Time | Thread | Line | Function | Message |
12:34:15.137 | 36B0 | 365 | ftw1 | Loading (pid: 13796) |
12:34:15.140 | 36B0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XE7770000>6|2|1247872178 |
12:34:15.140 | 36B0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XEA840000>6|2|1247872542 |
12:34:15.346 | 36B0 | 173 | DXManager::Detect | Found in 0 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0X1FE0|8160 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0X69650|431696 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0X20930|133424 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0X3200|12800 |
12:34:15.347 | 36B0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XE7770000 <> 0XEA840000 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0XFD058860|-49969056 |
12:34:15.347 | 36B0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XE7770000 <> 0XEA840000 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0XFD05DC30|-49947600 |
12:34:15.347 | 36B0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XE7770000 <> 0XEA840000 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0XFD05C5F0|-49953296 |
12:34:15.347 | 36B0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XE7770000 <> 0XEA840000 |
12:34:15.347 | 36B0 | 209 | Initialize::GetLocation | @ 0XFCF3A7F0|-51140624 |
12:34:15.548 | 36B0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XB4F60000>6|2|1247872542 |
12:34:15.668 | 36B0 | 129 | DXManager::Detect | OK |
12:34:15.766 | 36B0 | 186 | DXManager::Detect | Done |
12:34:15.766 | 36B0 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x55a0 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X42C70|273520 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X39570|234864 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X3F550|259408 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XB83A0|754592 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XB7EF0|753392 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X9EF0|40688 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XB7F90|753552 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X1AD20|109856 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X1D770|120688 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X25DA0|155040 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X114620|1132064 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X1140E0|1130720 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X1AC10|109584 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X1AB20|109344 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XC880|51328 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X4A100|303360 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X9A60|39520 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XCF590|849296 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XCFC60|851040 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0X9A60|39520 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XD0750|853840 |
12:34:15.767 | 36B0 | 209 | Initialize::GetLocation | @ 0XD0DB0|855472 |
12:34:15.817 | 36B0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0XB7A10000>6|2|1247870977 |
12:34:15.902 | 36B0 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
12:34:15.902 | 36B0 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
12:34:15.902 | 36B0 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
12:34:15.902 | 36B0 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
12:34:15.907 | 36B0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XAA160000>6|2|1247870977 |
12:34:15.931 | 36B0 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
12:34:15.931 | 36B0 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
12:34:15.932 | 36B0 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
12:34:15.932 | 36B0 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
12:34:15.932 | 36B0 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
12:34:15.994 | 36B0 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_19113796 opened succesfuly |
12:34:15.994 | 36B0 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x55a0 |
12:34:15.994 | 36B0 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_19113796 close 2147483647 bytes |
12:34:15.994 | 36B0 | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.191.0.20\OWExplorer.dll] |
12:34:16.296 | 36B0 | 389 | ftw1 | OWExplorer injected |
12:34:16.337 | DFC | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
12:34:20.499 | 830 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
12:34:20.500 | 830 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
12:34:20.500 | 830 | 56 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
12:34:20.500 | 830 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |100| (w: 0x0): Registry |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |1864| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |2276| (w: 0x0): MemCompression |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |2556| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |2600| (w: 0x0): C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |2660| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |2884| (w: 0x0): \Device\HarddiskVolume2\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |2916| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |3092| (w: 0x0): C:\Program Files\DellTPad\ApMsgFwd.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |3596| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\84.0.4316.43\opera_crashreporter.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |3840| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |4044| (w: 0x0): \Device\HarddiskVolume2\Program Files\DellTPad\HidMonitorSvc.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |4112| (w: 0x0): \Device\HarddiskVolume2\Program Files\LGHUB\lghub_updater.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |4980| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |4992| (w: 0x0): \Device\HarddiskVolume2\Program Files\WindowsApps\Microsoft.GamingServices_3.63.16003.0_x64__8wekyb3d8bbwe\gamingservices.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |5012| (w: 0x0): \Device\HarddiskVolume2\Program Files\WindowsApps\Microsoft.GamingServices_3.63.16003.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |5796| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |5968| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |5976| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |6092| (w: 0x0): C:\Program Files\DellTPad\ApntEx.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |6472| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |6700| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |7212| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |7412| (w: 0x0): C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |7632| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |7920| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |8164| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |8176| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |8896| (w: 0x0): C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |9160| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\crashpad_handler.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |9932| (w: 0x0): C:\Program Files\DellTPad\Apoint.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |10628| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22012.167.0_x64__8wekyb3d8bbwe\YourPhone.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |10960| (w: 0x0): \Device\HarddiskVolume2\Program Files\Realtek\Audio\HDA\RAVBg64.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |10964| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |11252| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |11404| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |12260| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |12412| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |12868| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |12980| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\crashpad_handler.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |13624| (w: 0x0): C:\Program Files\DellTPad\hidfind.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |13752| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |14040| (w: 0x0): \Device\HarddiskVolume2\Program Files\Realtek\Audio\HDA\RAVBg64.exe |
12:36:21.187 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |14244| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:37:09.624 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |11724| (w: 0x0): C:\Program Files\Google\Drive File Stream\55.0.3.0\crashpad_handler.exe |
12:41:19.14 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |10228| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:44:12.610 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |12296| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:46:13.637 | 1808 | 590 | ProcessInjector::InjectExplorerToProcess | Injected to process 9952 [mt 1088] 0x3066a |
12:47:47.859 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |13140| (w: 0x0): C:\Program Files\WindowsApps\microsoft.xboxgamingoverlay_5.721.12013.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
12:51:08.809 | 1808 | 590 | ProcessInjector::InjectExplorerToProcess | Injected to process 13848 [mt 108] 0x10047c |
12:56:04.49 | 1808 | 267 | ProcessInjector::HandlePendingProccesss | process detection skipped |248| (w: 0x0): C:\Users\cecer\AppData\Local\Programs\Opera GX\opera.exe |
12:59:33.63 | DFC | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
12:59:33.126 | 36B0 | 66 | ProcessesMonitor::Stop | stopping PM... |
12:59:33.126 | 830 | 126 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
12:59:33.127 | 36B0 | 402 | ProcessInjector::Unhook | unhook running process |