Time | Thread | Line | Function | Message |
18:09:52.682 | 3A0C | 361 | ftw1 | Loading (pid: 23748) |
18:09:52.682 | 1E68 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
18:09:52.685 | 3A0C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0XF7620000>6|2|1247870977 |
18:09:52.686 | 3A0C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0XFD100000>6|2|1247870977 |
18:09:52.743 | 3A0C | 172 | DXManager::Detect | Found in 0 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0X69160|430432 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0X20410|132112 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
18:09:52.743 | 3A0C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0XFA648850|-94074800 |
18:09:52.743 | 3A0C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0XFA64DE80|-94052736 |
18:09:52.743 | 3A0C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000 |
18:09:52.743 | 3A0C | 209 | Initialize::GetLocation | @ 0XFA64C5E0|-94059040 |
18:09:52.744 | 3A0C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000 |
18:09:52.744 | 3A0C | 209 | Initialize::GetLocation | @ 0XFA52A7F0|-95246352 |
18:09:52.751 | 3A0C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0XF44D0000>6|2|1247870977 |
18:09:52.779 | 3A0C | 129 | DXManager::Detect | OK |
18:09:52.796 | 3A0C | 186 | DXManager::Detect | Done |
18:09:52.796 | 3A0C | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X3FC10|261136 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X33840|211008 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X3BFA0|245664 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XB70E0|749792 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XB6C30|748592 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XAF40|44864 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XB6CD0|748752 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X20C40|134208 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X16A10|92688 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X2D530|185648 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X113350|1127248 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X112E10|1125904 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X20B30|133936 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X20A40|133696 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XD8D0|55504 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0X466B0|288432 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XAAB0|43696 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XCE2D0|844496 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XCE9A0|846240 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XAAB0|43696 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XCF490|849040 |
18:09:52.797 | 3A0C | 209 | Initialize::GetLocation | @ 0XCFAF0|850672 |
18:09:52.839 | 3A0C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0XABF40000>6|2|1247870977 |
18:09:52.920 | 3A0C | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
18:09:52.921 | 3A0C | 209 | Initialize::GetLocation | @ 0X4040|16448 |
18:09:52.921 | 3A0C | 209 | Initialize::GetLocation | @ 0X6410|25616 |
18:09:52.921 | 3A0C | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
18:09:52.944 | 3A0C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0XA4010000>6|2|1247870977 |
18:09:52.968 | 3A0C | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
18:09:52.970 | 3A0C | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
18:09:52.970 | 3A0C | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
18:09:52.970 | 3A0C | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
18:09:52.970 | 3A0C | 209 | Initialize::GetLocation | @ 0XD290|53904 |
18:09:53.32 | 3A0C | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_78_14_23748 opened succesfuly |
18:09:53.32 | 3A0C | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
18:09:53.32 | 3A0C | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_78_14_23748 close 2147483647 bytes |
18:09:53.32 | 3A0C | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.149.2.30\OWExplorer.dll] |
18:09:53.114 | 3A0C | 385 | ftw1 | OWExplorer injected |
18:09:53.868 | 44AC | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
18:09:53.868 | 44AC | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
18:09:53.868 | 44AC | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
18:09:53.868 | 44AC | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
18:12:24.295 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2684] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
18:12:24.295 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2684|: NVDisplay.Container.exe |
18:12:24.295 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4964] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
18:12:24.295 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4964|: nvcontainer.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2556] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2556|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3352] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3352|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6952] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6952|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8264] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8264|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8460|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8672] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8672|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8764] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8764|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9068] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9068|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9872] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9872|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10132|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10388] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10388|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11680] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11680|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11780] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11780|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12132] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12132|: MsMpEng.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13880] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13880|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13964|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14144] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14144|: node.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14444] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14444|: firefox.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20580] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20580|: Code.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23476] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23476|: node.exe |
18:12:25.308 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [25056] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:12:25.308 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |25056|: Code.exe |
18:16:31.461 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:16:31.461 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12460|: firefox.exe |
18:18:33.628 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23564] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
18:18:33.628 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23564|: firefox.exe |
18:23:22.197 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1236] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:23:22.197 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1236|: Code.exe |
18:24:56.21 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [532] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:24:56.21 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |532|: node.exe |
18:33:27.520 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17968] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5 |
18:33:27.520 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17968|: node.exe |
18:36:33.909 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11572] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
18:36:33.909 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11572|: firefox.exe |
18:36:34.925 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24800] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
18:36:34.925 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24800|: firefox.exe |
18:49:15.675 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20864] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
18:49:15.675 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20864|: firefox.exe |
19:04:32.861 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
19:04:32.861 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17964|: firefox.exe |
19:20:06.415 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10336] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
19:20:06.415 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10336|: firefox.exe |
19:38:56.669 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10180] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f |
19:38:56.669 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10180|: firefox.exe |
22:31:42.174 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10788] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5 |
22:31:42.174 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10788|: Code.exe |
22:39:19.51 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
22:39:19.52 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7964|: firefox.exe |
00:05:55.107 | 2FC8 | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8712] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x5 |
00:05:55.107 | 2FC8 | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8712|: openvpn.exe |
00:49:53.988 | 3A0C | 66 | ProcessesMonitor::Stop | stopping PM... |
00:49:53.988 | 44AC | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
00:49:59.995 | 3A0C | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |