe
18:32:52.4942724394ProcessInjector::HandleElevatedProcessFail injection to process [12620] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:32:52.4942724333ProcessInjector::HandlePendingProccesssFail to inject pending process |12620|: firefox.exe
18:35:42.422724394ProcessInjector::HandleElevatedProcessFail injection to process [3972] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
18:35:42.422724333ProcessInjector::HandlePendingProccesssFail to inject pending process |3972|: init
18:35:42.422724394ProcessInjector::HandleElevatedProcessFail injection to process [20416] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
18:35:42.422724333ProcessInjector::HandlePendingProccesssFail to inject pending process |20416|: bash
18:43:39.2142724394ProcessInjector::HandleElevatedProcessFail injection to process [19232] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f
18:43:39.2142724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19232|: fzsftp.exe
18:44:11.5062724394ProcessInjector::HandleElevatedProcessFail injection to process [13460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:44:11.5062724333ProcessInjector::HandlePendingProccesssFail to inject pending process |13460|: firefox.exe
18:44:12.5112724394ProcessInjector::HandleElevatedProcessFail injection to process [11788] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:44:12.5112724333ProcessInjector::HandlePendingProccesssFail to inject pending process |11788|: firefox.exe
18:58:01.2862724394ProcessInjector::HandleElevatedProcessFail injection to process [23360] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:58:01.2862724333ProcessInjector::HandlePendingProccesssFail to inject pending process |23360|: firefox.exe
19:02:03.5512724394ProcessInjector::HandleElevatedProcessFail injection to process [21012] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x1f
19:02:03.5522724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21012|: java.exe
19:16:17.292724394ProcessInjector::HandleElevatedProcessFail injection to process [5684] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
19:16:17.292724333ProcessInjector::HandlePendingProccesssFail to inject pending process |5684|: firefox.exe
20:07:56.1202724394ProcessInjector::HandleElevatedProcessFail injection to process [19196] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:07:56.1202724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19196|: firefox.exe
20:07:57.1242724394ProcessInjector::HandleElevatedProcessFail injection to process [8452] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
20:07:57.1242724333ProcessInjector::HandlePendingProccesssFail to inject pending process |8452|: firefox.exe
20:08:34.3702724394ProcessInjector::HandleElevatedProcessFail injection to process [17044] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x1f
20:08:34.3702724333ProcessInjector::HandlePendingProccesssFail to inject pending process |17044|: plugin-container.exe
20:37:29.2312724394ProcessInjector::HandleElevatedProcessFail injection to process [19088] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
20:37:29.2312724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19088|: firefox.exe
20:52:33.1912724394ProcessInjector::HandleElevatedProcessFail injection to process [4264] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
20:52:33.1912724333ProcessInjector::HandlePendingProccesssFail to inject pending process |4264|: firefox.exe
21:07:56.4552724394ProcessInjector::HandleElevatedProcessFail injection to process [20500] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:07:56.4552724333ProcessInjector::HandlePendingProccesssFail to inject pending process |20500|: firefox.exe
21:12:21.232724394ProcessInjector::HandleElevatedProcessFail injection to process [5484] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
21:12:21.232724333ProcessInjector::HandlePendingProccesssFail to inject pending process |5484|: ssh
21:41:26.6472724394ProcessInjector::HandleElevatedProcessFail injection to process [19268] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:41:26.6472724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19268|: firefox.exe
21:44:28.8922724394ProcessInjector::HandleElevatedProcessFail injection to process [12900] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
21:44:28.8922724333ProcessInjector::HandlePendingProccesssFail to inject pending process |12900|: bash
21:44:28.8922724394ProcessInjector::HandleElevatedProcessFail injection to process [23424] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
21:44:28.8922724333ProcessInjector::HandlePendingProccesssFail to inject pending process |23424|: init
21:44:45.142724394ProcessInjector::HandleElevatedProcessFail injection to process [9816] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
21:44:45.142724333ProcessInjector::HandlePendingProccesssFail to inject pending process |9816|: ssh
21:46:15.6232724394ProcessInjector::HandleElevatedProcessFail injection to process [4392] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
21:46:15.6232724333ProcessInjector::HandlePendingProccesssFail to inject pending process |4392|: init
21:46:15.6232724394ProcessInjector::HandleElevatedProcessFail injection to process [19348] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
21:46:15.6232724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19348|: bash
21:46:18.6472724394ProcessInjector::HandleElevatedProcessFail injection to process [9872] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
21:46:18.6472724333ProcessInjector::HandlePendingProccesssFail to inject pending process |9872|: ssh
21:49:29.9422724394ProcessInjector::HandleElevatedProcessFail injection to process [3312] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
21:49:29.9422724333ProcessInjector::HandlePendingProccesssFail to inject pending process |3312|: firefox.exe
21:53:47.5572724394ProcessInjector::HandleElevatedProcessFail injection to process [11752] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
21:53:47.5572724333ProcessInjector::HandlePendingProccesssFail to inject pending process |11752|: firefox.exe
22:02:52.3602724394ProcessInjector::HandleElevatedProcessFail injection to process [6100] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
22:02:52.3602724333ProcessInjector::HandlePendingProccesssFail to inject pending process |6100|: firefox.exe
22:06:39.1022724394ProcessInjector::HandleElevatedProcessFail injection to process [10004] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
22:06:39.1022724333ProcessInjector::HandlePendingProccesssFail to inject pending process |10004|: firefox.exe
22:06:40.1162724394ProcessInjector::HandleElevatedProcessFail injection to process [16248] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
22:06:40.1162724333ProcessInjector::HandlePendingProccesssFail to inject pending process |16248|: firefox.exe
22:22:00.7692724394ProcessInjector::HandleElevatedProcessFail injection to process [13560] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
22:22:00.7692724333ProcessInjector::HandlePendingProccesssFail to inject pending process |13560|: firefox.exe
22:22:02.8112724394ProcessInjector::HandleElevatedProcessFail injection to process [13748] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
22:22:02.8112724333ProcessInjector::HandlePendingProccesssFail to inject pending process |13748|: firefox.exe
22:55:53.9012724394ProcessInjector::HandleElevatedProcessFail injection to process [17496] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
22:55:53.9012724333ProcessInjector::HandlePendingProccesssFail to inject pending process |17496|: firefox.exe
23:20:15.892724394ProcessInjector::HandleElevatedProcessFail injection to process [12260] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
23:20:15.902724333ProcessInjector::HandlePendingProccesssFail to inject pending process |12260|: firefox.exe
23:26:55.9312724394ProcessInjector::HandleElevatedProcessFail injection to process [4732] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f
23:26:55.9312724333ProcessInjector::HandlePendingProccesssFail to inject pending process |4732|: openvpn.exe
23:27:05.9572724394ProcessInjector::HandleElevatedProcessFail injection to process [21004] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
23:27:05.9572724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21004|: bash
23:27:05.9572724394ProcessInjector::HandleElevatedProcessFail injection to process [22624] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
23:27:05.9572724333ProcessInjector::HandlePendingProccesssFail to inject pending process |22624|: init
23:27:16.342724394ProcessInjector::HandleElevatedProcessFail injection to process [15720] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
23:27:16.342724333ProcessInjector::HandlePendingProccesssFail to inject pending process |15720|: bash
23:27:26.1022724394ProcessInjector::HandleElevatedProcessFail injection to process [16512] [t: 0 w_t_id: 0]- rsync (elevated True) 0x1f
23:27:26.1022724333ProcessInjector::HandlePendingProccesssFail to inject pending process |16512|: rsync
23:27:27.1132724394ProcessInjector::HandleElevatedProcessFail injection to process [18188] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
23:27:27.1132724333ProcessInjector::HandlePendingProccesssFail to inject pending process |18188|: ssh
23:30:59.5502724394ProcessInjector::HandleElevatedProcessFail injection to process [15856] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x1f
23:30:59.5502724333ProcessInjector::HandlePendingProccesssFail to inject pending process |15856|: plugin-container.exe
23:35:28.5572724394ProcessInjector::HandleElevatedProcessFail injection to process [21668] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x1f
23:35:28.5572724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21668|: plugin-container.exe
23:50:29.8582724394ProcessInjector::HandleElevatedProcessFail injection to process [9596] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
23:50:29.8592724333ProcessInjector::HandlePendingProccesssFail to inject pending process |9596|: ssh
23:53:38.3702724394ProcessInjector::HandleElevatedProcessFail injection to process [2360] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
23:53:38.3702724333ProcessInjector::HandlePendingProccesssFail to inject pending process |2360|: firefox.exe
00:32:20.2192724394ProcessInjector::HandleElevatedProcessFail injection to process [21936] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
00:32:20.2192724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21936|: firefox.exe
00:32:22.2362724394ProcessInjector::HandleElevatedProcessFail injection to process [12564] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
00:32:22.2362724333ProcessInjector::HandlePendingProccesssFail to inject pending process |12564|: firefox.exe
01:13:27.2442724394ProcessInjector::HandleElevatedProcessFail injection to process [9368] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:13:27.2442724333ProcessInjector::HandlePendingProccesssFail to inject pending process |9368|: firefox.exe
01:24:07.5182724394ProcessInjector::HandleElevatedProcessFail injection to process [18724] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
01:24:07.5182724333ProcessInjector::HandlePendingProccesssFail to inject pending process |18724|: bash
01:24:07.5182724394ProcessInjector::HandleElevatedProcessFail injection to process [21152] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
01:24:07.5182724333ProcessInjector::HandlePendingProccesssFail to inject pending process |21152|: init
01:44:11.7592724394ProcessInjector::HandleElevatedProcessFail injection to process [19860] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:44:11.7602724333ProcessInjector::HandlePendingProccesssFail to inject pending process |19860|: firefox.exe
01:44:12.7752724394ProcessInjector::HandleElevatedProcessFail injection to process [14152] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:44:12.7752724333ProcessInjector::HandlePendingProccesssFail to inject pending process |14152|: firefox.exe
01:51:23.8842724394ProcessInjector::HandleElevatedProcessFail injection to process [13036] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
01:51:23.8842724333ProcessInjector::HandlePendingProccesssFail to inject pending process |13036|: ssh
01:53:32.9612724394ProcessInjector::HandleElevatedProcessFail injection to process [15312] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:53:32.9612724333ProcessInjector::HandlePendingProccesssFail to inject pending process |15312|: firefox.exe
01:53:33.9742724394ProcessInjector::HandleElevatedProcessFail injection to process [18484] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:53:33.9742724333ProcessInjector::HandlePendingProccesssFail to inject pending process |18484|: firefox.exe
02:03:37.60185066ProcessesMonitor::Stopstopping PM...
02:03:37.601FF0119ProcessesMonitor::ProcessEnumerateThreadexit process listener
02:03:37.611850479ProcessInjector::Unhookunhook running process
02:03:43.78185066ProcessesMonitor::Stopstopping PM...