TimeThreadLineFunctionMessage
15:40:08.13350EC361ftw1Loading (pid: 22992)
15:40:08.13550EC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XB7F80000>6|2|1203373203
15:40:08.13550EC48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XB9FC0000>6|2|1203373081
15:40:08.2012B34146ProcessHardwareRecorder::CommandThreadstarting recorder thread
15:40:08.97950EC172DXManager::DetectFound in 0
15:40:08.98050EC209Initialize::GetLocation@ 0X4660|18016
15:40:08.98050EC209Initialize::GetLocation@ 0X661F0|418288
15:40:08.98050EC209Initialize::GetLocation@ 0X19DB0|105904
15:40:08.98050EC209Initialize::GetLocation@ 0X1350|4944
15:40:08.98050EC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
15:40:08.98050EC209Initialize::GetLocation@ 0XFE0E3020|-32624608
15:40:08.98050EC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
15:40:08.98050EC209Initialize::GetLocation@ 0XFE0E8060|-32604064
15:40:08.98050EC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
15:40:08.98050EC209Initialize::GetLocation@ 0XFE0DE620|-32643552
15:40:08.98050EC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
15:40:08.98050EC209Initialize::GetLocation@ 0XFDFCAA80|-33772928
15:40:09.16950EC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X8AB00000>6|2|1203373142
15:40:09.64050EC129DXManager::DetectOK
15:40:09.86550EC186DXManager::DetectDone
15:40:09.86650EC215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
15:40:09.86750EC209Initialize::GetLocation@ 0X3AC00|240640
15:40:09.86750EC209Initialize::GetLocation@ 0X2C5B0|181680
15:40:09.86750EC209Initialize::GetLocation@ 0X36D00|224512
15:40:09.86750EC209Initialize::GetLocation@ 0XAE210|713232
15:40:09.86750EC209Initialize::GetLocation@ 0XADD60|712032
15:40:09.86750EC209Initialize::GetLocation@ 0X5880|22656
15:40:09.86750EC209Initialize::GetLocation@ 0XADE00|712192
15:40:09.86750EC209Initialize::GetLocation@ 0X20FF0|135152
15:40:09.86750EC209Initialize::GetLocation@ 0X1CA60|117344
15:40:09.86750EC209Initialize::GetLocation@ 0X1C8E0|116960
15:40:09.86750EC209Initialize::GetLocation@ 0X1086D0|1083088
15:40:09.86750EC209Initialize::GetLocation@ 0X108180|1081728
15:40:09.86750EC209Initialize::GetLocation@ 0X248B0|149680
15:40:09.86750EC209Initialize::GetLocation@ 0X247A0|149408
15:40:09.86750EC209Initialize::GetLocation@ 0X2C440|181312
15:40:09.86750EC209Initialize::GetLocation@ 0X3F3F0|259056
15:40:09.86750EC209Initialize::GetLocation@ 0XF3E0|62432
15:40:09.86750EC209Initialize::GetLocation@ 0XF4E0|62688
15:40:09.86750EC209Initialize::GetLocation@ 0XF5D0|62928
15:40:09.86750EC209Initialize::GetLocation@ 0XF3E0|62432
15:40:09.86750EC209Initialize::GetLocation@ 0XF280|62080
15:40:09.86750EC209Initialize::GetLocation@ 0XF430|62512
15:40:09.93450EC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X8C7B0000>6|2|1203372033
15:40:09.94750EC83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
15:40:09.94850EC209Initialize::GetLocation@ 0X3CC0|15552
15:40:09.94850EC209Initialize::GetLocation@ 0X5FD0|24528
15:40:09.94850EC209Initialize::GetLocation@ 0X6180|24960
15:40:09.95150EC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X8C760000>6|2|1203372033
15:40:09.96150EC93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
15:40:09.96150EC110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
15:40:09.96150EC209Initialize::GetLocation@ 0X10000|65536
15:40:09.96150EC209Initialize::GetLocation@ 0X12C80|76928
15:40:09.96150EC209Initialize::GetLocation@ 0X12A60|76384
15:40:10.1450EC225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_22992 opened succesfuly
15:40:10.1450EC72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
15:40:10.1550EC256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_22992 close 2147483647 bytes
15:40:10.1550EC297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.25\OWExplorer.dll]
15:40:10.7350EC385ftw1OWExplorer injected
15:40:11.228697051`anonymous-namespace'::CreateProviderInitialize provider: NET
15:40:11.2286970117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
15:40:11.228697054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
15:40:11.228697051`anonymous-namespace'::CreateProviderInitialize provider: GPU
15:40:11.267258C629ProcessInjector::InjectProcessprocess |vpnagent.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |com.docker.service| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |nassvc.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |httpd.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |mysqld.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |httpd.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |MicrosoftEdge_X64_87.0.664.52_87.0.664.47.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |tv_w32.exe| missing h
15:40:11.267258C629ProcessInjector::InjectProcessprocess |tv_x64.exe| missing h
15:40:11.399258C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:40:11.445258C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:40:40.363258C629ProcessInjector::InjectProcessprocess |setup.exe| missing h
15:40:51.376258C629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
15:40:51.376258C629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
15:40:51.376258C629ProcessInjector::InjectProcessprocess |setup.exe| missing h
15:40:54.415258C629ProcessInjector::InjectProcessprocess |00110000000951552078DF83| missing h
15:40:54.415258C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:41:41.197258C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
15:41:42.189258C629ProcessInjector::InjectProcessprocess |VSIXAutoUpdate.exe| missing h
15:41:42.189258C629ProcessInjector::InjectProcessprocess |CCUpdate.exe| missing h
15:41:50.196258C629ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
15:42:09.226258C629ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [2672] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |2672|: vpnagent.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [2896] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |2896|: MsMpEng.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [3684] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3684|: com.docker.service
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [3728] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3728|: gameinputsvc.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [4048] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4048|: nassvc.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [4148] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4148|: httpd.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [4652] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4652|: mysqld.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [5680] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5680|: GoogleCrashHandler64.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [5716] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5716|: DropboxUpdate.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [6276] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6276|: tv_w32.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [6668] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6668|: httpd.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [7876] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |7876|: GoogleCrashHandler.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [9464] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |9464|: tv_x64.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [13916] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13916|: Teams.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [18528] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |18528|: Teams.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [18944] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |18944|: Teams.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [20152] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |20152|: MicrosoftEdgeUpdate.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [20400] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |20400|: Teams.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [27700] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |27700|: gameinputsvc.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [31224] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |31224|: GoogleUpdate.exe
15:42:42.254258C441ProcessInjector::HandleElevatedProcessFail injection to process [32736] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
15:42:42.254258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |32736|: Teams.exe
15:42:46.263258C441ProcessInjector::HandleElevatedProcessFail injection to process [16212] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x5
15:42:46.263258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |16212|: docker-mutagen.exe
15:42:46.263258C441ProcessInjector::HandleElevatedProcessFail injection to process [25564] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x5
15:42:46.263258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |25564|: com.docker.backend.exe
15:43:03.447258C441ProcessInjector::HandleElevatedProcessFail injection to process [31692] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x1f
15:43:03.447258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |31692|: vpnkit-bridge.exe
15:43:24.448258C441ProcessInjector::HandleElevatedProcessFail injection to process [23248] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x1f
15:43:24.448258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |23248|: vpnkit.exe
15:43:28.449258C441ProcessInjector::HandleElevatedProcessFail injection to process [22108] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x1f
15:43:28.449258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |22108|: com.docker.proxy.exe
15:44:02.457258C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:44:22.446258C441ProcessInjector::HandleElevatedProcessFail injection to process [16592] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:22.446258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |16592|: Code.exe
15:44:22.446258C441ProcessInjector::HandleElevatedProcessFail injection to process [19760] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:22.446258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |19760|: Code.exe
15:44:24.446258C441ProcessInjector::HandleElevatedProcessFail injection to process [18500] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:24.446258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |18500|: Code.exe
15:44:27.449258C441ProcessInjector::HandleElevatedProcessFail injection to process [31436] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:27.449258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |31436|: Code.exe
15:44:28.446258C441ProcessInjector::HandleElevatedProcessFail injection to process [23288] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:28.446258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |23288|: Code.exe
15:44:28.446258C441ProcessInjector::HandleElevatedProcessFail injection to process [27372] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:28.446258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |27372|: Code.exe
15:44:30.446258C441ProcessInjector::HandleElevatedProcessFail injection to process [13876] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
15:44:30.447258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13876|: Code.exe
15:44:35.450258C441ProcessInjector::HandleElevatedProcessFail injection to process [13168] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f
15:44:35.450258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13168|: rg.exe
15:44:35.450258C441ProcessInjector::HandleElevatedProcessFail injection to process [14104] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f
15:44:35.450258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |14104|: rg.exe
15:44:35.450258C441ProcessInjector::HandleElevatedProcessFail injection to process [18524] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f
15:44:35.450258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |18524|: rg.exe
15:44:35.450258C441ProcessInjector::HandleElevatedProcessFail injection to process [32204] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f
15:44:35.450258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |32204|: rg.exe
15:44:50.460258C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:44:51.459258C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:48:39.500258C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
16:09:25.606258C441ProcessInjector::HandleElevatedProcessFail injection to process [32492] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:09:25.606258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |32492|: Teams.exe
16:11:43.633258C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
16:18:02.682258C629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
16:20:46.685258C441ProcessInjector::HandleElevatedProcessFail injection to process [19008] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:20:46.685258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |19008|: Teams.exe
16:24:48.689258C441ProcessInjector::HandleElevatedProcessFail injection to process [28380] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
16:24:48.690258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |28380|: Teams.exe
16:29:19.865258C441ProcessInjector::HandleElevatedProcessFail injection to process [3708] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
16:29:19.865258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3708|: Code.exe
16:29:19.865258C441ProcessInjector::HandleElevatedProcessFail injection to process [6828] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
16:29:19.865258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6828|: Code.exe
16:29:19.865258C441ProcessInjector::HandleElevatedProcessFail injection to process [21628] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
16:29:19.865258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |21628|: Code.exe
16:30:50.910258C441ProcessInjector::HandleElevatedProcessFail injection to process [17252] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
16:30:50.910258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |17252|: Teams.exe
16:38:51.88258C441ProcessInjector::HandleElevatedProcessFail injection to process [13600] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:38:51.88258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13600|: Teams.exe
16:44:53.180258C441ProcessInjector::HandleElevatedProcessFail injection to process [4644] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:44:53.180258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4644|: Teams.exe
16:55:59.499258C441ProcessInjector::HandleElevatedProcessFail injection to process [15052] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:55:59.499258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |15052|: Teams.exe
16:59:59.609258C441ProcessInjector::HandleElevatedProcessFail injection to process [28524] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:59:59.609258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |28524|: Teams.exe
17:05:34.824258C441ProcessInjector::HandleElevatedProcessFail injection to process [19236] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:05:34.824258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |19236|: Teams.exe
17:11:35.977258C441ProcessInjector::HandleElevatedProcessFail injection to process [15744] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:11:35.977258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |15744|: Teams.exe
17:18:03.43258C629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
17:18:17.36258C441ProcessInjector::HandleElevatedProcessFail injection to process [17964] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:18:17.36258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |17964|: Teams.exe
17:20:29.279258C441ProcessInjector::HandleElevatedProcessFail injection to process [14404] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
17:20:29.279258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |14404|: node.exe
17:20:30.282258C441ProcessInjector::HandleElevatedProcessFail injection to process [7224] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
17:20:30.282258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |7224|: node.exe
17:20:49.282258C441ProcessInjector::HandleElevatedProcessFail injection to process [31372] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:20:49.282258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |31372|: Teams.exe
17:24:49.456258C441ProcessInjector::HandleElevatedProcessFail injection to process [19132] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
17:24:49.456258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |19132|: Teams.exe
17:46:12.868258C441ProcessInjector::HandleElevatedProcessFail injection to process [6900] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
17:46:12.868258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6900|: Teams.exe
17:53:29.395258C441ProcessInjector::HandleElevatedProcessFail injection to process [24572] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:53:29.395258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |24572|: Teams.exe
17:56:33.505258C441ProcessInjector::HandleElevatedProcessFail injection to process [30900] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:56:33.505258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |30900|: Teams.exe
18:01:19.567258C441ProcessInjector::HandleElevatedProcessFail injection to process [27364] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:01:19.567258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |27364|: Teams.exe
18:06:53.872258C441ProcessInjector::HandleElevatedProcessFail injection to process [26460] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
18:06:53.872258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |26460|: Teams.exe
18:18:02.288258C629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
18:20:51.344258C441ProcessInjector::HandleElevatedProcessFail injection to process [14536] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
18:20:51.344258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |14536|: Teams.exe
18:24:13.572258C441ProcessInjector::HandleElevatedProcessFail injection to process [26044] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
18:24:13.572258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |26044|: node.exe
18:24:14.572258C441ProcessInjector::HandleElevatedProcessFail injection to process [11696] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
18:24:14.572258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |11696|: node.exe
18:28:16.671258C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
18:29:41.682258C441ProcessInjector::HandleElevatedProcessFail injection to process [20064] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
18:29:41.682258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |20064|: Teams.exe
18:50:23.858258C441ProcessInjector::HandleElevatedProcessFail injection to process [28812] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
18:50:23.858258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |28812|: Teams.exe
18:57:08.865258C441ProcessInjector::HandleElevatedProcessFail injection to process [31796] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:57:08.866258C380ProcessInjector::HandlePendingProccesssFail to inject pending process |31796|: Teams.exe
19:02:47.2450EC66ProcessesMonitor::Stopstopping PM...
19:02:47.246970119ProcessesMonitor::ProcessEnumerateThreadexit process listener
19:02:47.2750EC526ProcessInjector::Unhookunhook running process
19:02:53.4550EC66ProcessesMonitor::Stopstopping PM...