TimeThreadLineFunctionMessage
10:18:46.17259F4146ProcessHardwareRecorder::CommandThreadstarting recorder thread
10:18:46.1724A2C361ftw1Loading (pid: 3484)
10:18:46.1734A2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X9D0B0000>6|2|1247871722
10:18:46.1734A2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X9FCD0000>6|2|1247871722
10:18:46.3234A2C172DXManager::DetectFound in 0
10:18:46.3254A2C209Initialize::GetLocation@ 0X4F80|20352
10:18:46.3254A2C209Initialize::GetLocation@ 0X69700|431872
10:18:46.3254A2C209Initialize::GetLocation@ 0X206F0|132848
10:18:46.3254A2C209Initialize::GetLocation@ 0X1DE0|7648
10:18:46.3254A2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D0B0000 <> 0X9FCD0000
10:18:46.3254A2C209Initialize::GetLocation@ 0XFD508860|-45053856
10:18:46.3254A2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D0B0000 <> 0X9FCD0000
10:18:46.3254A2C209Initialize::GetLocation@ 0XFD50DC30|-45032400
10:18:46.3254A2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D0B0000 <> 0X9FCD0000
10:18:46.3254A2C209Initialize::GetLocation@ 0XFD50C5F0|-45038096
10:18:46.3254A2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D0B0000 <> 0X9FCD0000
10:18:46.3254A2C209Initialize::GetLocation@ 0XFD3EA7F0|-46225424
10:18:46.3424A2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X82980000>6|2|1247871638
10:18:46.4794A2C129DXManager::DetectOK
10:18:46.5494A2C186DXManager::DetectDone
10:18:46.5494A2C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
10:18:46.5494A2C209Initialize::GetLocation@ 0X41B90|269200
10:18:46.5494A2C209Initialize::GetLocation@ 0X33E20|212512
10:18:46.5494A2C209Initialize::GetLocation@ 0X3D6C0|251584
10:18:46.5494A2C209Initialize::GetLocation@ 0XB8E10|757264
10:18:46.5494A2C209Initialize::GetLocation@ 0XB8960|756064
10:18:46.5494A2C209Initialize::GetLocation@ 0XACF0|44272
10:18:46.5494A2C209Initialize::GetLocation@ 0XB8A00|756224
10:18:46.5494A2C209Initialize::GetLocation@ 0X1B6B0|112304
10:18:46.5494A2C209Initialize::GetLocation@ 0X1E100|123136
10:18:46.5494A2C209Initialize::GetLocation@ 0X26730|157488
10:18:46.5494A2C209Initialize::GetLocation@ 0X1146B0|1132208
10:18:46.5494A2C209Initialize::GetLocation@ 0X114170|1130864
10:18:46.5494A2C209Initialize::GetLocation@ 0X1B5A0|112032
10:18:46.5494A2C209Initialize::GetLocation@ 0X1B4B0|111792
10:18:46.5494A2C209Initialize::GetLocation@ 0XD680|54912
10:18:46.5494A2C209Initialize::GetLocation@ 0X493C0|299968
10:18:46.5494A2C209Initialize::GetLocation@ 0XA860|43104
10:18:46.5494A2C209Initialize::GetLocation@ 0XD0000|851968
10:18:46.5494A2C209Initialize::GetLocation@ 0XD06D0|853712
10:18:46.5494A2C209Initialize::GetLocation@ 0XA860|43104
10:18:46.5494A2C209Initialize::GetLocation@ 0XD11C0|856512
10:18:46.5494A2C209Initialize::GetLocation@ 0XD1820|858144
10:18:46.5704A2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X54400000>6|2|1247870977
10:18:46.5894A2C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
10:18:46.5894A2C209Initialize::GetLocation@ 0X4040|16448
10:18:46.5894A2C209Initialize::GetLocation@ 0X6410|25616
10:18:46.5894A2C209Initialize::GetLocation@ 0X65C0|26048
10:18:46.5904A2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X31400000>6|2|1247870977
10:18:46.6064A2C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
10:18:46.6064A2C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
10:18:46.6064A2C209Initialize::GetLocation@ 0XA5D0|42448
10:18:46.6064A2C209Initialize::GetLocation@ 0XD4D0|54480
10:18:46.6064A2C209Initialize::GetLocation@ 0XD290|53904
10:18:46.6634A2C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_3484 opened succesfuly
10:18:46.6634A2C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
10:18:46.6644A2C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_3484 close 2147483647 bytes
10:18:46.6644A2C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.162.0.13\OWExplorer.dll]
10:18:46.6664A2C385ftw1OWExplorer injected
10:18:46.951633C51`anonymous-namespace'::CreateProviderInitialize provider: NET
10:18:46.951633C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
10:18:46.951633C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
10:18:46.951633C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
10:18:46.9624330629ProcessInjector::InjectProcessprocess |CTAudSvc.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |EvtEng.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |RzSDKServer.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |GCloud.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |IAStorDataMgrSvc.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |LMS.exe| missing h
10:18:46.9624330629ProcessInjector::InjectProcessprocess |XSpltVidSvc.exe| missing h
10:18:46.9634330629ProcessInjector::InjectProcessprocess |nvfvsdksvc_x64.exe| missing h
10:18:46.9634330629ProcessInjector::InjectProcessprocess |PresentMon_x64.exe| missing h
10:18:47.264330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:18:47.264330629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:18:47.1484330629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:18:47.1484330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:18:47.1484330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:18:47.3314330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:18:49.8324330629ProcessInjector::InjectProcessprocess |owver64.exe| missing h
10:19:01.7784330629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
10:19:05.8014330629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
10:19:05.8014330629ProcessInjector::InjectProcessprocess |AORUS.exe| missing h
10:19:10.8314330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:19:12.8394330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:19:13.8634330629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:19:14.8564330629ProcessInjector::InjectProcessprocess |AORUS.exe| missing h
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [2416] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |2416|: NVDisplay.Container.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [3396] [t: 0 w_t_id: 0]- CTAudSvc.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |3396|: CTAudSvc.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [4124] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |4124|: nvcontainer.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [4156] [t: 0 w_t_id: 0]- EvtEng.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |4156|: EvtEng.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [4208] [t: 0 w_t_id: 0]- RzSDKServer.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |4208|: RzSDKServer.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [6136] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |6136|: DropboxUpdate.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [10812] [t: 0 w_t_id: 0]- nvfvsdksvc_x64.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |10812|: nvfvsdksvc_x64.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [10888] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |10888|: LMS.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [11528] [t: 0 w_t_id: 0]- PresentMon_x64.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |11528|: PresentMon_x64.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [14372] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |14372|: NVIDIA Share.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [17044] [t: 0 w_t_id: 0]- XSpltVidSvc.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |17044|: XSpltVidSvc.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [19028] [t: 0 w_t_id: 0]- GCloud.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |19028|: GCloud.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [19652] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |19652|: MsMpEng.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [19936] [t: 0 w_t_id: 0]- IAStorDataMgrSvc.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |19936|: IAStorDataMgrSvc.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [20360] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |20360|: NVIDIA Share.exe
10:21:17.8214330441ProcessInjector::HandleElevatedProcessFail injection to process [22996] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
10:21:17.8214330380ProcessInjector::HandlePendingProccesssFail to inject pending process |22996|: MicrosoftEdgeUpdate.exe
10:21:20.8244330441ProcessInjector::HandleElevatedProcessFail injection to process [8868] [t: 0 w_t_id: 0]- Zygor.exe (elevated True) 0x0
10:21:20.8254330380ProcessInjector::HandlePendingProccesssFail to inject pending process |8868|: Zygor.exe
10:21:20.8254330441ProcessInjector::HandleElevatedProcessFail injection to process [9848] [t: 0 w_t_id: 0]- Zygor.exe (elevated True) 0x0
10:21:20.8254330380ProcessInjector::HandlePendingProccesssFail to inject pending process |9848|: Zygor.exe
10:21:20.8254330441ProcessInjector::HandleElevatedProcessFail injection to process [10200] [t: 0 w_t_id: 0]- Zygor.exe (elevated True) 0x0
10:21:20.8254330380ProcessInjector::HandlePendingProccesssFail to inject pending process |10200|: Zygor.exe
10:21:42.174330441ProcessInjector::HandleElevatedProcessFail injection to process [17624] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:42.174330380ProcessInjector::HandlePendingProccesssFail to inject pending process |17624|: firefox.exe
10:21:44.224330441ProcessInjector::HandleElevatedProcessFail injection to process [6744] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:44.224330380ProcessInjector::HandlePendingProccesssFail to inject pending process |6744|: firefox.exe
10:21:44.224330441ProcessInjector::HandleElevatedProcessFail injection to process [11532] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:44.224330380ProcessInjector::HandlePendingProccesssFail to inject pending process |11532|: firefox.exe
10:21:45.324330441ProcessInjector::HandleElevatedProcessFail injection to process [9612] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:45.324330380ProcessInjector::HandlePendingProccesssFail to inject pending process |9612|: firefox.exe
10:21:45.324330441ProcessInjector::HandleElevatedProcessFail injection to process [19720] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:45.324330380ProcessInjector::HandlePendingProccesssFail to inject pending process |19720|: firefox.exe
10:21:48.484330441ProcessInjector::HandleElevatedProcessFail injection to process [20156] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:48.484330380ProcessInjector::HandlePendingProccesssFail to inject pending process |20156|: firefox.exe
10:21:49.584330441ProcessInjector::HandleElevatedProcessFail injection to process [20980] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:49.584330380ProcessInjector::HandlePendingProccesssFail to inject pending process |20980|: firefox.exe
10:21:50.674330441ProcessInjector::HandleElevatedProcessFail injection to process [20436] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:21:50.674330380ProcessInjector::HandlePendingProccesssFail to inject pending process |20436|: firefox.exe
10:23:14.6974330441ProcessInjector::HandleElevatedProcessFail injection to process [11380] [t: 0 w_t_id: 0]- curseforge.exe (elevated True) 0x0
10:23:14.6974330380ProcessInjector::HandlePendingProccesssFail to inject pending process |11380|: curseforge.exe
10:23:29.8134330441ProcessInjector::HandleElevatedProcessFail injection to process [16932] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:23:29.8144330380ProcessInjector::HandlePendingProccesssFail to inject pending process |16932|: firefox.exe
10:23:41.9114330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:23:42.9214330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:36:14.4854330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:38:10.2684330441ProcessInjector::HandleElevatedProcessFail injection to process [21296] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:38:10.2684330380ProcessInjector::HandlePendingProccesssFail to inject pending process |21296|: firefox.exe
10:41:45.8514330441ProcessInjector::HandleElevatedProcessFail injection to process [828] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:41:45.8514330380ProcessInjector::HandlePendingProccesssFail to inject pending process |828|: firefox.exe
10:47:57.5324330441ProcessInjector::HandleElevatedProcessFail injection to process [17508] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:47:57.5324330380ProcessInjector::HandlePendingProccesssFail to inject pending process |17508|: firefox.exe
10:48:04.5734330441ProcessInjector::HandleElevatedProcessFail injection to process [13096] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:48:04.5734330380ProcessInjector::HandlePendingProccesssFail to inject pending process |13096|: firefox.exe
10:48:07.6094330441ProcessInjector::HandleElevatedProcessFail injection to process [18700] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:48:07.6094330380ProcessInjector::HandlePendingProccesssFail to inject pending process |18700|: firefox.exe
10:48:11.6414330441ProcessInjector::HandleElevatedProcessFail injection to process [10996] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:48:11.6414330380ProcessInjector::HandlePendingProccesssFail to inject pending process |10996|: firefox.exe
10:50:51.7454330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:50:51.7454330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:50:51.7454330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:50:51.7454330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:58:02.6104330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:58:45.8704330441ProcessInjector::HandleElevatedProcessFail injection to process [22928] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
10:58:45.8704330380ProcessInjector::HandlePendingProccesssFail to inject pending process |22928|: firefox.exe
11:01:04.8474330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
11:01:04.8474330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
11:01:04.8474330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
11:01:04.8474330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
11:29:32.8574330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
11:36:58.4374330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
11:58:02.3404330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
12:05:49.8274330441ProcessInjector::HandleElevatedProcessFail injection to process [3240] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
12:05:49.8274330380ProcessInjector::HandlePendingProccesssFail to inject pending process |3240|: firefox.exe
12:21:06.5184330629ProcessInjector::InjectProcessprocess |VSIXAutoUpdate.exe| missing h
12:21:06.5184330629ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
12:23:00.2964330441ProcessInjector::HandleElevatedProcessFail injection to process [17648] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
12:23:00.2964330380ProcessInjector::HandlePendingProccesssFail to inject pending process |17648|: firefox.exe
12:36:58.4444330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
12:55:24.2694330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:58:02.4094330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
13:06:10.6434330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:06:10.6434330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:36:58.4244330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
13:58:03.3414330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
14:24:26.5504330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
14:36:57.9204330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
14:55:39.2994330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
14:55:39.2994330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
14:58:02.4244330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
14:59:17.9804330441ProcessInjector::HandleElevatedProcessFail injection to process [4480] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:17.9804330380ProcessInjector::HandlePendingProccesssFail to inject pending process |4480|: msedge.exe
14:59:17.9804330441ProcessInjector::HandleElevatedProcessFail injection to process [18876] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:17.9804330380ProcessInjector::HandlePendingProccesssFail to inject pending process |18876|: msedge.exe
14:59:17.9804330441ProcessInjector::HandleElevatedProcessFail injection to process [19104] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:17.9804330380ProcessInjector::HandlePendingProccesssFail to inject pending process |19104|: msedge.exe
14:59:17.9804330441ProcessInjector::HandleElevatedProcessFail injection to process [20664] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:17.9804330380ProcessInjector::HandlePendingProccesssFail to inject pending process |20664|: msedge.exe
14:59:30.584330441ProcessInjector::HandleElevatedProcessFail injection to process [18604] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:30.584330380ProcessInjector::HandlePendingProccesssFail to inject pending process |18604|: msedge.exe
14:59:33.814330441ProcessInjector::HandleElevatedProcessFail injection to process [2452] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:33.814330380ProcessInjector::HandlePendingProccesssFail to inject pending process |2452|: msedge.exe
14:59:33.814330441ProcessInjector::HandleElevatedProcessFail injection to process [7900] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:33.814330380ProcessInjector::HandlePendingProccesssFail to inject pending process |7900|: msedge.exe
14:59:33.814330441ProcessInjector::HandleElevatedProcessFail injection to process [13624] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:33.814330380ProcessInjector::HandlePendingProccesssFail to inject pending process |13624|: msedge.exe
14:59:33.814330441ProcessInjector::HandleElevatedProcessFail injection to process [19228] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:33.814330380ProcessInjector::HandlePendingProccesssFail to inject pending process |19228|: msedge.exe
14:59:34.884330441ProcessInjector::HandleElevatedProcessFail injection to process [7180] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:34.884330380ProcessInjector::HandlePendingProccesssFail to inject pending process |7180|: msedge.exe
14:59:34.884330441ProcessInjector::HandleElevatedProcessFail injection to process [15500] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:34.884330380ProcessInjector::HandlePendingProccesssFail to inject pending process |15500|: msedge.exe
14:59:36.944330441ProcessInjector::HandleElevatedProcessFail injection to process [9444] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:36.944330380ProcessInjector::HandlePendingProccesssFail to inject pending process |9444|: msedge.exe
14:59:36.944330441ProcessInjector::HandleElevatedProcessFail injection to process [17272] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:36.944330380ProcessInjector::HandlePendingProccesssFail to inject pending process |17272|: msedge.exe
14:59:37.1084330441ProcessInjector::HandleElevatedProcessFail injection to process [11936] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:37.1084330380ProcessInjector::HandlePendingProccesssFail to inject pending process |11936|: msedge.exe
14:59:37.1084330441ProcessInjector::HandleElevatedProcessFail injection to process [13548] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:37.1084330380ProcessInjector::HandlePendingProccesssFail to inject pending process |13548|: msedge.exe
14:59:37.1084330441ProcessInjector::HandleElevatedProcessFail injection to process [16832] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
14:59:37.1084330380ProcessInjector::HandlePendingProccesssFail to inject pending process |16832|: msedge.exe
15:01:42.464330441ProcessInjector::HandleElevatedProcessFail injection to process [26608] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
15:01:42.464330380ProcessInjector::HandlePendingProccesssFail to inject pending process |26608|: msedge.exe
15:02:42.4844330441ProcessInjector::HandleElevatedProcessFail injection to process [7224] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
15:02:42.4844330380ProcessInjector::HandlePendingProccesssFail to inject pending process |7224|: msedge.exe
15:28:14.2744330629ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
15:30:44.3684330441ProcessInjector::HandleElevatedProcessFail injection to process [10588] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
15:30:44.3684330380ProcessInjector::HandlePendingProccesssFail to inject pending process |10588|: EasyAntiCheat.exe
15:33:36.7374330629ProcessInjector::InjectProcessprocess |PresentMon_x64.exe| missing h
15:36:58.2094330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
15:36:58.2094330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
15:58:02.3694330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
16:16:54.9754330441ProcessInjector::HandleElevatedProcessFail injection to process [12680] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
16:16:54.9754330380ProcessInjector::HandlePendingProccesssFail to inject pending process |12680|: owobs-ffmpeg-mux.exe
16:21:19.784330441ProcessInjector::HandleElevatedProcessFail injection to process [26104] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
16:21:19.784330380ProcessInjector::HandlePendingProccesssFail to inject pending process |26104|: owobs-ffmpeg-mux.exe
16:36:58.1024330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
16:37:58.5524330441ProcessInjector::HandleElevatedProcessFail injection to process [21092] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5
16:37:58.5524330380ProcessInjector::HandlePendingProccesssFail to inject pending process |21092|: owobs-ffmpeg-mux.exe
16:48:49.2744330441ProcessInjector::HandleElevatedProcessFail injection to process [7904] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5
16:48:49.2744330380ProcessInjector::HandlePendingProccesssFail to inject pending process |7904|: owobs-ffmpeg-mux.exe
16:55:24.3384330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:58:02.4634330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
17:01:58.2294330441ProcessInjector::HandleElevatedProcessFail injection to process [4612] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5
17:01:58.2294330380ProcessInjector::HandlePendingProccesssFail to inject pending process |4612|: owobs-ffmpeg-mux.exe
17:06:11.1394330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:06:11.1394330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:17:14.1724330441ProcessInjector::HandleElevatedProcessFail injection to process [15160] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x1f
17:17:14.1724330380ProcessInjector::HandlePendingProccesssFail to inject pending process |15160|: owobs-ffmpeg-mux.exe
17:22:44.7944330629ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
17:25:14.9304330441ProcessInjector::HandleElevatedProcessFail injection to process [16412] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
17:25:14.9304330380ProcessInjector::HandlePendingProccesssFail to inject pending process |16412|: EasyAntiCheat.exe
17:27:07.7554330441ProcessInjector::HandleElevatedProcessFail injection to process [17312] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
17:27:07.7554330380ProcessInjector::HandlePendingProccesssFail to inject pending process |17312|: owobs-ffmpeg-mux.exe
17:36:58.2134330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
17:58:02.4244330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
18:12:20.2194330441ProcessInjector::HandleElevatedProcessFail injection to process [10384] [t: 0 w_t_id: 0]- ErrorReportLauncher.exe (elevated True) 0x0
18:12:20.2194330380ProcessInjector::HandlePendingProccesssFail to inject pending process |10384|: ErrorReportLauncher.exe
18:24:26.7874330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:24:27.7924330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:36:58.5524330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
18:58:02.294330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
19:36:58.5374330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
19:56:41.6894330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:56:41.6894330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:56:41.6894330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:56:41.6894330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:58:02.3144330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
20:36:59.884330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
20:55:24.4284330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
20:58:02.6884330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
21:01:14.654330629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
21:01:33.1964330629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
21:06:11.684330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
21:06:11.684330629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
21:36:58.7984330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
21:58:03.884330629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
22:24:27.154330629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
22:50:21.7354A2C66ProcessesMonitor::Stopstopping PM...
22:50:21.735633C119ProcessesMonitor::ProcessEnumerateThreadexit process listener
22:50:21.7374A2C526ProcessInjector::Unhookunhook running process