Time | Thread | Line | Function | Message |
07:49:11.570 | 238C | 361 | ftw1 | Loading (pid: 15284) |
07:49:11.570 | 3530 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
07:49:11.571 | 238C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X64CE0000>6|2|1203373203 |
07:49:11.571 | 238C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X66790000>6|2|1203373081 |
07:49:11.636 | 238C | 172 | DXManager::Detect | Found in 0 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0X4660|18016 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0X661F0|418288 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0X1350|4944 |
07:49:11.637 | 238C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X64CE0000 <> 0X66790000 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0XFE673020|-26791904 |
07:49:11.637 | 238C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X64CE0000 <> 0X66790000 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0XFE678060|-26771360 |
07:49:11.637 | 238C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X64CE0000 <> 0X66790000 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0XFE66E620|-26810848 |
07:49:11.637 | 238C | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X64CE0000 <> 0X66790000 |
07:49:11.637 | 238C | 209 | Initialize::GetLocation | @ 0XFE55AA80|-27940224 |
07:49:11.646 | 238C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X5B900000>6|2|1203373142 |
07:49:11.721 | 238C | 129 | DXManager::Detect | OK |
07:49:11.751 | 238C | 186 | DXManager::Detect | Done |
07:49:11.751 | 238C | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X5880|22656 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XF280|62080 |
07:49:11.752 | 238C | 209 | Initialize::GetLocation | @ 0XF430|62512 |
07:49:11.765 | 238C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X30010000>6|2|1203372033 |
07:49:11.780 | 238C | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
07:49:11.781 | 238C | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
07:49:11.781 | 238C | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
07:49:11.781 | 238C | 209 | Initialize::GetLocation | @ 0X6180|24960 |
07:49:11.781 | 238C | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X4CE60000>6|2|1203372033 |
07:49:11.788 | 238C | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
07:49:11.788 | 238C | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
07:49:11.788 | 238C | 209 | Initialize::GetLocation | @ 0X10000|65536 |
07:49:11.788 | 238C | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
07:49:11.788 | 238C | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
07:49:11.843 | 238C | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_82_5_15284 opened succesfuly |
07:49:11.843 | 238C | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
07:49:11.843 | 238C | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_82_5_15284 close 2147483647 bytes |
07:49:11.843 | 238C | 297 | InjectOWExplorer | Explorer file name [G:\Facecheck\Overwolf\0.159.0.31\OWExplorer.dll] |
07:49:11.847 | 238C | 385 | ftw1 | OWExplorer injected |
07:49:11.949 | 4480 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
07:49:11.949 | 4480 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
07:49:11.949 | 4480 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
07:49:11.949 | 4480 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |mDNSResponder.exe| missing h |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |nsWscSvc.exe| missing h |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |NortonSecurity.exe| missing h |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |lghub_updater.exe| missing h |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |WPSHWPBC.exe| missing h |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |WPSService20.exe| missing h |
07:49:12.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |RzSDKServer.exe| missing h |
07:49:12.44 | 4484 | 629 | ProcessInjector::InjectProcess | process |swrm.exe| missing h |
07:49:12.132 | 4484 | 629 | ProcessInjector::InjectProcess | process |VideoCardMonitorII.exe| missing h |
07:49:12.176 | 4484 | 629 | ProcessInjector::InjectProcess | process |EyeRest.exe| missing h |
07:49:12.220 | 4484 | 629 | ProcessInjector::InjectProcess | process |TriggerModeMonitor.exe| missing h |
07:49:12.262 | 4484 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
07:49:12.350 | 4484 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
07:49:12.480 | 4484 | 629 | ProcessInjector::InjectProcess | process |logi_crashpad_handler.exe| missing h |
07:50:50.894 | 4484 | 629 | ProcessInjector::InjectProcess | process |vrol.exe| missing h |
07:50:54.895 | 4484 | 629 | ProcessInjector::InjectProcess | process |WSCStub.exe| missing h |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1404] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1404|: GoogleCrashHandler.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1872] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1872|: NVDisplay.Container.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4232] [t: 0 w_t_id: 0]- mDNSResponder.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4232|: mDNSResponder.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4460] [t: 0 w_t_id: 0]- nsWscSvc.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4460|: nsWscSvc.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4472] [t: 0 w_t_id: 0]- NortonSecurity.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4472|: NortonSecurity.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4556] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4556|: nvcontainer.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4572] [t: 0 w_t_id: 0]- lghub_updater.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4572|: lghub_updater.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4612] [t: 0 w_t_id: 0]- WPSHWPBC.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4612|: WPSHWPBC.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4620] [t: 0 w_t_id: 0]- WPSService20.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4620|: WPSService20.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4672] [t: 0 w_t_id: 0]- RzSDKServer.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4672|: RzSDKServer.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7748] [t: 0 w_t_id: 0]- swrm.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7748|: swrm.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9708] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9708|: NVIDIA Share.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12252] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12252|: GoogleCrashHandler64.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12936] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12936|: NVIDIA Share.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14704] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14704|: lghub.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15764] [t: 0 w_t_id: 0]- logi_crashpad_handler.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15764|: logi_crashpad_handler.exe |
07:51:42.917 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15772] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0 |
07:51:42.917 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15772|: lghub.exe |
07:52:07.29 | 4484 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
07:52:37.950 | 4484 | 629 | ProcessInjector::InjectProcess | process |EasyAntiCheat.exe| missing h |
07:53:20.960 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15168] [t: 0 w_t_id: 0]- vrol.exe (elevated True) 0x0 |
07:53:20.960 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15168|: vrol.exe |
07:54:08.0 | 4484 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
07:55:07.985 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5980] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0 |
07:55:07.985 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5980|: EasyAntiCheat.exe |
07:55:28.999 | 4484 | 629 | ProcessInjector::InjectProcess | process |cltLMH.exe| missing h |
08:05:02.94 | 4484 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
08:05:31.97 | 4484 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
08:13:10.203 | 4484 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
08:13:10.203 | 4484 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
08:15:40.246 | 4484 | 629 | ProcessInjector::InjectProcess | process |EasyAntiCheat.exe| missing h |
08:18:10.272 | 4484 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10608] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0 |
08:18:10.273 | 4484 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10608|: EasyAntiCheat.exe |
08:25:39.385 | 4484 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
08:25:42.386 | 4484 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |