Time | Thread | Line | Function | Message |
15:07:57.869 | AD4 | 365 | ftw1 | Loading (pid: 17900) |
15:07:57.871 | AD4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0XB9BD0000>6|2|1247872178 |
15:07:57.871 | AD4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0XBC7A0000>6|2|1247871940 |
15:07:58.38 | AD4 | 173 | DXManager::Detect | Found in 0 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0X59E0|23008 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0X6AE20|437792 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0X211E0|135648 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0X2840|10304 |
15:07:58.38 | AD4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB9BD0000 <> 0XBC7A0000 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0XFD558860|-44726176 |
15:07:58.38 | AD4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB9BD0000 <> 0XBC7A0000 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0XFD55DC30|-44704720 |
15:07:58.38 | AD4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB9BD0000 <> 0XBC7A0000 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0XFD55C5F0|-44710416 |
15:07:58.38 | AD4 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XB9BD0000 <> 0XBC7A0000 |
15:07:58.38 | AD4 | 209 | Initialize::GetLocation | @ 0XFD43A7F0|-45897744 |
15:07:58.59 | AD4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0XAE950000>6|2|1247871904 |
15:07:58.184 | AD4 | 129 | DXManager::Detect | OK |
15:07:58.261 | AD4 | 186 | DXManager::Detect | Done |
15:07:58.261 | AD4 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
15:07:58.263 | AD4 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
15:07:58.292 | AD4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X93720000>6|2|1247870977 |
15:07:58.312 | AD4 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
15:07:58.313 | AD4 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
15:07:58.313 | AD4 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
15:07:58.313 | AD4 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
15:07:58.316 | AD4 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X47560000>6|2|1247870977 |
15:07:58.330 | AD4 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
15:07:58.331 | AD4 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
15:07:58.331 | AD4 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
15:07:58.331 | AD4 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
15:07:58.331 | AD4 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
15:07:58.386 | AD4 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_180_3_17900 opened succesfuly |
15:07:58.386 | AD4 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
15:07:58.386 | AD4 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_180_3_17900 close 2147483647 bytes |
15:07:58.387 | AD4 | 301 | InjectOWExplorer | Explorer file name [C:\Games\Overwolf\0.180.0.6\OWExplorer.dll] |
15:07:58.393 | AD4 | 389 | ftw1 | OWExplorer injected |
15:07:58.395 | 3764 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
15:07:58.607 | 5344 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
15:07:58.607 | 5344 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
15:07:58.607 | 5344 | 56 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
15:07:58.607 | 5344 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |172|: Registry |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3100|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nvrzi.inf_amd64_38a3422a01b8ac30\Display.NvContainer\NVDisplay.Container.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3616|: MemCompression |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4308|: \Device\HarddiskVolume4\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6132|: \Device\HarddiskVolume4\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6140|: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6572|: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6580|: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\gamingservices.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |7812|: C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.20.40028.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10504|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11092|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11696|: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11940|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\GoogleUpdate.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13752|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nvrzi.inf_amd64_38a3422a01b8ac30\Display.NvContainer\NVDisplay.Container.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |17096|: C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.20.40028.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |18324|: C:\Users\lucas\AppData\Local\Medal\app-4.1000.0\Medal.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19728|: C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20560|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\GazoomTrayInterface.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21308|: C:\Users\lucas\AppData\Local\Medal\app-4.1000.0\Medal.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21872|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\BS\GazoomBackgroundService.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |22472|: C:\Program Files\Riot Vanguard\vgtray.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |23056|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21084.78.0_x64__8wekyb3d8bbwe\YourPhone.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |23820|: C:\Users\lucas\AppData\Local\Medal\app-4.1000.0\Medal.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |24524|: C:\Users\lucas\AppData\Local\Medal\app-4.1000.0\Medal.exe |
15:08:58.760 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |26260|: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
15:09:01.801 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13024|: C:\Program Files (x86)\Razer\Razer Cortex\x64\PMRunner64.exe |
15:09:02.812 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19476|: C:\Program Files (x86)\Razer\Razer Cortex\x64\FPSRunner64.exe |
15:09:03.825 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |15544|: C:\Users\lucas\AppData\Local\Medal\app-4.1000.0\resources\app\Medal.exe |
15:09:05.849 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4208|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
15:09:05.849 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19704|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
15:09:10.870 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |26080|: C:\Users\lucas\AppData\Local\Medal\app-4.1000.0\Medal.exe |
15:13:28.111 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |1280|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:13:28.111 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |14772|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:13:28.111 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19124|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:13:28.111 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21568|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:13:29.118 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |24252|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:13:43.247 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |24968|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:48:16.326 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12856|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:48:16.326 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13456|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:48:16.326 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |23260|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:48:17.331 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |932|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:48:17.331 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |23476|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
15:48:22.365 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20664|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:13:40.737 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19924|: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21090.10007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe |
16:14:31.204 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12284|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:14:31.204 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12440|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:14:31.204 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19712|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:14:31.204 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21076|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:14:32.204 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12820|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:14:33.211 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |22248|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:32:11.140 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4952|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:32:11.140 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12732|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:32:11.140 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13216|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:32:11.140 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |17984|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:32:12.154 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |25336|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
16:32:26.287 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21380|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
17:14:53.892 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12204|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\GazoomTrayInterface.exe |
17:14:54.906 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |1264|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\BS\GazoomBackgroundService.exe |
17:29:15.121 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4404|: C:\Program Files\WindowsApps\AudibleInc.AudibleforWindowsPhone_10.5.67.0_x64__xns73kv1ymhp2\AudibleRT.WindowsPhone.exe |
18:12:35.306 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16880|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
18:12:36.318 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |9956|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
18:15:04.482 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21956|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
18:15:04.482 | 64E8 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |24720|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
19:10:38.652 | 3764 | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
19:10:38.669 | AD4 | 66 | ProcessesMonitor::Stop | stopping PM... |
19:10:38.669 | 5344 | 126 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |