Time | Thread | Line | Function | Message |
18:11:56.564 | 1AA4 | 74 | GameListService::CreateProcessMap | loading game list... |
18:11:56.565 | 1AA4 | 88 | GameListService::CreateProcessMap | 1628, 2 loaded |
18:11:56.566 | 1AA4 | 369 | ftw1 | Loading (pid: 18220) |
18:11:56.566 | 1AA4 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X54970000>6|2|1482491926 |
18:11:56.567 | 1AA4 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X559A0000>6|2|1482491926 |
18:11:56.673 | 1AA4 | 173 | DXManager::Detect | Found in 0 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0X347B0|214960 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0X1540|5440 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0X23820|145440 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0X19F0|6640 |
18:11:56.673 | 1AA4 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X54970000 <> 0X559A0000 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0XFF0D42F0|-15908112 |
18:11:56.673 | 1AA4 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X54970000 <> 0X559A0000 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0XFF0D1E00|-15917568 |
18:11:56.673 | 1AA4 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X54970000 <> 0X559A0000 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0XFF0D5880|-15902592 |
18:11:56.673 | 1AA4 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X54970000 <> 0X559A0000 |
18:11:56.673 | 1AA4 | 209 | Initialize::GetLocation | @ 0XFEFDBD10|-16925424 |
18:11:56.683 | 1AA4 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X18CC0000>6|2|1482491491 |
18:11:56.755 | 1AA4 | 129 | DXManager::Detect | OK |
18:11:56.789 | 1AA4 | 186 | DXManager::Detect | Done |
18:11:56.789 | 1AA4 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4030 , 0x55a0 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X3CC50|248912 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X2CFD0|184272 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X387C0|231360 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0XBC570|771440 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X482B0|295600 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0XC2B0|49840 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X48350|295760 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X2ACE0|175328 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X1F260|127584 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X1F0B0|127152 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X4AD70|306544 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X100050|1048656 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X2B030|176176 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X2AE30|175664 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X2CE30|183856 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X40A70|264816 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X176B0|95920 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X17700|96000 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X177F0|96240 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X176B0|95920 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X174D0|95440 |
18:11:56.790 | 1AA4 | 209 | Initialize::GetLocation | @ 0X17560|95584 |
18:11:56.800 | 1AA4 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0XC04E0000>6|2|1482489857 |
18:11:56.809 | 1AA4 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
18:11:56.809 | 1AA4 | 209 | Initialize::GetLocation | @ 0X3DC0|15808 |
18:11:56.809 | 1AA4 | 209 | Initialize::GetLocation | @ 0X7140|28992 |
18:11:56.809 | 1AA4 | 209 | Initialize::GetLocation | @ 0X6F00|28416 |
18:11:56.810 | 1AA4 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XD7EB0000>6|2|1482489857 |
18:11:56.817 | 1AA4 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
18:11:56.817 | 1AA4 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
18:11:56.818 | 1AA4 | 209 | Initialize::GetLocation | @ 0XB510|46352 |
18:11:56.818 | 1AA4 | 209 | Initialize::GetLocation | @ 0XE5B0|58800 |
18:11:56.818 | 1AA4 | 209 | Initialize::GetLocation | @ 0XE360|58208 |
18:11:56.878 | 1AA4 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_23018220 opened succesfuly |
18:11:56.878 | 1AA4 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4030 , 0x55a0 |
18:11:56.878 | 1AA4 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_23018220 close 2147483647 bytes |
18:11:56.878 | 1AA4 | 305 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.230.0.10\OWExplorer.dll] |
18:11:57.83 | 1AA4 | 393 | ftw1 | OWExplorer injected |
18:11:57.83 | 13FC | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |268| (w: 0x0): Registry |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4996| (w: 0x0): \Device\HarddiskVolume3\Program Files\McAfee\WPS\1.11.184.1\mc-fw-host.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3012| (w: 0x0): C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |17372| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |2884| (w: 0x0): \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdd.inf_amd64_67b1df330bec74ef\Display.NvContainer\NVDisplay.Container.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |1216| (w: 0x0): MemCompression |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4856| (w: 0x0): \Device\HarddiskVolume3\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4720| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |7668| (w: 0x0): \Device\HarddiskVolume3\Program Files\McAfee\WPS\1.11.184.1\neo\core\mc-neo-host.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4464| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |6876| (w: 0x0): C:\Windows\System32\taskhostw.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |5864| (w: 0x0): \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.GamingServices_13.80.25001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |5840| (w: 0x0): \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.GamingServices_13.80.25001.0_x64__8wekyb3d8bbwe\gamingservices.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |14752| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23062.153.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |2368| (w: 0x0): C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_661f1eb27bd1743c\ipf_helper.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |15628| (w: 0x0): C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3284| (w: 0x0): C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |10756| (w: 0x0): C:\Program Files\McAfee\WPS\1.11.184.1\mc-fw-host.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |11748| (w: 0x0): C:\Windows\System32\conhost.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |16332| (w: 0x0): C:\Windows\System32\smartscreen.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |12156| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Google\Update\1.3.36.292\GoogleCrashHandler.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18384| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |12184| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Google\Update\1.3.36.292\GoogleCrashHandler64.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |14800| (w: 0x0): C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |12600| (w: 0x0): C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.21300.10.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18396| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |16372| (w: 0x0): C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_444148fa7298b49f\RtkAudUService64.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |14572| (w: 0x0): C:\Windows\System32\ctfmon.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |14556| (w: 0x0): C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.21300.10.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |13988| (w: 0x0): C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |12612| (w: 0x0): C:\Program Files\Riot Vanguard\vgtray.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18072| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18164| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
18:13:58.50 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |17636| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
18:13:59.59 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |19824| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
18:14:00.71 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |20264| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:14:01.78 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |14444| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:14:01.78 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |19692| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:14:03.100 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |21404| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:14:03.100 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |21204| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:14:06.119 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |22104| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\Medal.exe |
18:14:11.157 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 23752 [mt 28444] 0x1107e2 |
18:14:14.184 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |24660| (w: 0x0): C:\Windows\System32\conhost.exe |
18:14:14.184 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |12992| (w: 0x0): C:\Users\logan\AppData\Local\Medal\app-4.2050.0\resources\app\Medal.exe |
18:14:16.205 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |10448| (w: 0x0): C:\Users\logan\AppData\Local\Medal\recorder-3.701.0\DLLs\crashpad_handler.exe |
18:14:21.152 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 19340 [mt 20472] 0x70844 |
18:14:34.416 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 27984 [mt 4652] 0x6031a |
18:14:38.384 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |5192| (w: 0x0): C:\Windows\System32\taskhostw.exe |
18:14:56.494 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3516| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe |
18:14:56.494 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18408| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.WinSvc.exe |
18:14:57.497 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |10936| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Dell\UpdateService\ServiceShell.exe |
18:14:58.502 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4512| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\TechHub\Dell.TechHub.exe |
18:15:00.514 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |11740| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe |
18:15:01.519 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18780| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DDVDataCollector.exe |
18:15:01.519 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |16128| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe |
18:15:21.663 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |16736| (w: 0x0): \Device\HarddiskVolume3\Program Files\McAfee\WebAdvisor\servicehost.exe |
18:15:21.663 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |10488| (w: 0x0): C:\Program Files\McAfee\WebAdvisor\uihost.exe |
18:15:34.751 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |24116| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe |
18:15:36.763 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |25380| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DTP\AnalyticsSubAgent\Dell.TechHub.Analytics.SubAgent.exe |
18:15:37.771 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |23720| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Dell\UpdateService\DCF\Dell.DCF.UA.Bradbury.API.SubAgent.exe |
18:15:40.785 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |2392| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DTP\DataManagerSubAgent\Dell.TechHub.DataManager.SubAgent.exe |
18:15:44.822 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |23272| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe |
18:15:45.822 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |20104| (w: 0x0): \Device\HarddiskVolume3\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.UserProcess.exe |
18:16:02.957 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |26192| (w: 0x0): C:\Windows\System32\cmd.exe |
18:16:02.957 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |25104| (w: 0x0): C:\Windows\System32\cmd.exe |
18:16:02.957 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |26872| (w: 0x0): C:\Windows\System32\conhost.exe |
18:16:02.957 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |9112| (w: 0x0): C:\Windows\System32\conhost.exe |
18:16:02.957 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3912| (w: 0x0): C:\Program Files\McAfee\WPS\1.11.184.1\extnhost\mc-extn-browserhost.exe |
18:16:02.957 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |26572| (w: 0x0): C:\Program Files\McAfee\WebAdvisor\browserhost.exe |
18:16:45.212 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |28484| (w: 0x0): C:\Windows\System32\GameBarPresenceWriter.exe |
18:18:37.95 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |28720| (w: 0x0): C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_4000.964.11.0_x64__8wekyb3d8bbwe\PushNotificationsLongRunningTask.exe |
18:18:42.113 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18736| (w: 0x0): C:\Windows\System32\LocationNotificationWindows.exe |
18:18:53.156 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |29156| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe |
18:18:53.156 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |17724| (w: 0x0): \Device\HarddiskVolume3\Program Files (x86)\Google\Update\GoogleUpdate.exe |
18:18:53.156 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |5976| (w: 0x0): C:\Users\logan\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe |
18:18:55.172 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |30172| (w: 0x0): C:\Users\logan\AppData\Local\Microsoft\OneDrive\23.169.0813.0001\Microsoft.SharePoint.exe |
20:53:25.515 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |23276| (w: 0x0): \Device\HarddiskVolume3\Program Files\McAfee\WPS\1.11.184.1\mc-update.exe |
20:53:25.801 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |15376| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
20:53:25.801 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |23120| (w: 0x0): C:\Windows\System32\taskhostw.exe |
20:54:57.504 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 12968 [mt 30928] 0x11086a |
20:55:12.721 | 4398 | 360 | ProcessInjector::DoElevetedInjection | Failed to inject process [25336 mt:2820 h:0x83080a] 0x57 |
20:55:32.973 | 4398 | 622 | ProcessInjector::InjectExplorerToProcess | Inject to process 25336 error (to many retires, TID detected: 1) |
20:55:33.704 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 3268 [mt 4524] 0x90502 |
20:55:50.59 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |31496| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
20:56:10.178 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |20360| (w: 0x0): C:\Windows\System32\oobe\UserOOBEBroker.exe |
20:57:16.323 | 4398 | 360 | ProcessInjector::DoElevetedInjection | Failed to inject process [4212 mt:32580 h:0x13067a] 0x57 |
20:57:36.480 | 4398 | 622 | ProcessInjector::InjectExplorerToProcess | Inject to process 4212 error (to many retires, TID detected: 1) |
20:57:38.641 | 4398 | 360 | ProcessInjector::DoElevetedInjection | Failed to inject process [32640 mt:27324 h:0x6091c] 0x57 |
20:57:58.851 | 4398 | 622 | ProcessInjector::InjectExplorerToProcess | Inject to process 32640 error (to many retires, TID detected: 1) |
20:57:59.580 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 32536 [mt 21004] 0x60972 |
20:59:08.356 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |20492| (w: 0x0): C:\Windows\System32\GameBarPresenceWriter.exe |
21:05:22.238 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |29924| (w: 0x0): C:\Windows\System32\smartscreen.exe |
21:06:06.672 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |15452| (w: 0x0): C:\Windows\System32\audiodg.exe |
21:29:00.550 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |22096| (w: 0x0): C:\Windows\System32\smartscreen.exe |
21:30:26.405 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |30132| (w: 0x0): C:\Windows\System32\taskhostw.exe |
21:50:44.398 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |26052| (w: 0x0): C:\Windows\System32\taskhostw.exe |
22:01:08.239 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |27640| (w: 0x0): C:\Windows\System32\smartscreen.exe |
22:19:11.512 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3404| (w: 0x0): C:\Windows\System32\smartscreen.exe |
15:26:40.519 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |28620| (w: 0x0): C:\Windows\System32\smartscreen.exe |
15:26:40.817 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |10520| (w: 0x0): C:\Users\logan\AppData\Local\Microsoft\OneDrive\23.169.0813.0001\FileCoAuth.exe |
15:26:40.817 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |28304| (w: 0x0): C:\Windows\System32\taskhostw.exe |
15:26:40.817 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |30752| (w: 0x0): C:\Windows\System32\cleanmgr.exe |
15:26:40.817 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |29808| (w: 0x0): C:\Windows\System32\Dism\DismHost.exe |
15:28:42.316 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 27908 [mt 14468] 0x88108c8 |
15:28:51.512 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 1460 [mt 9032] 0x5607d4 |
15:29:02.771 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 16916 [mt 31424] 0x1b0958 |
15:30:03.123 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |31748| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
15:31:13.668 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |20040| (w: 0x0): C:\Windows\System32\GameBarPresenceWriter.exe |
15:34:42.135 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |16004| (w: 0x0): C:\Users\logan\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe |
15:38:45.321 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |31624| (w: 0x0): C:\Windows\System32\taskhostw.exe |
15:38:47.343 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |17176| (w: 0x0): C:\Windows\System32\smartscreen.exe |
15:39:54.7 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |8688| (w: 0x0): C:\Users\logan\AppData\Local\Microsoft\OneDrive\23.174.0820.0003\Microsoft.SharePoint.exe |
15:47:36.308 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 4388 [mt 25532] 0xf06c2 |
15:47:55.564 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |14296| (w: 0x0): C:\Windows\System32\smartscreen.exe |
15:47:56.315 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 32116 [mt 25276] 0x2f08d2 |
15:49:18.402 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |29252| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
15:49:19.416 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |1640| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
15:49:19.416 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |21968| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
15:49:20.429 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |21132| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
15:49:20.429 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |7636| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
15:49:20.429 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |29724| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
15:50:04.868 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |24964| (w: 0x0): C:\Windows\System32\GameBarPresenceWriter.exe |
15:57:58.5 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |17748| (w: 0x0): C:\Windows\System32\taskhostw.exe |
16:05:30.198 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |32260| (w: 0x0): C:\Windows\System32\conhost.exe |
16:33:57.941 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |9692| (w: 0x0): C:\Windows\System32\conhost.exe |
16:54:52.158 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |21952| (w: 0x0): C:\Windows\System32\conhost.exe |
17:27:36.92 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3880| (w: 0x0): C:\Windows\System32\conhost.exe |
18:02:55.317 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |27776| (w: 0x0): C:\Windows\System32\SystemSettingsBroker.exe |
18:05:44.598 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4256| (w: 0x0): C:\Windows\System32\conhost.exe |
18:10:04.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |4936| (w: 0x0): C:\Windows\System32\smartscreen.exe |
18:10:05.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |6128| (w: 0x0): C:\Windows\System32\cmd.exe |
18:10:05.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |21260| (w: 0x0): C:\Windows\System32\conhost.exe |
18:10:05.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |8616| (w: 0x0): C:\Windows\System32\cmd.exe |
18:10:05.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |12820| (w: 0x0): C:\Windows\System32\conhost.exe |
18:10:05.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |27344| (w: 0x0): C:\Program Files\McAfee\WPS\1.11.184.1\extnhost\mc-extn-browserhost.exe |
18:10:05.857 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |19284| (w: 0x0): C:\Program Files\McAfee\WebAdvisor\browserhost.exe |
18:29:55.748 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |28900| (w: 0x0): C:\Windows\System32\taskhostw.exe |
15:50:20.652 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18968| (w: 0x0): C:\Users\logan\AppData\Local\Microsoft\OneDrive\23.174.0820.0003\FileCoAuth.exe |
15:50:20.652 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |18204| (w: 0x0): C:\Windows\System32\taskhostw.exe |
15:50:20.652 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |30784| (w: 0x0): C:\Users\logan\AppData\Roaming\Spotify\Spotify.exe |
15:56:48.737 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 8892 [mt 12196] 0x950622 |
15:57:03.964 | 4398 | 360 | ProcessInjector::DoElevetedInjection | Failed to inject process [17904 mt:27812 h:0x960622] 0x57 |
15:57:24.153 | 4398 | 622 | ProcessInjector::InjectExplorerToProcess | Inject to process 17904 error (to many retires, TID detected: 1) |
15:57:24.908 | 4398 | 613 | ProcessInjector::InjectExplorerToProcess | Injected to process 30116 [mt 22916] 0x1a20850 |
15:58:06.695 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |3108| (w: 0x0): C:\Windows\System32\audiodg.exe |
15:58:29.885 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |33516| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
15:59:26.375 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |5068| (w: 0x0): C:\Windows\System32\GameBarPresenceWriter.exe |
16:02:17.929 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |23284| (w: 0x0): C:\Windows\System32\smartscreen.exe |
16:50:31.909 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |34592| (w: 0x0): C:\Windows\System32\conhost.exe |
17:12:53.790 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |31752| (w: 0x0): C:\Windows\System32\conhost.exe |
17:40:51.320 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |26996| (w: 0x0): C:\Windows\System32\smartscreen.exe |
17:40:52.329 | 4398 | 281 | ProcessInjector::HandlePendingProccesss | process detection skipped |25652| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2023.11050.16005.0_x64__8wekyb3d8bbwe\PhotosService\PhotosService.exe |
17:56:24.697 | 13FC | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
17:56:24.772 | 1AA4 | 66 | ProcessesMonitor::Stop | stopping PM... |
17:56:24.772 | 1350 | 125 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
17:56:24.774 | 1AA4 | 421 | ProcessInjector::Unhook | unhook running process |