Time | Thread | Line | Function | Message |
12:34:01.865 | 31DC | 361 | ftw1 | Loading (pid: 25620) |
12:34:01.865 | 1F08 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
12:34:01.867 | 31DC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X34220000>6|2|1247870977 |
12:34:01.867 | 31DC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X3A1F0000>6|2|1247871464 |
12:34:01.924 | 31DC | 172 | DXManager::Detect | Found in 0 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0X69530|431408 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0X20410|132112 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
12:34:01.924 | 31DC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0XFA158850|-99252144 |
12:34:01.924 | 31DC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0XFA15DE80|-99230080 |
12:34:01.924 | 31DC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0XFA15C5E0|-99236384 |
12:34:01.924 | 31DC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000 |
12:34:01.924 | 31DC | 209 | Initialize::GetLocation | @ 0XFA03A7F0|-100423696 |
12:34:01.932 | 31DC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X25C10000>6|2|1247871464 |
12:34:01.958 | 31DC | 129 | DXManager::Detect | OK |
12:34:01.976 | 31DC | 186 | DXManager::Detect | Done |
12:34:01.976 | 31DC | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X41000|266240 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X332C0|209600 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X3CB30|248624 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XB72C0|750272 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XB6E10|749072 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XA190|41360 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XB6EB0|749232 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X1AB50|109392 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X1D5A0|120224 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X25BD0|154576 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X113530|1127728 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X112FF0|1126384 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X1AA40|109120 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X1A950|108880 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XCB20|52000 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X47D50|294224 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X9D00|40192 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XCE4B0|844976 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XCEB80|846720 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0X9D00|40192 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XCF670|849520 |
12:34:01.977 | 31DC | 209 | Initialize::GetLocation | @ 0XCFCD0|851152 |
12:34:01.991 | 31DC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0XDD100000>6|2|1247870977 |
12:34:02.67 | 31DC | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
12:34:02.68 | 31DC | 209 | Initialize::GetLocation | @ 0X4040|16448 |
12:34:02.68 | 31DC | 209 | Initialize::GetLocation | @ 0X6410|25616 |
12:34:02.68 | 31DC | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
12:34:02.71 | 31DC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0XDBE50000>6|2|1247870977 |
12:34:02.95 | 31DC | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
12:34:02.95 | 31DC | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
12:34:02.96 | 31DC | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
12:34:02.96 | 31DC | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
12:34:02.96 | 31DC | 209 | Initialize::GetLocation | @ 0XD290|53904 |
12:34:02.165 | 31DC | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_80_3_25620 opened succesfuly |
12:34:02.166 | 31DC | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
12:34:02.166 | 31DC | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_80_3_25620 close 2147483647 bytes |
12:34:02.166 | 31DC | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll] |
12:34:02.252 | 31DC | 385 | ftw1 | OWExplorer injected |
12:34:02.853 | 5940 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
12:34:02.853 | 5940 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
12:34:02.853 | 5940 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
12:34:02.853 | 5940 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
12:36:32.966 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2652] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
12:36:32.966 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2652|: NVDisplay.Container.exe |
12:36:32.966 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4972] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
12:36:32.966 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4972|: nvcontainer.exe |
12:36:32.966 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23460] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
12:36:32.966 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23460|: MsMpEng.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1452] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1452|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9084] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9084|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12916] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12916|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13532|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18408] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18408|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18956] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18956|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20604] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20604|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22724] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22724|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24324] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24324|: firefox.exe |
12:36:33.975 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [26164] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
12:36:33.975 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |26164|: node.exe |
12:38:08.643 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:38:08.643 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24460|: firefox.exe |
12:39:32.276 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19092] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:39:32.276 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19092|: firefox.exe |
12:43:22.169 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22548] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:43:22.169 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22548|: firefox.exe |
12:48:52.350 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9012] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:48:52.350 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9012|: firefox.exe |
12:50:27.249 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22168] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:50:27.249 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22168|: firefox.exe |
12:54:32.707 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17824] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
12:54:32.707 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17824|: firefox.exe |
13:03:44.183 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10456] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
13:03:44.183 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10456|: firefox.exe |
13:04:19.501 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5488] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0 |
13:04:19.501 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5488|: WhatsApp.exe |
13:04:19.501 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15244] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0 |
13:04:19.501 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15244|: WhatsApp.exe |
13:04:21.515 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9760] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0 |
13:04:21.515 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9760|: WhatsApp.exe |
13:13:48.956 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23240] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
13:13:48.956 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23240|: firefox.exe |
13:16:11.169 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5804] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
13:16:11.169 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5804|: node.exe |
13:19:34.173 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13352] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
13:19:34.173 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13352|: firefox.exe |
13:22:48.110 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25332] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
13:22:48.110 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25332|: firefox.exe |
14:58:49.571 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16404] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f |
14:58:49.571 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16404|: node.exe |
15:42:10.514 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4996] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
15:42:10.514 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4996|: firefox.exe |
15:42:11.539 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10416] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
15:42:11.539 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10416|: firefox.exe |
15:47:01.211 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [21528] 0x57 |
15:47:01.211 | 4980 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [21528] [t: 14780 w_t_id: 14780]- ConEmuC64.exe (elevated True) 0x57 |
15:47:02.221 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [21528] 0x57 |
15:47:02.221 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21528] [t: 14780 w_t_id: 14780]- ConEmuC64.exe (elevated True) 0x57 |
15:47:02.221 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21528|: ConEmuC64.exe |
15:52:43.430 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x57 |
15:52:43.430 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21632|: firefox.exe |
16:05:25.772 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3932] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
16:05:25.772 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3932|: software_reporter_tool.exe |
16:05:25.772 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11028] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
16:05:25.772 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11028|: software_reporter_tool.exe |
16:05:25.772 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21420] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
16:05:25.772 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21420|: software_reporter_tool.exe |
17:09:28.779 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22444] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:09:28.779 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22444|: firefox.exe |
17:15:43.302 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19252] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:15:43.302 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19252|: firefox.exe |
17:15:44.300 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24036] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:15:44.300 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24036|: firefox.exe |
17:16:28.710 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19912] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:16:28.710 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19912|: firefox.exe |
17:24:58.363 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21684] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:24:58.363 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21684|: firefox.exe |
17:31:52.399 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2184] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:31:52.399 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2184|: firefox.exe |
18:29:34.371 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
18:29:34.371 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7384|: firefox.exe |
18:31:01.205 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1048] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
18:31:01.205 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1048|: firefox.exe |
18:36:32.259 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8452] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
18:36:32.259 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8452|: firefox.exe |
18:36:36.285 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9208] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
18:36:36.286 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9208|: firefox.exe |
18:45:24.299 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9872] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x578 |
18:45:24.299 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9872|: openvpn.exe |
18:46:05.714 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [888] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578 |
18:46:05.714 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |888|: fzsftp.exe |
18:47:12.328 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3948] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f |
18:47:12.328 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3948|: fzsftp.exe |
18:48:57.310 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11720] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
18:48:57.310 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11720|: init |
18:48:57.310 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13272] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
18:48:57.310 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13272|: init |
18:48:57.310 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24264] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f |
18:48:57.310 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24264|: bash |
18:50:12.11 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19980] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
18:50:12.11 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19980|: firefox.exe |
18:54:47.506 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15516] [t: 0 w_t_id: 0]- git-bash.exe (elevated True) 0x1f |
18:54:47.506 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15516|: git-bash.exe |
18:54:47.506 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19788] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x1f |
18:54:47.506 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19788|: bash.exe |
18:55:40.42 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6496] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f |
18:55:40.42 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6496|: node.exe |
19:28:36.53 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25636] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x1f |
19:28:36.53 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25636|: WhatsApp.exe |
20:18:35.204 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2480] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
20:18:35.204 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2480|: firefox.exe |
20:19:17.592 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11544] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f |
20:19:17.592 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11544|: fzsftp.exe |
20:20:57.535 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4712] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
20:20:57.535 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4712|: firefox.exe |
20:24:33.567 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15960] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
20:24:33.567 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15960|: firefox.exe |
20:27:21.125 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17412] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
20:27:21.125 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17412|: firefox.exe |
20:29:17.179 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16200] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
20:29:17.179 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16200|: firefox.exe |
21:20:30.211 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23024] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
21:20:30.211 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23024|: firefox.exe |
21:20:32.239 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19904] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
21:20:32.239 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19904|: firefox.exe |
21:21:08.590 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16572] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
21:21:08.590 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16572|: firefox.exe |
21:22:10.35 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25424] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
21:22:10.35 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25424|: node.exe |
21:22:24.137 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20612] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:24.137 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20612|: Code.exe |
21:22:24.137 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24852] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:24.137 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24852|: Code.exe |
21:22:26.153 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12804] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:26.153 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12804|: Code.exe |
21:22:27.169 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12968] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:27.169 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12968|: Code.exe |
21:22:28.176 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1004] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:28.176 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1004|: Code.exe |
21:22:28.176 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5436] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:28.176 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5436|: Code.exe |
21:22:28.176 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13860] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:28.176 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13860|: Code.exe |
21:22:32.197 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20056] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
21:22:32.197 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20056|: Code.exe |
21:31:30.987 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10344] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f |
21:31:30.987 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10344|: bash |
21:31:30.987 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18384] [t: 0 w_t_id: 0]- init (elevated True) 0x1f |
21:31:30.987 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18384|: init |
21:31:37.48 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19112] [t: 0 w_t_id: 0]- redis-cli (elevated True) 0x1f |
21:31:37.48 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19112|: redis-cli |
21:58:11.21 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
21:58:11.21 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11532|: firefox.exe |
22:16:19.272 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [7600] 0x57 |
22:16:19.272 | 4980 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [7600] [t: 24940 w_t_id: 24940]- conhost.exe (elevated True) 0x57 |
22:16:20.204 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [7600] 0x57 |
22:16:20.204 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7600] [t: 24940 w_t_id: 24940]- conhost.exe (elevated True) 0x57 |
22:16:20.205 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7600|: conhost.exe |
22:19:13.565 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [9920] 0x57 |
22:19:13.565 | 4980 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [9920] [t: 14792 w_t_id: 14792]- conhost.exe (elevated True) 0x57 |
22:19:14.532 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [9920] 0x57 |
22:19:14.532 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9920] [t: 14792 w_t_id: 14792]- conhost.exe (elevated True) 0x57 |
22:19:14.532 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9920|: conhost.exe |
22:21:34.812 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [25864] 0x57 |
22:21:34.812 | 4980 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [25864] [t: 15060 w_t_id: 15060]- conhost.exe (elevated True) 0x57 |
22:21:35.749 | 4980 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [25864] 0x57 |
22:21:35.750 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25864] [t: 15060 w_t_id: 15060]- conhost.exe (elevated True) 0x57 |
22:21:35.750 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25864|: conhost.exe |
22:30:50.444 | 4980 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3192] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
22:30:50.444 | 4980 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3192|: Code.exe |