TimeThreadLineFunctionMessage
12:41:49.8263258361ftw1Loading (pid: 15480)
12:41:49.8265F64146ProcessHardwareRecorder::CommandThreadstarting recorder thread
12:41:49.827325848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X34220000>6|2|1247870977
12:41:49.827325848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X3A1F0000>6|2|1247871464
12:41:49.8683258172DXManager::DetectFound in 0
12:41:49.8683258209Initialize::GetLocation@ 0X4F80|20352
12:41:49.8683258209Initialize::GetLocation@ 0X69530|431408
12:41:49.8683258209Initialize::GetLocation@ 0X20410|132112
12:41:49.8683258209Initialize::GetLocation@ 0X1DE0|7648
12:41:49.8683258111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:41:49.8683258209Initialize::GetLocation@ 0XFA158850|-99252144
12:41:49.8683258111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:41:49.8683258209Initialize::GetLocation@ 0XFA15DE80|-99230080
12:41:49.8683258111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:41:49.8683258209Initialize::GetLocation@ 0XFA15C5E0|-99236384
12:41:49.8683258111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
12:41:49.8683258209Initialize::GetLocation@ 0XFA03A7F0|-100423696
12:41:49.874325848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X262F0000>6|2|1247871464
12:41:49.8983258129DXManager::DetectOK
12:41:49.9123258186DXManager::DetectDone
12:41:49.9133258215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
12:41:49.9133258209Initialize::GetLocation@ 0X41000|266240
12:41:49.9133258209Initialize::GetLocation@ 0X332C0|209600
12:41:49.9133258209Initialize::GetLocation@ 0X3CB30|248624
12:41:49.9133258209Initialize::GetLocation@ 0XB72C0|750272
12:41:49.9133258209Initialize::GetLocation@ 0XB6E10|749072
12:41:49.9133258209Initialize::GetLocation@ 0XA190|41360
12:41:49.9133258209Initialize::GetLocation@ 0XB6EB0|749232
12:41:49.9133258209Initialize::GetLocation@ 0X1AB50|109392
12:41:49.9133258209Initialize::GetLocation@ 0X1D5A0|120224
12:41:49.9133258209Initialize::GetLocation@ 0X25BD0|154576
12:41:49.9133258209Initialize::GetLocation@ 0X113530|1127728
12:41:49.9133258209Initialize::GetLocation@ 0X112FF0|1126384
12:41:49.9133258209Initialize::GetLocation@ 0X1AA40|109120
12:41:49.9133258209Initialize::GetLocation@ 0X1A950|108880
12:41:49.9133258209Initialize::GetLocation@ 0XCB20|52000
12:41:49.9133258209Initialize::GetLocation@ 0X47D50|294224
12:41:49.9133258209Initialize::GetLocation@ 0X9D00|40192
12:41:49.9133258209Initialize::GetLocation@ 0XCE4B0|844976
12:41:49.9133258209Initialize::GetLocation@ 0XCEB80|846720
12:41:49.9133258209Initialize::GetLocation@ 0X9D00|40192
12:41:49.9133258209Initialize::GetLocation@ 0XCF670|849520
12:41:49.9133258209Initialize::GetLocation@ 0XCFCD0|851152
12:41:49.926325848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XE0540000>6|2|1247870977
12:41:49.979325883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
12:41:49.9793258209Initialize::GetLocation@ 0X4040|16448
12:41:49.9793258209Initialize::GetLocation@ 0X6410|25616
12:41:49.9793258209Initialize::GetLocation@ 0X65C0|26048
12:41:49.980325848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XDD700000>6|2|1247870977
12:41:49.996325893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
12:41:49.9963258110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
12:41:49.9963258209Initialize::GetLocation@ 0XA5D0|42448
12:41:49.9963258209Initialize::GetLocation@ 0XD4D0|54480
12:41:49.9963258209Initialize::GetLocation@ 0XD290|53904
12:41:50.543258225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_15480 opened succesfuly
12:41:50.54325872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
12:41:50.543258256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_15480 close 2147483647 bytes
12:41:50.543258297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll]
12:41:50.1223258385ftw1OWExplorer injected
12:41:50.6854B7451`anonymous-namespace'::CreateProviderInitialize provider: NET
12:41:50.6854B74117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
12:41:50.6854B7454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
12:41:50.6854B7451`anonymous-namespace'::CreateProviderInitialize provider: GPU
12:41:52.1375028421ProcessInjector::DoElevetedInjectionFailed to inject process [16944] 0x57
12:41:52.1375028377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [16944] [t: 22708 w_t_id: 22708]- OverwolfLauncher.exe (elevated True) 0x57
12:41:52.1405028421ProcessInjector::DoElevetedInjectionFailed to inject process [16944] 0x57
12:41:52.1405028394ProcessInjector::HandleElevatedProcessFail injection to process [16944] [t: 22708 w_t_id: 22708]- OverwolfLauncher.exe (elevated True) 0x57
12:41:52.1405028333ProcessInjector::HandlePendingProccesssFail to inject pending process |16944|: OverwolfLauncher.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [2652] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |2652|: NVDisplay.Container.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [2960] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |2960|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [4384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |4384|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [4600] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |4600|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [4972] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |4972|: nvcontainer.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [5360] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |5360|: MsMpEng.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [5592] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |5592|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [9528] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |9528|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [10048] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |10048|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [12764] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |12764|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [16340] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |16340|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [20124] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20124|: firefox.exe
12:44:21.4015028394ProcessInjector::HandleElevatedProcessFail injection to process [25296] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:21.4015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |25296|: firefox.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [3936] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |3936|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [4064] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |4064|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [8444] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |8444|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [10036] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |10036|: firefox.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [16348] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |16348|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [17320] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17320|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [17612] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17612|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [17668] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17668|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [18488] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |18488|: Code.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [19024] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |19024|: node.exe
12:44:22.3975028394ProcessInjector::HandleElevatedProcessFail injection to process [25128] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
12:44:22.3975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |25128|: Code.exe
13:36:04.1975028394ProcessInjector::HandleElevatedProcessFail injection to process [2356] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
13:36:04.1975028333ProcessInjector::HandlePendingProccesssFail to inject pending process |2356|: Code.exe
13:39:37.675028394ProcessInjector::HandleElevatedProcessFail injection to process [10832] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
13:39:37.675028333ProcessInjector::HandlePendingProccesssFail to inject pending process |10832|: Code.exe
13:42:53.8225028394ProcessInjector::HandleElevatedProcessFail injection to process [18444] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
13:42:53.8225028333ProcessInjector::HandlePendingProccesssFail to inject pending process |18444|: Code.exe
13:44:15.4505028394ProcessInjector::HandleElevatedProcessFail injection to process [24208] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
13:44:15.4505028333ProcessInjector::HandlePendingProccesssFail to inject pending process |24208|: node.exe
13:45:27.705028394ProcessInjector::HandleElevatedProcessFail injection to process [4732] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5a4
13:45:27.705028333ProcessInjector::HandlePendingProccesssFail to inject pending process |4732|: node.exe
15:36:31.5955028394ProcessInjector::HandleElevatedProcessFail injection to process [20132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
15:36:31.5955028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20132|: firefox.exe
15:36:57.8885028421ProcessInjector::DoElevetedInjectionFailed to inject process [15152] 0x57
15:36:57.8895028377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [15152] [t: 17596 w_t_id: 17596]- conhost.exe (elevated True) 0x57
15:36:58.8305028421ProcessInjector::DoElevetedInjectionFailed to inject process [15152] 0x57
15:36:58.8305028394ProcessInjector::HandleElevatedProcessFail injection to process [15152] [t: 17596 w_t_id: 17596]- conhost.exe (elevated True) 0x57
15:36:58.8305028333ProcessInjector::HandlePendingProccesssFail to inject pending process |15152|: conhost.exe
15:39:45.4965028421ProcessInjector::DoElevetedInjectionFailed to inject process [19484] 0x57
15:39:45.4965028377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [19484] [t: 7464 w_t_id: 7464]- conhost.exe (elevated True) 0x57
15:39:46.4175028421ProcessInjector::DoElevetedInjectionFailed to inject process [19484] 0x57
15:39:46.4175028394ProcessInjector::HandleElevatedProcessFail injection to process [19484] [t: 7464 w_t_id: 7464]- conhost.exe (elevated True) 0x57
15:39:46.4175028333ProcessInjector::HandlePendingProccesssFail to inject pending process |19484|: conhost.exe
15:45:16.7025028394ProcessInjector::HandleElevatedProcessFail injection to process [20304] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
15:45:16.7035028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20304|: node.exe
16:12:14.1935028394ProcessInjector::HandleElevatedProcessFail injection to process [18748] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
16:12:14.1935028333ProcessInjector::HandlePendingProccesssFail to inject pending process |18748|: Code.exe
16:41:41.575028394ProcessInjector::HandleElevatedProcessFail injection to process [15564] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
16:41:41.575028333ProcessInjector::HandlePendingProccesssFail to inject pending process |15564|: fzsftp.exe
16:41:47.1115028394ProcessInjector::HandleElevatedProcessFail injection to process [24976] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:41:47.1115028333ProcessInjector::HandlePendingProccesssFail to inject pending process |24976|: fzsftp.exe
16:41:58.1995028394ProcessInjector::HandleElevatedProcessFail injection to process [11040] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:41:58.1995028333ProcessInjector::HandlePendingProccesssFail to inject pending process |11040|: fzsftp.exe
16:42:08.2935028394ProcessInjector::HandleElevatedProcessFail injection to process [17464] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:08.2935028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17464|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [2372] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |2372|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [3020] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |3020|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [8528] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |8528|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [10416] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |10416|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [10456] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |10456|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [13028] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |13028|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [22256] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |22256|: fzsftp.exe
16:42:20.3805028394ProcessInjector::HandleElevatedProcessFail injection to process [23472] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x578
16:42:20.3805028333ProcessInjector::HandlePendingProccesssFail to inject pending process |23472|: fzsftp.exe
16:45:28.275028394ProcessInjector::HandleElevatedProcessFail injection to process [20760] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
16:45:28.275028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20760|: init
16:45:28.275028394ProcessInjector::HandleElevatedProcessFail injection to process [20788] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
16:45:28.275028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20788|: init
16:45:28.275028394ProcessInjector::HandleElevatedProcessFail injection to process [25284] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
16:45:28.275028333ProcessInjector::HandlePendingProccesssFail to inject pending process |25284|: bash
16:45:44.1265028394ProcessInjector::HandleElevatedProcessFail injection to process [3824] [t: 0 w_t_id: 0]- gzip (elevated True) 0x1f
16:45:44.1265028333ProcessInjector::HandlePendingProccesssFail to inject pending process |3824|: gzip
16:45:44.1265028394ProcessInjector::HandleElevatedProcessFail injection to process [6668] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
16:45:44.1265028333ProcessInjector::HandlePendingProccesssFail to inject pending process |6668|: init
16:45:44.1265028394ProcessInjector::HandleElevatedProcessFail injection to process [11024] [t: 0 w_t_id: 0]- mysql.exe (elevated True) 0x1f
16:45:44.1265028333ProcessInjector::HandlePendingProccesssFail to inject pending process |11024|: mysql.exe
16:49:28.275028394ProcessInjector::HandleElevatedProcessFail injection to process [16264] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x1f
16:49:28.275028333ProcessInjector::HandlePendingProccesssFail to inject pending process |16264|: fzsftp.exe
16:55:19.8655028394ProcessInjector::HandleElevatedProcessFail injection to process [4768] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
16:55:19.8655028333ProcessInjector::HandlePendingProccesssFail to inject pending process |4768|: node.exe
17:17:49.7865028394ProcessInjector::HandleElevatedProcessFail injection to process [9284] [t: 0 w_t_id: 0]- init (elevated True) 0x1f
17:17:49.7865028333ProcessInjector::HandlePendingProccesssFail to inject pending process |9284|: init
17:17:49.7865028394ProcessInjector::HandleElevatedProcessFail injection to process [13768] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
17:17:49.7865028333ProcessInjector::HandlePendingProccesssFail to inject pending process |13768|: bash
17:19:46.6015028394ProcessInjector::HandleElevatedProcessFail injection to process [18936] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
17:19:46.6015028333ProcessInjector::HandlePendingProccesssFail to inject pending process |18936|: node.exe
19:04:09.1445028394ProcessInjector::HandleElevatedProcessFail injection to process [24136] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f
19:04:09.1445028333ProcessInjector::HandlePendingProccesssFail to inject pending process |24136|: openvpn.exe
19:04:35.4235028394ProcessInjector::HandleElevatedProcessFail injection to process [16288] [t: 0 w_t_id: 0]- bash (elevated True) 0x1f
19:04:35.4235028333ProcessInjector::HandlePendingProccesssFail to inject pending process |16288|: bash
19:04:45.5205028394ProcessInjector::HandleElevatedProcessFail injection to process [9380] [t: 0 w_t_id: 0]- ssh (elevated True) 0x1f
19:04:45.5205028333ProcessInjector::HandlePendingProccesssFail to inject pending process |9380|: ssh
19:04:45.5205028394ProcessInjector::HandleElevatedProcessFail injection to process [11544] [t: 0 w_t_id: 0]- rsync (elevated True) 0x1f
19:04:45.5205028333ProcessInjector::HandlePendingProccesssFail to inject pending process |11544|: rsync
19:20:31.355028394ProcessInjector::HandleElevatedProcessFail injection to process [23460] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f
19:20:31.355028333ProcessInjector::HandlePendingProccesssFail to inject pending process |23460|: MsMpEng.exe
19:30:44.3485028394ProcessInjector::HandleElevatedProcessFail injection to process [17324] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x578
19:30:44.3485028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17324|: node.exe
19:30:44.3485028394ProcessInjector::HandleElevatedProcessFail injection to process [19956] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x578
19:30:44.3485028333ProcessInjector::HandlePendingProccesssFail to inject pending process |19956|: node.exe
19:30:45.3515028394ProcessInjector::HandleElevatedProcessFail injection to process [23768] [t: 0 w_t_id: 0]- electron.exe (elevated True) 0x578
19:30:45.3515028333ProcessInjector::HandlePendingProccesssFail to inject pending process |23768|: electron.exe
19:35:29.8815028394ProcessInjector::HandleElevatedProcessFail injection to process [12272] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
19:35:29.8815028333ProcessInjector::HandlePendingProccesssFail to inject pending process |12272|: firefox.exe
19:41:55.3995028394ProcessInjector::HandleElevatedProcessFail injection to process [272] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
19:41:55.3995028333ProcessInjector::HandlePendingProccesssFail to inject pending process |272|: node.exe
19:41:55.3995028394ProcessInjector::HandleElevatedProcessFail injection to process [18712] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
19:41:55.3995028333ProcessInjector::HandlePendingProccesssFail to inject pending process |18712|: node.exe
19:41:56.4145028394ProcessInjector::HandleElevatedProcessFail injection to process [5596] [t: 0 w_t_id: 0]- electron.exe (elevated True) 0x0
19:41:56.4145028333ProcessInjector::HandlePendingProccesssFail to inject pending process |5596|: electron.exe
19:41:56.4145028394ProcessInjector::HandleElevatedProcessFail injection to process [18900] [t: 0 w_t_id: 0]- electron.exe (elevated True) 0x0
19:41:56.4145028333ProcessInjector::HandlePendingProccesssFail to inject pending process |18900|: electron.exe
19:44:32.8715028394ProcessInjector::HandleElevatedProcessFail injection to process [15380] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
19:44:32.8715028333ProcessInjector::HandlePendingProccesssFail to inject pending process |15380|: software_reporter_tool.exe
19:44:32.8715028394ProcessInjector::HandleElevatedProcessFail injection to process [20544] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
19:44:32.8715028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20544|: software_reporter_tool.exe
19:44:33.8855028394ProcessInjector::HandleElevatedProcessFail injection to process [17392] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
19:44:33.8855028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17392|: software_reporter_tool.exe
19:49:28.6375028394ProcessInjector::HandleElevatedProcessFail injection to process [16164] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
19:49:28.6375028333ProcessInjector::HandlePendingProccesssFail to inject pending process |16164|: firefox.exe
19:58:08.865028394ProcessInjector::HandleElevatedProcessFail injection to process [11940] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
19:58:08.865028333ProcessInjector::HandlePendingProccesssFail to inject pending process |11940|: Code.exe
21:00:16.3035028394ProcessInjector::HandleElevatedProcessFail injection to process [22768] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
21:00:16.3035028333ProcessInjector::HandlePendingProccesssFail to inject pending process |22768|: firefox.exe
21:21:51.2555028394ProcessInjector::HandleElevatedProcessFail injection to process [24532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
21:21:51.2555028333ProcessInjector::HandlePendingProccesssFail to inject pending process |24532|: firefox.exe
21:21:52.2545028394ProcessInjector::HandleElevatedProcessFail injection to process [11188] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
21:21:52.2545028333ProcessInjector::HandlePendingProccesssFail to inject pending process |11188|: firefox.exe
21:21:54.2775028394ProcessInjector::HandleElevatedProcessFail injection to process [24840] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x5
21:21:54.2775028333ProcessInjector::HandlePendingProccesssFail to inject pending process |24840|: plugin-container.exe
22:22:25.4495028394ProcessInjector::HandleElevatedProcessFail injection to process [20804] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
22:22:25.4495028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20804|: Code.exe
22:39:31.2865028394ProcessInjector::HandleElevatedProcessFail injection to process [17300] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
22:39:31.2865028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17300|: firefox.exe
22:55:18.6535028394ProcessInjector::HandleElevatedProcessFail injection to process [15656] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
22:55:18.6535028333ProcessInjector::HandlePendingProccesssFail to inject pending process |15656|: firefox.exe
23:50:59.2855028394ProcessInjector::HandleElevatedProcessFail injection to process [11200] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
23:50:59.2855028333ProcessInjector::HandlePendingProccesssFail to inject pending process |11200|: Code.exe
00:01:50.7615028394ProcessInjector::HandleElevatedProcessFail injection to process [10992] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
00:01:50.7615028333ProcessInjector::HandlePendingProccesssFail to inject pending process |10992|: firefox.exe
00:01:52.7875028394ProcessInjector::HandleElevatedProcessFail injection to process [24928] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
00:01:52.7875028333ProcessInjector::HandlePendingProccesssFail to inject pending process |24928|: firefox.exe
00:46:23.3715028394ProcessInjector::HandleElevatedProcessFail injection to process [25888] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
00:46:23.3715028333ProcessInjector::HandlePendingProccesssFail to inject pending process |25888|: firefox.exe
00:46:24.3745028394ProcessInjector::HandleElevatedProcessFail injection to process [6308] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
00:46:24.3745028333ProcessInjector::HandlePendingProccesssFail to inject pending process |6308|: firefox.exe
01:00:18.9785028394ProcessInjector::HandleElevatedProcessFail injection to process [17896] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
01:00:18.9785028333ProcessInjector::HandlePendingProccesssFail to inject pending process |17896|: firefox.exe
01:20:42.8765028394ProcessInjector::HandleElevatedProcessFail injection to process [20804] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
01:20:42.8765028333ProcessInjector::HandlePendingProccesssFail to inject pending process |20804|: firefox.exe
01:32:14.6375028394ProcessInjector::HandleElevatedProcessFail injection to process [21364] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f
01:32:14.6375028333ProcessInjector::HandlePendingProccesssFail to inject pending process |21364|: openvpn.exe
01:33:00.9565028394ProcessInjector::HandleElevatedProcessFail injection to process [9748] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:33:00.9565028333ProcessInjector::HandlePendingProccesssFail to inject pending process |9748|: firefox.exe
01:33:01.9685028394ProcessInjector::HandleElevatedProcessFail injection to process [21400] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:33:01.9685028333ProcessInjector::HandlePendingProccesssFail to inject pending process |21400|: firefox.exe
02:34:01.536325866ProcessesMonitor::Stopstopping PM...
02:34:01.5374B74119ProcessesMonitor::ProcessEnumerateThreadexit process listener
02:34:01.5403258479ProcessInjector::Unhookunhook running process