Time | Thread | Line | Function | Message |
15:29:41.201 | 4FFC | 365 | ftw1 | Loading (pid: 892) |
15:29:41.203 | 4FFC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X38370000>6|2|1203373348 |
15:29:41.203 | 4FFC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X3A140000>6|2|1203373348 |
15:29:41.206 | 4F54 | 147 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
15:29:41.398 | 4FFC | 172 | DXManager::Detect | Found in 0 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0X4660|18016 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0X662B0|418480 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0X1350|4944 |
15:29:41.399 | 4FFC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0XFE353020|-30068704 |
15:29:41.399 | 4FFC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0XFE358060|-30048160 |
15:29:41.399 | 4FFC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0XFE34E620|-30087648 |
15:29:41.399 | 4FFC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000 |
15:29:41.399 | 4FFC | 209 | Initialize::GetLocation | @ 0XFE23AA80|-31217024 |
15:29:41.434 | 4FFC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X31480000>6|2|1203373142 |
15:29:41.634 | 4FFC | 129 | DXManager::Detect | OK |
15:29:41.733 | 4FFC | 186 | DXManager::Detect | Done |
15:29:41.733 | 4FFC | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X5880|22656 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XF280|62080 |
15:29:41.735 | 4FFC | 209 | Initialize::GetLocation | @ 0XF430|62512 |
15:29:41.815 | 4FFC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X2FA60000>6|2|1203372033 |
15:29:41.958 | 4FFC | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
15:29:41.959 | 4FFC | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
15:29:41.959 | 4FFC | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
15:29:41.959 | 4FFC | 209 | Initialize::GetLocation | @ 0X6180|24960 |
15:29:41.960 | 4FFC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XDBB90000>6|2|1203372033 |
15:29:42.103 | 4FFC | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
15:29:42.104 | 4FFC | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
15:29:42.104 | 4FFC | 209 | Initialize::GetLocation | @ 0X10000|65536 |
15:29:42.104 | 4FFC | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
15:29:42.104 | 4FFC | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
15:29:42.157 | 4FFC | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_84_12_892 opened succesfuly |
15:29:42.157 | 4FFC | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
15:29:42.158 | 4FFC | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_84_12_892 close 2147483647 bytes |
15:29:42.158 | 4FFC | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.165.0.25\OWExplorer.dll] |
15:29:42.249 | 4FFC | 389 | ftw1 | OWExplorer injected |
15:29:42.250 | 4648 | 70 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
15:29:42.845 | 3B8C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
15:29:42.845 | 3B8C | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
15:29:42.845 | 3B8C | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
15:29:42.845 | 3B8C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
15:29:42.897 | 52D4 | 726 | ProcessInjector::InjectProcess | process |vpnagent.exe| missing h |
15:29:42.897 | 52D4 | 726 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
15:29:42.897 | 52D4 | 726 | ProcessInjector::InjectProcess | process |vmware-authd.exe| missing h |
15:29:42.897 | 52D4 | 726 | ProcessInjector::InjectProcess | process |WifiSvc.exe| missing h |
15:29:42.897 | 52D4 | 726 | ProcessInjector::InjectProcess | process |sqlceip.exe| missing h |
15:29:42.897 | 52D4 | 726 | ProcessInjector::InjectProcess | process |sqlservr.exe| missing h |
15:29:42.898 | 52D4 | 726 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
15:29:42.898 | 52D4 | 726 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
15:29:42.898 | 52D4 | 726 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
15:29:42.898 | 52D4 | 726 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [512] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |512|: QtWebEngineProcess.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2012] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2012|: NVDisplay.Container.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3060] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3060|: vpnagent.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3728] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3728|: Microsoft.ServiceHub.Controller.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4168] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4168|: gameinputsvc.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4392] [t: 0 w_t_id: 0]- vmware-authd.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4392|: vmware-authd.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4572] [t: 0 w_t_id: 0]- WifiSvc.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4572|: WifiSvc.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4580] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4580|: MsMpEng.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4912] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4912|: obs-browser-page.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6088] [t: 0 w_t_id: 0]- sqlceip.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6088|: sqlceip.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6096] [t: 0 w_t_id: 0]- sqlservr.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6096|: sqlservr.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7556] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7556|: DropboxUpdate.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8004] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8004|: QtWebEngineProcess.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8468] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8468|: Teams.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9136] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9136|: GoogleCrashHandler.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9664] [t: 0 w_t_id: 0]- voicemodplugin.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9664|: voicemodplugin.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9744] [t: 0 w_t_id: 0]- sdaudioswitch.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9744|: sdaudioswitch.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9748] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9748|: GoogleCrashHandler64.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10616] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10616|: node.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10628] [t: 0 w_t_id: 0]- ServiceHub.RoslynCodeAnalysisService.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10628|: ServiceHub.RoslynCodeAnalysisService.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12692] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12692|: Teams.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13264] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13264|: obs-browser-page.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14200] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14200|: Teams.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14768] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14768|: Teams.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18760] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18760|: obs-browser-page.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18776] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18776|: obs-browser-page.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19584] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19584|: QtWebEngineProcess.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19780] [t: 0 w_t_id: 0]- ServiceHub.TestWindowStoreHost.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19780|: ServiceHub.TestWindowStoreHost.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20936] [t: 0 w_t_id: 0]- ServiceHub.RoslynCodeAnalysisService.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20936|: ServiceHub.RoslynCodeAnalysisService.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21564] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21564|: Microsoft.ServiceHub.Controller.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23520] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23520|: Teams.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23912] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23912|: obs-browser-page.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24228] [t: 0 w_t_id: 0]- twitchstudiostreamdeck.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24228|: twitchstudiostreamdeck.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24372] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24372|: gameinputsvc.exe |
15:32:13.323 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [27592] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0 |
15:32:13.323 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |27592|: obs-browser-page.exe |
15:32:44.336 | 52D4 | 481 | ProcessInjector::HandleElevatedProcess | Fail injection to process [26608] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0 |
15:32:44.336 | 52D4 | 413 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |26608|: Teams.exe |
15:32:55.992 | 4648 | 75 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
15:32:57.193 | 4FFC | 66 | ProcessesMonitor::Stop | stopping PM... |
15:32:57.193 | 3B8C | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
15:32:57.193 | 4FFC | 619 | ProcessInjector::Unhook | unhook running process |
15:33:03.200 | 4FFC | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |