Time | Thread | Line | Function | Message |
15:40:08.133 | 50EC | 361 | ftw1 | Loading (pid: 22992) |
15:40:08.135 | 50EC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0XB7F80000>6|2|1203373203 |
15:40:08.135 | 50EC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0XB9FC0000>6|2|1203373081 |
15:40:08.201 | 2B34 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
15:40:08.979 | 50EC | 172 | DXManager::Detect | Found in 0 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0X4660|18016 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0X661F0|418288 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0X1350|4944 |
15:40:08.980 | 50EC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0XFE0E3020|-32624608 |
15:40:08.980 | 50EC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0XFE0E8060|-32604064 |
15:40:08.980 | 50EC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0XFE0DE620|-32643552 |
15:40:08.980 | 50EC | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000 |
15:40:08.980 | 50EC | 209 | Initialize::GetLocation | @ 0XFDFCAA80|-33772928 |
15:40:09.169 | 50EC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X8AB00000>6|2|1203373142 |
15:40:09.640 | 50EC | 129 | DXManager::Detect | OK |
15:40:09.865 | 50EC | 186 | DXManager::Detect | Done |
15:40:09.866 | 50EC | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X5880|22656 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XF280|62080 |
15:40:09.867 | 50EC | 209 | Initialize::GetLocation | @ 0XF430|62512 |
15:40:09.934 | 50EC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X8C7B0000>6|2|1203372033 |
15:40:09.947 | 50EC | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
15:40:09.948 | 50EC | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
15:40:09.948 | 50EC | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
15:40:09.948 | 50EC | 209 | Initialize::GetLocation | @ 0X6180|24960 |
15:40:09.951 | 50EC | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X8C760000>6|2|1203372033 |
15:40:09.961 | 50EC | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
15:40:09.961 | 50EC | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
15:40:09.961 | 50EC | 209 | Initialize::GetLocation | @ 0X10000|65536 |
15:40:09.961 | 50EC | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
15:40:09.961 | 50EC | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
15:40:10.14 | 50EC | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_82_5_22992 opened succesfuly |
15:40:10.14 | 50EC | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
15:40:10.15 | 50EC | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_82_5_22992 close 2147483647 bytes |
15:40:10.15 | 50EC | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.159.0.25\OWExplorer.dll] |
15:40:10.73 | 50EC | 385 | ftw1 | OWExplorer injected |
15:40:11.228 | 6970 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
15:40:11.228 | 6970 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
15:40:11.228 | 6970 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
15:40:11.228 | 6970 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |vpnagent.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |com.docker.service| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |nassvc.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |mysqld.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |httpd.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdge_X64_87.0.664.52_87.0.664.47.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |tv_w32.exe| missing h |
15:40:11.267 | 258C | 629 | ProcessInjector::InjectProcess | process |tv_x64.exe| missing h |
15:40:11.399 | 258C | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:40:11.445 | 258C | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:40:40.363 | 258C | 629 | ProcessInjector::InjectProcess | process |setup.exe| missing h |
15:40:51.376 | 258C | 629 | ProcessInjector::InjectProcess | process |OverwolfSetup.exe| missing h |
15:40:51.376 | 258C | 629 | ProcessInjector::InjectProcess | process |OverwolfSetup.exe| missing h |
15:40:51.376 | 258C | 629 | ProcessInjector::InjectProcess | process |setup.exe| missing h |
15:40:54.415 | 258C | 629 | ProcessInjector::InjectProcess | process |00110000000951552078DF83| missing h |
15:40:54.415 | 258C | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:41:41.197 | 258C | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:41:42.189 | 258C | 629 | ProcessInjector::InjectProcess | process |VSIXAutoUpdate.exe| missing h |
15:41:42.189 | 258C | 629 | ProcessInjector::InjectProcess | process |CCUpdate.exe| missing h |
15:41:50.196 | 258C | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
15:42:09.226 | 258C | 629 | ProcessInjector::InjectProcess | process |VSHiveStub.exe| missing h |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2672] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2672|: vpnagent.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2896] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2896|: MsMpEng.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3684] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3684|: com.docker.service |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3728] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3728|: gameinputsvc.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4048] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4048|: nassvc.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4148] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4148|: httpd.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4652] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4652|: mysqld.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5680] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5680|: GoogleCrashHandler64.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5716] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5716|: DropboxUpdate.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6276] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6276|: tv_w32.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6668] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6668|: httpd.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7876] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7876|: GoogleCrashHandler.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9464] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9464|: tv_x64.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13916] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13916|: Teams.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18528] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18528|: Teams.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18944] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18944|: Teams.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20152] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20152|: MicrosoftEdgeUpdate.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20400] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20400|: Teams.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [27700] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |27700|: gameinputsvc.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [31224] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |31224|: GoogleUpdate.exe |
15:42:42.254 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [32736] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
15:42:42.254 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |32736|: Teams.exe |
15:42:46.263 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16212] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x5 |
15:42:46.263 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16212|: docker-mutagen.exe |
15:42:46.263 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25564] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x5 |
15:42:46.263 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25564|: com.docker.backend.exe |
15:43:03.447 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [31692] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x1f |
15:43:03.447 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |31692|: vpnkit-bridge.exe |
15:43:24.448 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23248] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x1f |
15:43:24.448 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23248|: vpnkit.exe |
15:43:28.449 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22108] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x1f |
15:43:28.449 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22108|: com.docker.proxy.exe |
15:44:02.457 | 258C | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
15:44:22.446 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16592] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:22.446 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16592|: Code.exe |
15:44:22.446 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19760] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:22.446 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19760|: Code.exe |
15:44:24.446 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18500] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:24.446 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18500|: Code.exe |
15:44:27.449 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [31436] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:27.449 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |31436|: Code.exe |
15:44:28.446 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23288] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:28.446 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23288|: Code.exe |
15:44:28.446 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [27372] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:28.446 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |27372|: Code.exe |
15:44:30.446 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13876] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f |
15:44:30.447 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13876|: Code.exe |
15:44:35.450 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13168] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f |
15:44:35.450 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13168|: rg.exe |
15:44:35.450 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14104] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f |
15:44:35.450 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14104|: rg.exe |
15:44:35.450 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18524] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f |
15:44:35.450 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18524|: rg.exe |
15:44:35.450 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [32204] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x1f |
15:44:35.450 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |32204|: rg.exe |
15:44:50.460 | 258C | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:44:51.459 | 258C | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:48:39.500 | 258C | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
16:09:25.606 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [32492] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:09:25.606 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |32492|: Teams.exe |
16:11:43.633 | 258C | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
16:18:02.682 | 258C | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:20:46.685 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19008] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:20:46.685 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19008|: Teams.exe |
16:24:48.689 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [28380] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
16:24:48.690 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |28380|: Teams.exe |
16:29:19.865 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3708] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
16:29:19.865 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3708|: Code.exe |
16:29:19.865 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6828] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
16:29:19.865 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6828|: Code.exe |
16:29:19.865 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21628] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
16:29:19.865 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21628|: Code.exe |
16:30:50.910 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17252] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
16:30:50.910 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17252|: Teams.exe |
16:38:51.88 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13600] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:38:51.88 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13600|: Teams.exe |
16:44:53.180 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4644] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:44:53.180 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4644|: Teams.exe |
16:55:59.499 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15052] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:55:59.499 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15052|: Teams.exe |
16:59:59.609 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [28524] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
16:59:59.609 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |28524|: Teams.exe |
17:05:34.824 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19236] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:05:34.824 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19236|: Teams.exe |
17:11:35.977 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15744] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:11:35.977 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15744|: Teams.exe |
17:18:03.43 | 258C | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
17:18:17.36 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17964] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:18:17.36 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17964|: Teams.exe |
17:20:29.279 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14404] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
17:20:29.279 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14404|: node.exe |
17:20:30.282 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7224] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
17:20:30.282 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7224|: node.exe |
17:20:49.282 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [31372] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:20:49.282 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |31372|: Teams.exe |
17:24:49.456 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19132] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
17:24:49.456 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19132|: Teams.exe |
17:46:12.868 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6900] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
17:46:12.868 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6900|: Teams.exe |
17:53:29.395 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24572] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:53:29.395 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24572|: Teams.exe |
17:56:33.505 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [30900] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
17:56:33.505 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |30900|: Teams.exe |
18:01:19.567 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [27364] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:01:19.567 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |27364|: Teams.exe |
18:06:53.872 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [26460] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
18:06:53.872 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |26460|: Teams.exe |
18:18:02.288 | 258C | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
18:20:51.344 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14536] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
18:20:51.344 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14536|: Teams.exe |
18:24:13.572 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [26044] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
18:24:13.572 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |26044|: node.exe |
18:24:14.572 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11696] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
18:24:14.572 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11696|: node.exe |
18:28:16.671 | 258C | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
18:29:41.682 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20064] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
18:29:41.682 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20064|: Teams.exe |
18:50:23.858 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [28812] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f |
18:50:23.858 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |28812|: Teams.exe |
18:57:08.865 | 258C | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [31796] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5 |
18:57:08.866 | 258C | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |31796|: Teams.exe |
19:02:47.24 | 50EC | 66 | ProcessesMonitor::Stop | stopping PM... |
19:02:47.24 | 6970 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
19:02:47.27 | 50EC | 526 | ProcessInjector::Unhook | unhook running process |
19:02:53.45 | 50EC | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |