Time | Thread | Line | Function | Message |
19:11:30.660 | 4C70 | 365 | ftw1 | Loading (pid: 12568) |
19:11:30.663 | 4C70 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X2BD50000>6|2|1247872178 |
19:11:30.663 | 4C70 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X2E780000>6|2|1247871940 |
19:11:30.818 | 4C70 | 173 | DXManager::Detect | Found in 0 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0X59E0|23008 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0X6AE20|437792 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0X211E0|135648 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0X2840|10304 |
19:11:30.820 | 4C70 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X2BD50000 <> 0X2E780000 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0XFD6F8860|-43022240 |
19:11:30.820 | 4C70 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X2BD50000 <> 0X2E780000 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0XFD6FDC30|-43000784 |
19:11:30.820 | 4C70 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X2BD50000 <> 0X2E780000 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0XFD6FC5F0|-43006480 |
19:11:30.820 | 4C70 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X2BD50000 <> 0X2E780000 |
19:11:30.820 | 4C70 | 209 | Initialize::GetLocation | @ 0XFD5DA7F0|-44193808 |
19:11:30.845 | 4C70 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X23FA0000>6|2|1247871904 |
19:11:30.999 | 4C70 | 129 | DXManager::Detect | OK |
19:11:31.62 | 4C70 | 186 | DXManager::Detect | Done |
19:11:31.63 | 4C70 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
19:11:31.64 | 4C70 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
19:11:31.87 | 4C70 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0XBBCC0000>6|2|1247870977 |
19:11:31.134 | 4C70 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
19:11:31.134 | 4C70 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
19:11:31.134 | 4C70 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
19:11:31.134 | 4C70 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
19:11:31.138 | 4C70 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0XFBB00000>6|2|1247870977 |
19:11:31.166 | 4C70 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
19:11:31.167 | 4C70 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
19:11:31.167 | 4C70 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
19:11:31.167 | 4C70 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
19:11:31.167 | 4C70 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
19:11:31.223 | 4C70 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_180_3_12568 opened succesfuly |
19:11:31.223 | 4C70 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
19:11:31.223 | 4C70 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_180_3_12568 close 2147483647 bytes |
19:11:31.223 | 4C70 | 301 | InjectOWExplorer | Explorer file name [C:\Games\Overwolf\0.180.0.6\OWExplorer.dll] |
19:11:31.232 | 4C70 | 389 | ftw1 | OWExplorer injected |
19:11:31.233 | 5484 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
19:11:31.532 | 5480 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
19:11:31.532 | 5480 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
19:11:31.532 | 5480 | 56 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
19:11:31.532 | 5480 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |172|: Registry |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3204|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nvrzi.inf_amd64_38a3422a01b8ac30\Display.NvContainer\NVDisplay.Container.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3352|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nvrzi.inf_amd64_38a3422a01b8ac30\Display.NvContainer\NVDisplay.Container.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3644|: MemCompression |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4548|: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5156|: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5236|: \Device\HarddiskVolume4\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5276|: \Device\HarddiskVolume4\Program Files\Norton Security\Engine\22.21.9.25\nsWscSvc.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5468|: \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\gamingservices.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |7228|: \Device\HarddiskVolume4\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |8524|: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |8544|: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10340|: \Device\HarddiskVolume4\Program Files\Norton Security\Engine\22.21.9.25\NortonSecurity.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11584|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21084.78.0_x64__8wekyb3d8bbwe\YourPhone.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11604|: C:\Program Files\Norton Security\Engine\22.21.9.25\NortonSecurity.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13076|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13476|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |14548|: C:\Program Files\Riot Vanguard\vgtray.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |14696|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\GazoomTrayInterface.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |15464|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16192|: C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16472|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\BS\GazoomBackgroundService.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |17216|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20180|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20224|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20232|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20412|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20804|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
19:12:31.643 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21364|: C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2140.5.0_x64__cv1g1gvanyjgm\app\WhatsApp.exe |
19:12:35.671 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |18908|: C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.20.40028.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe |
19:12:36.678 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |23076|: C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.20.40028.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe |
19:12:41.719 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21076|: C:\Program Files (x86)\Razer\Razer Cortex\x64\PMRunner64.exe |
19:12:42.728 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3164|: C:\Program Files (x86)\Razer\Razer Cortex\x64\FPSRunner64.exe |
19:13:31.96 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4840|: C:\Program Files\WindowsApps\AudibleInc.AudibleforWindowsPhone_10.5.67.0_x64__xns73kv1ymhp2\AudibleRT.WindowsPhone.exe |
19:15:00.564 | 5488 | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 13184 [mt 25484] 0x4097c |
19:15:39.997 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2864|: \Device\HarddiskVolume4\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe |
19:15:50.31 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |19236|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBar.exe |
19:15:51.45 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |23460|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
19:25:31.276 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11508|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
19:25:31.276 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21588|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBar.exe |
19:42:12.647 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |15344|: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21092.10731.0_x64__8wekyb3d8bbwe\Video.UI.exe |
19:59:22.364 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |17208|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\BS\GazoomBackgroundService.exe |
20:11:14.261 | 5488 | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 19096 [mt 5752] 0x250232 |
20:11:52.878 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5384|: \Device\HarddiskVolume4\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe |
20:12:03.975 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6632|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
20:30:10.706 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |26844|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBar.exe |
20:30:10.706 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |26976|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
20:33:06.140 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |27096|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
20:33:07.152 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3716|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe |
20:34:49.975 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4704|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBar.exe |
20:34:49.975 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |9784|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
20:47:44.890 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10068|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nvrzi.inf_amd64_38a3422a01b8ac30\Display.NvContainer\NVDisplay.Container.exe |
21:17:57.971 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21256|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\GazoomTrayInterface.exe |
21:17:58.982 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |12748|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\BS\GazoomBackgroundService.exe |
21:22:06.983 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |26352|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
21:22:06.983 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |28604|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.9022.0_x64__8wekyb3d8bbwe\GameBar.exe |
21:23:18.513 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |492|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\GazoomTrayInterface.exe |
21:23:19.519 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |26272|: C:\Users\lucas\AppData\Local\Gazoom\gazoom-cloud-sync\BS\GazoomBackgroundService.exe |
21:32:47.778 | 5488 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11016|: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21090.10007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe |
21:34:47.448 | 5484 | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
21:34:47.478 | 4C70 | 66 | ProcessesMonitor::Stop | stopping PM... |
21:34:47.478 | 5480 | 126 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
21:34:47.486 | 4C70 | 394 | ProcessInjector::Unhook | unhook running process |