Time | Thread | Line | Function | Message |
18:30:50.562 | 5B10 | 365 | ftw1 | Loading (pid: 16464) |
18:30:50.562 | 240 | 147 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
18:30:50.563 | 5B10 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X9D340000>6|2|1247871722 |
18:30:50.564 | 5B10 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X9F9B0000>6|2|1247871904 |
18:30:50.657 | 5B10 | 172 | DXManager::Detect | Found in 0 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0X69700|431872 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
18:30:50.657 | 5B10 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0XFDAB8860|-39090080 |
18:30:50.657 | 5B10 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0XFDABDC30|-39068624 |
18:30:50.657 | 5B10 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0XFDABC5F0|-39074320 |
18:30:50.657 | 5B10 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000 |
18:30:50.657 | 5B10 | 209 | Initialize::GetLocation | @ 0XFD99A7F0|-40261648 |
18:30:50.668 | 5B10 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X73FB0000>6|2|1247871904 |
18:30:50.749 | 5B10 | 129 | DXManager::Detect | OK |
18:30:50.793 | 5B10 | 186 | DXManager::Detect | Done |
18:30:50.793 | 5B10 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
18:30:50.793 | 5B10 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
18:30:50.804 | 5B10 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X6BDA0000>6|2|1247870977 |
18:30:50.913 | 5B10 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
18:30:50.914 | 5B10 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
18:30:50.914 | 5B10 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
18:30:50.914 | 5B10 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
18:30:50.915 | 5B10 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X6BC00000>6|2|1247870977 |
18:30:50.965 | 5B10 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
18:30:50.965 | 5B10 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
18:30:50.965 | 5B10 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
18:30:50.965 | 5B10 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
18:30:50.965 | 5B10 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
18:30:51.23 | 5B10 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_84_14_16464 opened succesfuly |
18:30:51.23 | 5B10 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
18:30:51.23 | 5B10 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_84_14_16464 close 2147483647 bytes |
18:30:51.23 | 5B10 | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.168.0.12\OWExplorer.dll] |
18:30:51.24 | 5B10 | 389 | ftw1 | OWExplorer injected |
18:30:51.24 | 29CC | 70 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
18:30:51.223 | 5500 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
18:30:51.223 | 5500 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
18:30:51.223 | 5500 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
18:30:51.223 | 5500 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
18:30:51.236 | 3AFC | 646 | ProcessInjector::InjectProcess | process |vmware-authd.exe| missing h |
18:30:51.236 | 3AFC | 646 | ProcessInjector::InjectProcess | process |vmware-hostd.exe| missing h |
18:30:51.236 | 3AFC | 646 | ProcessInjector::InjectProcess | process |sqlservr.exe| missing h |
18:30:51.236 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
18:30:51.509 | 3AFC | 646 | ProcessInjector::InjectProcess | process |parsecd.exe| missing h |
18:30:51.720 | 3AFC | 646 | ProcessInjector::InjectProcess | process |com.docker.service| missing h |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2356] [t: 0 w_t_id: 0]- docker.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2356|: docker.exe |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3968] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3968|: com.docker.backend.exe |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4500] [t: 0 w_t_id: 0]- vmware-authd.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4500|: vmware-authd.exe |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4532] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4532|: nvcontainer.exe |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6460] [t: 0 w_t_id: 0]- vmware-hostd.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6460|: vmware-hostd.exe |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7284] [t: 0 w_t_id: 0]- sqlservr.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7284|: sqlservr.exe |
18:33:22.185 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11228] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
18:33:22.185 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11228|: DropboxUpdate.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11496] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11496|: com.docker.service |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12532] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12532|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13360] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13360|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13920] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13920|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14156] [t: 0 w_t_id: 0]- SnagPriv.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14156|: SnagPriv.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16108] [t: 0 w_t_id: 0]- com.docker.wsl-distro-proxy.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16108|: com.docker.wsl-distro-proxy.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17552] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17552|: vpnkit.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17868] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17868|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18832] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18832|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19744] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19744|: vpnkit-bridge.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20076] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20076|: CCXProcess.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20092] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20092|: node.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21284] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21284|: com.docker.proxy.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22132] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22132|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22764] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22764|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23692] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23692|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [23704] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |23704|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24064] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24064|: Code.exe |
18:33:22.186 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24484] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
18:33:22.186 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24484|: Code.exe |
18:35:47.202 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
18:55:01.702 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
19:55:01.729 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
20:55:01.897 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
21:55:02.546 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
22:14:03.286 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
22:35:46.934 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
22:35:47.933 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
22:36:57.687 | 3AFC | 646 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
22:37:06.794 | 3AFC | 646 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
22:47:16.951 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
22:47:16.951 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
22:55:01.747 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
07:31:33.212 | 3AFC | 646 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
07:31:33.484 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
07:31:33.484 | 3AFC | 646 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
07:32:12.488 | 3AFC | 646 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
07:32:17.516 | 3AFC | 646 | ProcessInjector::InjectProcess | process |MicrosoftEdge_X64_90.0.818.46_90.0.818.42.exe| missing h |
07:32:30.640 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
07:36:57.292 | 3AFC | 646 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
07:55:01.999 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
08:55:01.896 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
09:55:02.451 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
09:56:27.53 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
10:14:02.859 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
10:55:01.904 | 3AFC | 646 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
10:58:29.282 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
10:58:30.292 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
11:29:27.739 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5232] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:29:27.739 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5232|: Code.exe |
11:29:28.740 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [21028] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:29:28.740 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |21028|: Code.exe |
11:29:28.740 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22552] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:29:28.740 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22552|: Code.exe |
11:29:29.756 | 3AFC | 385 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19724] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0 |
11:29:29.756 | 3AFC | 317 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19724|: Code.exe |
11:40:58.695 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
11:41:03.741 | 3AFC | 646 | ProcessInjector::InjectProcess | process |owver64.exe| missing h |
11:41:10.802 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfSetup.exe| missing h |
11:41:10.802 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfSetup.exe| missing h |
11:41:12.812 | 3AFC | 646 | ProcessInjector::InjectProcess | process |00020000000E6AF873CF50BC| missing h |
11:41:12.812 | 3AFC | 646 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
11:41:18.970 | 29CC | 75 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
11:41:19.360 | 5B10 | 66 | ProcessesMonitor::Stop | stopping PM... |
11:41:19.360 | 5500 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
11:41:19.362 | 5B10 | 529 | ProcessInjector::Unhook | unhook running process |
11:41:25.376 | 5B10 | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |