Time | Thread | Line | Function | Message |
16:16:46.771 | 1160 | 361 | ftw1 | Loading (pid: 6012) |
16:16:46.773 | 1160 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X58560000>6|2|1203373203 |
16:16:46.773 | 1160 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X59FB0000>6|2|1203373081 |
16:16:46.792 | 4588 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
16:16:46.929 | 1160 | 172 | DXManager::Detect | Found in 0 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0X4660|18016 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0X661F0|418288 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0X1350|4944 |
16:16:46.930 | 1160 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0XFE6D3020|-26398688 |
16:16:46.930 | 1160 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0XFE6D8060|-26378144 |
16:16:46.930 | 1160 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0XFE6CE620|-26417632 |
16:16:46.930 | 1160 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000 |
16:16:46.930 | 1160 | 209 | Initialize::GetLocation | @ 0XFE5BAA80|-27547008 |
16:16:46.955 | 1160 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X2B0B0000>6|2|1203373142 |
16:16:47.10 | 1160 | 129 | DXManager::Detect | OK |
16:16:47.51 | 1160 | 186 | DXManager::Detect | Done |
16:16:47.51 | 1160 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
16:16:47.51 | 1160 | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
16:16:47.51 | 1160 | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
16:16:47.51 | 1160 | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
16:16:47.51 | 1160 | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X5880|22656 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XF280|62080 |
16:16:47.52 | 1160 | 209 | Initialize::GetLocation | @ 0XF430|62512 |
16:16:47.68 | 1160 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X2C030000>6|2|1203372033 |
16:16:47.78 | 1160 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
16:16:47.78 | 1160 | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
16:16:47.78 | 1160 | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
16:16:47.78 | 1160 | 209 | Initialize::GetLocation | @ 0X6180|24960 |
16:16:47.87 | 1160 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X27F50000>6|2|1203372033 |
16:16:47.96 | 1160 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
16:16:47.96 | 1160 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
16:16:47.96 | 1160 | 209 | Initialize::GetLocation | @ 0X10000|65536 |
16:16:47.96 | 1160 | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
16:16:47.96 | 1160 | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
16:16:47.154 | 1160 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_6012 opened succesfuly |
16:16:47.154 | 1160 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
16:16:47.154 | 1160 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_6012 close 2147483647 bytes |
16:16:47.154 | 1160 | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.162.0.7\OWExplorer.dll] |
16:16:47.163 | 1160 | 385 | ftw1 | OWExplorer injected |
16:16:47.649 | 3DA0 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
16:16:47.649 | 3DA0 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
16:16:47.649 | 3DA0 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
16:16:47.649 | 3DA0 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |vpnagent.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |com.docker.service| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |nassvc.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |mysqld.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |tv_w32.exe| missing h |
16:16:47.675 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |tv_x64.exe| missing h |
16:16:48.115 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
16:18:03.249 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [92] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |92|: Code.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [316] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |316|: Teams.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [840] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |840|: Teams.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2804] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2804|: Code.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2812] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2812|: Code.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2968] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2968|: vpnagent.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3652] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3652|: com.docker.service |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3720] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3720|: gameinputsvc.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3956] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0 |
16:19:18.288 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3956|: vpnkit-bridge.exe |
16:19:18.288 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3984] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3984|: nassvc.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4024] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4024|: MsMpEng.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4044] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4044|: httpd.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4464] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4464|: mysqld.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5204] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5204|: DropboxUpdate.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6440] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6440|: Teams.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6484] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6484|: GoogleCrashHandler64.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7928] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7928|: Code.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7992] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7992|: httpd.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9576] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9576|: com.docker.backend.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11064] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11064|: gameinputsvc.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11136] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11136|: tv_w32.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11244] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11244|: GoogleCrashHandler.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14364] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14364|: tv_x64.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14552] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14552|: docker-mutagen.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15416] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15416|: node.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16188] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16188|: vpnkit.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16752] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16752|: Code.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16876] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16876|: Code.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17712] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17712|: Teams.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19716] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19716|: node.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19748] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19748|: Teams.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21652] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21652|: com.docker.proxy.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22120] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22120|: Code.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22224] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22224|: Code.exe |
16:19:18.289 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24256] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
16:19:18.289 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24256|: Code.exe |
16:21:42.614 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
16:21:43.702 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
16:22:00.548 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16364] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:22:00.548 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16364|: Teams.exe |
16:24:53.719 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15868] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
16:24:53.719 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15868|: Code.exe |
16:35:22.780 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18928] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:35:22.780 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18928|: Teams.exe |
16:41:23.981 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14304] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:41:23.981 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14304|: Teams.exe |
16:47:25.458 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22628] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:47:25.458 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22628|: Teams.exe |
17:02:07.22 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19952] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:02:07.22 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19952|: Teams.exe |
17:05:14.145 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
17:08:10.462 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18648] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
17:08:10.462 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18648|: Teams.exe |
17:10:14.786 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16660] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
17:10:14.786 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16660|: Code.exe |
17:11:17.921 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11268] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
17:11:17.921 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11268|: Code.exe |
17:18:02.964 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
17:23:33.183 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1836] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:23:33.183 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1836|: Teams.exe |
17:29:33.319 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8812] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:29:33.319 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8812|: Teams.exe |
17:35:34.534 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23640] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:35:34.534 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23640|: Teams.exe |
17:41:34.911 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13736] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:41:34.911 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13736|: Teams.exe |
18:18:03.57 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
18:45:43.412 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23916] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
18:45:43.412 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23916|: Teams.exe |
18:51:32.447 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
19:02:32.535 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7832] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:02:32.535 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7832|: Teams.exe |
19:07:06.560 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7640] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:07:06.560 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7640|: Teams.exe |
19:11:13.592 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23624] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:11:13.592 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23624|: Teams.exe |
19:11:28.604 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
19:11:28.604 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
19:17:14.654 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8256] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:17:14.654 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8256|: Teams.exe |
19:18:02.656 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
19:22:10.666 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
19:23:14.679 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19596] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:23:14.679 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19596|: Teams.exe |
19:27:15.699 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21208] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:27:15.699 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21208|: Teams.exe |
19:35:15.734 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16036] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
19:35:15.734 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16036|: Teams.exe |
19:41:16.915 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20548] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
19:41:16.915 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20548|: Teams.exe |
20:05:20.105 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1248] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
20:05:20.105 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1248|: Teams.exe |
20:11:21.131 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21448] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
20:11:21.132 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21448|: Teams.exe |
20:18:02.149 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
20:21:41.169 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
20:32:03.882 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14892] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
20:32:03.882 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14892|: Teams.exe |
20:32:39.915 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
20:32:52.928 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
20:40:44.339 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9272] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
20:40:44.339 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9272|: Teams.exe |
20:49:51.822 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
20:52:05.977 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11516] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
20:52:05.977 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11516|: Teams.exe |
20:57:26.217 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23728] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
20:57:26.217 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23728|: Teams.exe |
21:05:15.320 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
21:05:15.320 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
21:05:27.307 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11216] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
21:05:27.307 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11216|: Teams.exe |
21:11:28.326 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21992] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
21:11:28.326 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21992|: Teams.exe |
21:17:28.372 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17336] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
21:17:28.372 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17336|: Teams.exe |
21:18:03.371 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
21:26:09.397 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16040] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
21:26:09.397 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16040|: Teams.exe |
21:32:10.434 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1856] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
21:32:10.434 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1856|: Teams.exe |
21:38:10.445 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15400] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
21:38:10.445 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15400|: Teams.exe |
22:17:35.621 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19156] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
22:17:35.621 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19156|: Teams.exe |
22:18:02.774 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
22:23:36.138 | 5FA0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19476] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
22:23:36.138 | 5FA0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19476|: Teams.exe |
22:24:16.145 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |CCUpdate.exe| missing h |
22:24:18.142 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
22:31:38.509 | 5FA0 | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |