TimeThreadLineFunctionMessage
04:35:26.68044B0365ftw1Loading (pid: 252)
04:35:26.68344B048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X23C10000>6|2|1203373443
04:35:26.68344B048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X259C0000>6|2|1203373348
04:35:27.11544B0173DXManager::DetectFound in 0
04:35:27.11544B0209Initialize::GetLocation@ 0X4660|18016
04:35:27.11544B0209Initialize::GetLocation@ 0X662B0|418480
04:35:27.11544B0209Initialize::GetLocation@ 0X19DB0|105904
04:35:27.11544B0209Initialize::GetLocation@ 0X1350|4944
04:35:27.11544B0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000
04:35:27.11544B0209Initialize::GetLocation@ 0XFE372F20|-29937888
04:35:27.11544B0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000
04:35:27.11544B0209Initialize::GetLocation@ 0XFE377F60|-29917344
04:35:27.11544B0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000
04:35:27.11544B0209Initialize::GetLocation@ 0XFE36E620|-29956576
04:35:27.11544B0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X23C10000 <> 0X259C0000
04:35:27.11544B0209Initialize::GetLocation@ 0XFE25AA80|-31085952
04:35:27.54944B048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X10F60000>6|2|1203373382
04:35:27.72944B0129DXManager::DetectOK
04:35:27.80644B0186DXManager::DetectDone
04:35:27.80644B0215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
04:35:27.80744B0209Initialize::GetLocation@ 0X3AC00|240640
04:35:27.80744B0209Initialize::GetLocation@ 0X2C5B0|181680
04:35:27.80744B0209Initialize::GetLocation@ 0X36D00|224512
04:35:27.80744B0209Initialize::GetLocation@ 0XAE030|712752
04:35:27.80744B0209Initialize::GetLocation@ 0XADB80|711552
04:35:27.80744B0209Initialize::GetLocation@ 0X5880|22656
04:35:27.80744B0209Initialize::GetLocation@ 0XADC20|711712
04:35:27.80744B0209Initialize::GetLocation@ 0X20FF0|135152
04:35:27.80744B0209Initialize::GetLocation@ 0X1CA60|117344
04:35:27.80744B0209Initialize::GetLocation@ 0X1C8E0|116960
04:35:27.80744B0209Initialize::GetLocation@ 0X1084F0|1082608
04:35:27.80744B0209Initialize::GetLocation@ 0X107FA0|1081248
04:35:27.80744B0209Initialize::GetLocation@ 0X248B0|149680
04:35:27.80744B0209Initialize::GetLocation@ 0X247A0|149408
04:35:27.80744B0209Initialize::GetLocation@ 0X2C440|181312
04:35:27.80744B0209Initialize::GetLocation@ 0X3F210|258576
04:35:27.80744B0209Initialize::GetLocation@ 0XF3E0|62432
04:35:27.80744B0209Initialize::GetLocation@ 0XF4E0|62688
04:35:27.80744B0209Initialize::GetLocation@ 0XF5D0|62928
04:35:27.80744B0209Initialize::GetLocation@ 0XF3E0|62432
04:35:27.80744B0209Initialize::GetLocation@ 0XF280|62080
04:35:27.80744B0209Initialize::GetLocation@ 0XF430|62512
04:35:27.87844B048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X7080000>6|2|1203372033
04:35:27.94344B083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
04:35:27.94344B0209Initialize::GetLocation@ 0X3CC0|15552
04:35:27.94344B0209Initialize::GetLocation@ 0X5FD0|24528
04:35:27.94344B0209Initialize::GetLocation@ 0X6180|24960
04:35:27.94544B048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XFC970000>6|2|1203372033
04:35:27.97944B093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
04:35:27.97944B0110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
04:35:27.98044B0209Initialize::GetLocation@ 0X10000|65536
04:35:27.98044B0209Initialize::GetLocation@ 0X12C80|76928
04:35:27.98044B0209Initialize::GetLocation@ 0X12A60|76384
04:35:28.3544B0225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_176_7_252 opened succesfuly
04:35:28.3644B072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
04:35:28.3644B0255InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_176_7_252 close 2147483647 bytes
04:35:28.3744B0301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.176.87.26\OWExplorer.dll]
04:35:28.6444B0389ftw1OWExplorer injected
04:35:28.65113071Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
04:35:28.88558C053`anonymous-namespace'::CreateProviderInitialize provider: NET
04:35:28.88558C0117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
04:35:28.88558C056`anonymous-namespace'::CreateProviderFail to initlized provider: NET
04:35:28.88558C053`anonymous-namespace'::CreateProviderInitialize provider: GPU
04:35:43.281A44564ProcessInjector::InjectExplorerToProcessInjected to process 21144 [mt 23180] 0xa22c8
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |120|: Registry
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |2632|: MemCompression
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |4792|: \Device\HarddiskVolume2\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |4836|: \Device\HarddiskVolume2\Program Files\LGHUB\lghub_updater.exe
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |4924|: \Device\HarddiskVolume2\Program Files\MongoDB\Server\4.2\bin\mongod.exe
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |5248|: \Device\HarddiskVolume2\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |7264|: \Device\HarddiskVolume2\Program Files (x86)\Google\Update\1.3.36.102\GoogleCrashHandler.exe
04:36:28.9541A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |9016|: \Device\HarddiskVolume2\Program Files (x86)\Google\Update\1.3.36.102\GoogleCrashHandler64.exe
04:36:28.9551A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |9964|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21062.150.0_x64__8wekyb3d8bbwe\YourPhone.exe
04:36:28.9551A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |10360|: C:\Program Files\LGHUB\lghub.exe
04:36:28.9551A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |10408|: C:\Program Files\LGHUB\lghub_agent.exe
04:36:28.9551A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |10520|: C:\Program Files\LGHUB\lghub.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |140|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |1368|: \Device\HarddiskVolume2\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |1800|: C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |3500|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |5440|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |7500|: C:\Program Files\nodejs\node.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |8524|: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21070.22007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |10032|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |11532|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |11764|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |15248|: C:\Program Files\LGHUB\logi_analytics_client.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |16564|: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21061.10121.0_x64__8wekyb3d8bbwe\Video.UI.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |17412|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |20572|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |20916|: C:\Users\galit\Desktop\cmder\vendor\conemu-maximus5\ConEmu\ConEmuC64.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |21640|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |22068|: \Device\HarddiskVolume2\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
04:36:31.9531A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |22476|: C:\Users\galit\AppData\Local\Programs\Microsoft VS Code\Code.exe
04:45:38.921A44333ProcessInjector::DoElevetedInjectionFailed to inject process [7884 mt:19096 h:0xa22fc] 0x57
04:45:39.1361A44564ProcessInjector::InjectExplorerToProcessInjected to process 7884 [mt 14888] 0x722dc
04:46:06.671A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |14972|: \Device\HarddiskVolume2\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
04:46:28.661A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |16436|: C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.6282.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
04:49:21.691A44258ProcessInjector::HandlePendingProccesssprocess detection skipped |17812|: C:\Program Files\Git\usr\bin\tail.exe
05:01:52.876113076Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
05:01:53.25044B066ProcessesMonitor::Stopstopping PM...
05:01:53.25058C0126ProcessesMonitor::ProcessEnumerateThreadexit process listener
05:01:53.25144B0394ProcessInjector::Unhookunhook running process
05:01:59.25744B066ProcessesMonitor::Stopstopping PM...