Time | Thread | Line | Function | Message |
15:40:56.387 | 3954 | 361 | ftw1 | Loading (pid: 11592) |
15:40:56.387 | 39D8 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
15:40:56.389 | 3954 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X5A1D0000>6|2|1247871522 |
15:40:56.389 | 3954 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X5CA80000>6|2|1247871522 |
15:40:56.471 | 3954 | 172 | DXManager::Detect | Found in 0 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0X69640|431680 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
15:40:56.472 | 3954 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X5A1D0000 <> 0X5CA80000 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0XFD878860|-41449376 |
15:40:56.472 | 3954 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X5A1D0000 <> 0X5CA80000 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0XFD87DC30|-41427920 |
15:40:56.472 | 3954 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X5A1D0000 <> 0X5CA80000 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0XFD87C5F0|-41433616 |
15:40:56.472 | 3954 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X5A1D0000 <> 0X5CA80000 |
15:40:56.472 | 3954 | 209 | Initialize::GetLocation | @ 0XFD75A7F0|-42620944 |
15:40:56.483 | 3954 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X4EE20000>6|2|1247871522 |
15:40:56.573 | 3954 | 129 | DXManager::Detect | OK |
15:40:56.610 | 3954 | 186 | DXManager::Detect | Done |
15:40:56.610 | 3954 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X41060|266336 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X3CB90|248720 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XB75B0|751024 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XB7100|749824 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XB71A0|749984 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X113820|1128480 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X1132E0|1127136 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X47F90|294800 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XCE7A0|845728 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XCEE70|847472 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XCF960|850272 |
15:40:56.611 | 3954 | 209 | Initialize::GetLocation | @ 0XCFFC0|851904 |
15:40:56.625 | 3954 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0XC3A60000>6|2|1247870977 |
15:40:56.649 | 3954 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
15:40:56.649 | 3954 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
15:40:56.649 | 3954 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
15:40:56.649 | 3954 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
15:40:56.650 | 3954 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0XBFBB0000>6|2|1247870977 |
15:40:56.667 | 3954 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
15:40:56.669 | 3954 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
15:40:56.669 | 3954 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
15:40:56.669 | 3954 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
15:40:56.669 | 3954 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
15:40:56.722 | 3954 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_81_2_11592 opened succesfuly |
15:40:56.722 | 3954 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
15:40:56.722 | 3954 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_81_2_11592 close 2147483647 bytes |
15:40:56.722 | 3954 | 297 | InjectOWExplorer | Explorer file name [E:\Apps\Overwolf\0.158.1.1\OWExplorer.dll] |
15:40:56.764 | 3954 | 385 | ftw1 | OWExplorer injected |
15:40:57.239 | 3AA0 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
15:40:57.239 | 3AA0 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
15:40:57.239 | 3AA0 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
15:40:57.240 | 3AA0 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1164] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1164|: dotnet.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1296] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1296|: firefox.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1864] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1864|: dotnet.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2728] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2728|: NVDisplay.Container.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3692] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3692|: node.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7356] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7356|: fsnotifier64.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8100] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8100|: fsnotifier64.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9384|: firefox.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12028] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12028|: MsMpEng.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13184] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13184|: firefox.exe |
15:43:27.801 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13356] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
15:43:27.801 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13356|: dotnet.exe |
15:55:01.13 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10064] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:55:01.13 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10064|: firefox.exe |
15:57:00.23 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8472] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:57:00.23 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8472|: Teams.exe |
15:57:00.23 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8816] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:57:00.23 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8816|: Teams.exe |
15:57:00.23 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14528] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:57:00.23 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14528|: Teams.exe |
15:57:00.23 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15800] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:57:00.23 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15800|: Teams.exe |
15:57:07.41 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6628] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:57:07.41 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6628|: Teams.exe |
15:57:40.38 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15088] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:57:40.38 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15088|: Teams.exe |
15:59:36.56 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14884] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
15:59:36.56 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14884|: dotnet.exe |
15:59:37.57 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4376] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
15:59:37.57 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4376|: dotnet.exe |
16:11:33.316 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14564] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:11:33.316 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14564|: Teams.exe |
16:13:57.341 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16100] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:13:57.341 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16100|: Teams.exe |
16:21:20.423 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10020] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
16:21:20.423 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10020|: firefox.exe |
16:23:09.449 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9160] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:23:09.449 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9160|: Teams.exe |
16:35:00.660 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7400] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
16:35:00.660 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7400|: firefox.exe |
16:40:00.757 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15376] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
16:40:00.757 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15376|: firefox.exe |
16:41:44.771 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15584] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:41:44.771 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15584|: Teams.exe |
16:46:51.812 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14680] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
16:46:51.813 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14680|: firefox.exe |
16:51:51.886 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2936] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:51:51.886 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2936|: Teams.exe |
16:55:00.928 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3152] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
16:55:00.928 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3152|: firefox.exe |
16:55:53.936 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7820] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:55:53.936 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7820|: Teams.exe |
16:58:28.961 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16032] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:58:28.961 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16032|: Teams.exe |
17:06:45.85 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15252] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:06:45.85 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15252|: Teams.exe |
17:14:05.177 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15588] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:14:05.177 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15588|: Teams.exe |
17:15:01.197 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2216] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:15:01.197 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2216|: firefox.exe |
17:22:00.294 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3552] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:22:00.294 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3552|: Teams.exe |
17:25:09.323 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15224] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:25:09.323 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15224|: Teams.exe |
17:32:48.410 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14900] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:32:48.410 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14900|: Teams.exe |
17:41:04.513 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15164] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:41:04.513 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15164|: Teams.exe |
17:43:02.542 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11356] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:43:02.542 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11356|: firefox.exe |
17:45:00.559 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11128] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:45:00.559 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11128|: firefox.exe |
17:46:11.580 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15284] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:46:11.580 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15284|: firefox.exe |
17:50:22.624 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
17:50:22.624 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9964|: firefox.exe |
17:55:39.676 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15324] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
17:55:39.676 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15324|: Teams.exe |
18:11:06.892 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11924] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:11:06.892 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11924|: Teams.exe |
18:20:23.27 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10064] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:20:23.27 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10064|: Teams.exe |
18:35:09.86 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2952] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:35:09.86 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2952|: Teams.exe |
18:37:56.125 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4260] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:37:56.125 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4260|: Teams.exe |
18:37:56.125 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12952] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:37:56.125 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12952|: Teams.exe |
18:37:56.125 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15856] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:37:56.125 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15856|: Teams.exe |
18:37:56.125 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16512] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:37:56.125 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16512|: Teams.exe |
18:38:04.130 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5888] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:38:04.130 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5888|: Teams.exe |
18:40:32.225 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12628] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x0 |
18:40:32.225 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12628|: fsnotifier64.exe |
18:40:40.228 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13220] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:40:40.228 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13220|: node.exe |
18:40:55.236 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14384] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x0 |
18:40:55.236 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14384|: fsnotifier64.exe |
18:40:56.236 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4684] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
18:40:56.236 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4684|: dotnet.exe |
18:41:29.252 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10136] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:41:29.252 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10136|: firefox.exe |
18:41:29.252 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11112] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:41:29.252 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11112|: firefox.exe |
18:41:30.250 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15272] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:41:30.250 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15272|: firefox.exe |
18:41:40.254 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10396] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:41:40.254 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10396|: firefox.exe |
18:44:05.301 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15652] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:44:05.301 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15652|: Teams.exe |
18:51:06.448 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14784] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:51:06.448 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14784|: Teams.exe |
18:56:27.533 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13008] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
18:56:27.533 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13008|: Teams.exe |
19:01:07.587 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15248] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
19:01:07.587 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15248|: Teams.exe |
19:14:46.782 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8032] [t: 0 w_t_id: 0]- oculus-platform-runtime.exe (elevated True) 0x0 |
19:14:46.782 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8032|: oculus-platform-runtime.exe |
19:14:46.782 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8188] [t: 0 w_t_id: 0]- OculusClient.exe (elevated True) 0x0 |
19:14:46.782 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8188|: OculusClient.exe |
19:15:25.794 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15652] [t: 0 w_t_id: 0]- Creed.exe (elevated True) 0x0 |
19:15:25.795 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15652|: Creed.exe |
19:34:24.104 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2632] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x0 |
19:34:24.104 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2632|: fsnotifier64.exe |
19:34:29.105 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13468] [t: 0 w_t_id: 0]- jcef_helper.exe (elevated True) 0x0 |
19:34:29.105 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13468|: jcef_helper.exe |
19:34:29.105 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14392] [t: 0 w_t_id: 0]- jcef_helper.exe (elevated True) 0x0 |
19:34:29.105 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14392|: jcef_helper.exe |
19:34:36.109 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17048] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x0 |
19:34:36.109 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17048|: java.exe |
19:34:46.119 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8332] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
19:34:46.119 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8332|: node.exe |
19:37:07.150 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15508] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x0 |
19:37:07.150 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15508|: java.exe |
19:37:07.150 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16848] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x0 |
19:37:07.150 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16848|: java.exe |
19:37:22.153 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1916] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
19:37:22.153 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1916|: node.exe |
19:37:22.153 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14460] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
19:37:22.153 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14460|: node.exe |
19:37:44.156 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15048] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
19:37:44.156 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15048|: node.exe |
19:37:55.175 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2828] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
19:37:55.175 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2828|: firefox.exe |
19:37:55.175 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5100] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
19:37:55.175 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5100|: firefox.exe |
19:37:55.175 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5152] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
19:37:55.175 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5152|: firefox.exe |
19:40:53.214 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6372] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x5 |
19:40:53.214 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6372|: java.exe |
19:40:53.214 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9348] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x5 |
19:40:53.214 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9348|: java.exe |
19:41:12.220 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3580] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
19:41:12.220 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3580|: firefox.exe |
19:41:23.220 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2320] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
19:41:23.220 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2320|: Teams.exe |
19:44:48.243 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4400] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
19:44:48.243 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4400|: firefox.exe |
19:44:53.243 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8944] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
19:44:53.243 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8944|: firefox.exe |
19:48:03.281 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15484] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
19:48:03.281 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15484|: Teams.exe |
20:06:05.841 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13100] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
20:06:05.841 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13100|: Teams.exe |
20:12:06.915 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2940] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
20:12:06.915 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2940|: Teams.exe |
20:25:03.126 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:25:03.126 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6632|: firefox.exe |
20:25:03.126 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9656] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:25:03.126 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9656|: firefox.exe |
20:25:04.127 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11616] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:25:04.127 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11616|: firefox.exe |
20:29:25.194 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8460] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
20:29:25.194 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8460|: Teams.exe |
20:39:58.447 | 3AA4 | 421 | ProcessInjector::DoElevetedInjection | Failed to inject process [7008] 0x57 |
20:39:58.447 | 3AA4 | 377 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [7008] [t: 8500 w_t_id: 8500]- pingsender.exe (elevated True) 0x57 |
20:41:26.449 | 3AA4 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9572] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
20:41:26.449 | 3AA4 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9572|: Teams.exe |
20:46:48.981 | 3954 | 66 | ProcessesMonitor::Stop | stopping PM... |
20:46:48.981 | 3AA0 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
20:46:48.982 | 3954 | 479 | ProcessInjector::Unhook | unhook running process |