Time | Thread | Line | Function | Message |
05:05:24.96 | 210C | 365 | ftw1 | Loading (pid: 23372) |
05:05:24.100 | 210C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X23C10000>6|2|1203373443 |
05:05:24.100 | 210C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X259C0000>6|2|1203373348 |
05:05:24.173 | 210C | 173 | DXManager::Detect | Found in 0 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0X4660|18016 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0X662B0|418480 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0X1350|4944 |
05:05:24.174 | 210C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0XFE372F20|-29937888 |
05:05:24.174 | 210C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0XFE377F60|-29917344 |
05:05:24.174 | 210C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0XFE36E620|-29956576 |
05:05:24.174 | 210C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000 |
05:05:24.174 | 210C | 209 | Initialize::GetLocation | @ 0XFE25AA80|-31085952 |
05:05:24.212 | 210C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X10F60000>6|2|1203373382 |
05:05:24.303 | 210C | 129 | DXManager::Detect | OK |
05:05:24.360 | 210C | 186 | DXManager::Detect | Done |
05:05:24.360 | 210C | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XAE030|712752 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XADB80|711552 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X5880|22656 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XADC20|711712 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X1084F0|1082608 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X107FA0|1081248 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0X3F210|258576 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XF280|62080 |
05:05:24.361 | 210C | 209 | Initialize::GetLocation | @ 0XF430|62512 |
05:05:24.382 | 210C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X9180000>6|2|1203372033 |
05:05:24.412 | 210C | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
05:05:24.413 | 210C | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
05:05:24.413 | 210C | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
05:05:24.413 | 210C | 209 | Initialize::GetLocation | @ 0X6180|24960 |
05:05:24.414 | 210C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X7060000>6|2|1203372033 |
05:05:24.437 | 210C | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
05:05:24.437 | 210C | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
05:05:24.437 | 210C | 209 | Initialize::GetLocation | @ 0X10000|65536 |
05:05:24.437 | 210C | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
05:05:24.437 | 210C | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
05:05:24.491 | 210C | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_176_7_23372 opened succesfuly |
05:05:24.491 | 210C | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
05:05:24.491 | 210C | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_176_7_23372 close 2147483647 bytes |
05:05:24.491 | 210C | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.176.87.26\OWExplorer.dll] |
05:05:24.507 | 210C | 389 | ftw1 | OWExplorer injected |
05:05:24.507 | 599C | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
05:05:24.857 | 37D8 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
05:05:24.857 | 37D8 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
05:05:24.857 | 37D8 | 56 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
05:05:24.857 | 37D8 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
05:05:36.868 | 4088 | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 7884 [mt 14888] 0x722dc |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |120|: Registry |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |140|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |1368|: \Device\HarddiskVolume2\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |1800|: C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2632|: MemCompression |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3500|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4792|: \Device\HarddiskVolume2\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4836|: \Device\HarddiskVolume2\Program Files\LGHUB\lghub_updater.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4924|: \Device\HarddiskVolume2\Program Files\MongoDB\Server\4.2\bin\mongod.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5248|: \Device\HarddiskVolume2\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5440|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6964|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.6282.0_x64__8wekyb3d8bbwe\GameBar.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |7264|: \Device\HarddiskVolume2\Program Files (x86)\Google\Update\1.3.36.102\GoogleCrashHandler.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |8524|: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |9016|: \Device\HarddiskVolume2\Program Files (x86)\Google\Update\1.3.36.102\GoogleCrashHandler64.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |9964|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21062.150.0_x64__8wekyb3d8bbwe\YourPhone.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10032|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10360|: C:\Program Files\LGHUB\lghub.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10408|: C:\Program Files\LGHUB\lghub_agent.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10520|: C:\Program Files\LGHUB\lghub.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11532|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11764|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |14972|: \Device\HarddiskVolume2\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |15248|: C:\Program Files\LGHUB\logi_analytics_client.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16436|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.6282.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16564|: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21061.10121.0_x64__8wekyb3d8bbwe\Video.UI.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |17412|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20572|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20916|: C:\Users\galit\Desktop\cmder\vendor\conemu-maximus5\ConEmu\ConEmuC64.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |21640|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:06:25.507 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |22476|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe |
05:07:11.493 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16016|: C:\Program Files\Git\usr\bin\tail.exe |
05:08:26.392 | 4088 | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 15140 [mt 7832] 0x1522de |
05:08:57.517 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |18260|: \Device\HarddiskVolume2\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe |
05:10:46.528 | 4088 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |8608|: C:\Program Files\Git\usr\bin\tail.exe |