Time | Thread | Line | Function | Message |
11:41:28.83 | 5BA0 | 365 | ftw1 | Loading (pid: 22800) |
11:41:28.83 | 2E3C | 147 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
11:41:28.85 | 5BA0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X9D340000>6|2|1247871722 |
11:41:28.85 | 5BA0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X9F9B0000>6|2|1247871904 |
11:41:28.171 | 5BA0 | 172 | DXManager::Detect | Found in 0 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0X69700|431872 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
11:41:28.172 | 5BA0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0XFDAB8860|-39090080 |
11:41:28.172 | 5BA0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0XFDABDC30|-39068624 |
11:41:28.172 | 5BA0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0XFDABC5F0|-39074320 |
11:41:28.172 | 5BA0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
11:41:28.172 | 5BA0 | 209 | Initialize::GetLocation | @ 0XFD99A7F0|-40261648 |
11:41:28.191 | 5BA0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X73FB0000>6|2|1247871904 |
11:41:28.281 | 5BA0 | 129 | DXManager::Detect | OK |
11:41:28.319 | 5BA0 | 186 | DXManager::Detect | Done |
11:41:28.319 | 5BA0 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
11:41:28.319 | 5BA0 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
11:41:28.338 | 5BA0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X6C2F0000>6|2|1247870977 |
11:41:28.475 | 5BA0 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
11:41:28.475 | 5BA0 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
11:41:28.475 | 5BA0 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
11:41:28.475 | 5BA0 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
11:41:28.477 | 5BA0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X6A810000>6|2|1247870977 |
11:41:28.525 | 5BA0 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
11:41:28.527 | 5BA0 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
11:41:28.527 | 5BA0 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
11:41:28.527 | 5BA0 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
11:41:28.527 | 5BA0 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
11:41:28.591 | 5BA0 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_85_4_22800 opened succesfuly |
11:41:28.591 | 5BA0 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
11:41:28.591 | 5BA0 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_85_4_22800 close 2147483647 bytes |
11:41:28.591 | 5BA0 | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.169.0.21\OWExplorer.dll] |
11:41:28.635 | 5BA0 | 389 | ftw1 | OWExplorer injected |
11:41:28.635 | 4A34 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
11:41:28.886 | 308C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
11:41:28.886 | 308C | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
11:41:28.886 | 308C | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
11:41:28.886 | 308C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
11:41:28.903 | 2F58 | 670 | ProcessInjector::InjectProcess | process |vmware-authd.exe| missing h |
11:41:28.903 | 2F58 | 670 | ProcessInjector::InjectProcess | process |vmware-hostd.exe| missing h |
11:41:28.903 | 2F58 | 670 | ProcessInjector::InjectProcess | process |sqlservr.exe| missing h |
11:41:28.969 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
11:41:29.254 | 2F58 | 670 | ProcessInjector::InjectProcess | process |parsecd.exe| missing h |
11:41:29.466 | 2F58 | 670 | ProcessInjector::InjectProcess | process |com.docker.service| missing h |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2356] [t: 0 w_t_id: 0]- docker.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2356|: docker.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2512] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2512|: NVDisplay.Container.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3968] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3968|: com.docker.backend.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4500] [t: 0 w_t_id: 0]- vmware-authd.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4500|: vmware-authd.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4532] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4532|: nvcontainer.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5232] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5232|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6460] [t: 0 w_t_id: 0]- vmware-hostd.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6460|: vmware-hostd.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7284] [t: 0 w_t_id: 0]- sqlservr.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7284|: sqlservr.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11228] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11228|: DropboxUpdate.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11496] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11496|: com.docker.service |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12532] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12532|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13360] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13360|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13920] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13920|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14156] [t: 0 w_t_id: 0]- SnagPriv.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14156|: SnagPriv.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16108] [t: 0 w_t_id: 0]- com.docker.wsl-distro-proxy.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16108|: com.docker.wsl-distro-proxy.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17552] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17552|: vpnkit.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17868] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17868|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18832] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18832|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19724] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19724|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19744] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19744|: vpnkit-bridge.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20076] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20076|: CCXProcess.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20092] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20092|: node.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21028] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21028|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21284] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21284|: com.docker.proxy.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22132] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22132|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22552] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22552|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22764] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22764|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23692] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23692|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23704] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23704|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24064] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24064|: Code.exe |
11:43:59.889 | 2F58 | 387 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24484] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:43:59.889 | 2F58 | 319 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24484|: Code.exe |
11:46:23.993 | 2F58 | 670 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
11:46:24.998 | 2F58 | 670 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
11:55:02.4 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
12:26:16.660 | 2F58 | 670 | ProcessInjector::InjectProcess | process |Veeam.EndPoint.Manager.exe| missing h |
12:36:58.514 | 2F58 | 670 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
12:55:02.306 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
13:55:02.320 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
14:14:02.645 | 2F58 | 670 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
14:55:02.400 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
15:46:24.696 | 2F58 | 670 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:55:02.266 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:55:01.779 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
17:34:42.679 | 2F58 | 670 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
17:35:02.824 | 2F58 | 670 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
17:55:01.424 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
17:55:01.424 | 2F58 | 670 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
18:14:02.886 | 2F58 | 670 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
18:36:57.942 | 2F58 | 670 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
18:37:40.277 | 2F58 | 670 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |