Time | Thread | Line | Function | Message |
14:15:14.304 | 4158 | 365 | ftw1 | Loading (pid: 12472) |
14:15:14.304 | A6C | 147 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
14:15:14.306 | 4158 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X87570000>6|2|1247871722 |
14:15:14.306 | 4158 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0X89F70000>6|2|1247871940 |
14:15:14.362 | 4158 | 173 | DXManager::Detect | Found in 0 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0X59E0|23008 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0X6AE20|437792 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0X211E0|135648 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0X2840|10304 |
14:15:14.363 | 4158 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0XFD728860|-42825632 |
14:15:14.363 | 4158 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0XFD72DC30|-42804176 |
14:15:14.363 | 4158 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0XFD72C5F0|-42809872 |
14:15:14.363 | 4158 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000 |
14:15:14.363 | 4158 | 209 | Initialize::GetLocation | @ 0XFD60A7F0|-43997200 |
14:15:14.374 | 4158 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X4A340000>6|2|1247871904 |
14:15:14.435 | 4158 | 129 | DXManager::Detect | OK |
14:15:14.472 | 4158 | 186 | DXManager::Detect | Done |
14:15:14.472 | 4158 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
14:15:14.472 | 4158 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
14:15:14.486 | 4158 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X2AD10000>6|2|1247870977 |
14:15:14.496 | 4158 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
14:15:14.496 | 4158 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
14:15:14.496 | 4158 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
14:15:14.496 | 4158 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
14:15:14.497 | 4158 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0X2ACC0000>6|2|1247870977 |
14:15:14.504 | 4158 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
14:15:14.504 | 4158 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
14:15:14.505 | 4158 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
14:15:14.505 | 4158 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
14:15:14.505 | 4158 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
14:15:14.558 | 4158 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_173_4_12472 opened succesfuly |
14:15:14.558 | 4158 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
14:15:14.558 | 4158 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_173_4_12472 close 2147483647 bytes |
14:15:14.558 | 4158 | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.173.0.16\OWExplorer.dll] |
14:15:14.619 | 4158 | 389 | ftw1 | OWExplorer injected |
14:15:14.619 | 654 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
14:15:15.6 | 6C8 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
14:15:15.6 | 6C8 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
14:15:15.6 | 6C8 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
14:15:15.6 | 6C8 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
14:15:15.79 | 968 | 669 | ProcessInjector::InjectProcess | process |atkexComSvc.exe| missing h |
14:15:15.79 | 968 | 669 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
14:15:15.79 | 968 | 669 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
14:15:15.79 | 968 | 669 | ProcessInjector::InjectProcess | process |RtWLan.exe| missing h |
14:15:15.203 | 968 | 669 | ProcessInjector::InjectProcess | process |Aac3572MbHal_x86.exe| missing h |
14:17:45.744 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4188] [t: 0 w_t_id: 0]- atkexComSvc.exe (elevated True) 0x0 |
14:17:45.744 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4188|: atkexComSvc.exe |
14:17:45.744 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4992] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
14:17:45.744 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4992|: GoogleCrashHandler.exe |
14:17:45.744 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5016] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
14:17:45.744 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5016|: GoogleCrashHandler64.exe |
14:17:45.744 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9660] [t: 0 w_t_id: 0]- Aac3572MbHal_x86.exe (elevated True) 0x0 |
14:17:45.744 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9660|: Aac3572MbHal_x86.exe |
14:19:42.671 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17388] [t: 0 w_t_id: 0]- curseforge.exe (elevated True) 0x0 |
14:19:42.671 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17388|: curseforge.exe |
14:20:09.929 | 968 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
14:20:41.197 | 968 | 669 | ProcessInjector::InjectProcess | process |AsusUpdate.exe| missing h |
14:20:41.197 | 968 | 669 | ProcessInjector::InjectProcess | process |AsusUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |AsusUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |AsusUpdate.exe| missing h |
14:20:43.214 | 968 | 669 | ProcessInjector::InjectProcess | process |Get-AppxVersion.exe| missing h |
14:20:52.263 | 968 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
14:20:55.278 | 968 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdge_X64_91.0.864.64_91.0.864.59.exe| missing h |
14:21:05.322 | 968 | 669 | ProcessInjector::InjectProcess | process |setup.exe| missing h |
14:21:05.322 | 968 | 669 | ProcessInjector::InjectProcess | process |setup.exe| missing h |
14:21:06.327 | 968 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdge_X64_91.0.864.64_91.0.864.59.exe| missing h |
14:21:07.333 | 968 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
14:21:41.587 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9752] [t: 0 w_t_id: 0]- Bitwarden.exe (elevated True) 0x578 |
14:21:41.587 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9752|: Bitwarden.exe |
14:21:41.587 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17488] [t: 0 w_t_id: 0]- Bitwarden.exe (elevated True) 0x578 |
14:21:41.587 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17488|: Bitwarden.exe |
14:23:13.330 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10044] [t: 0 w_t_id: 0]- AsusUpdate.exe (elevated True) 0x578 |
14:23:13.330 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10044|: AsusUpdate.exe |
14:23:13.330 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10860] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x578 |
14:23:13.330 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10860|: GoogleUpdate.exe |
14:23:13.330 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14508] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x578 |
14:23:13.330 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14508|: MicrosoftEdgeUpdate.exe |
15:46:14.814 | 968 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:50:21.16 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12236] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x578 |
15:50:21.16 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12236|: GameBarFTServer.exe |
16:07:14.1 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14276] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x578 |
16:07:14.1 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14276|: GameBarFTServer.exe |
16:20:08.594 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20344] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x0 |
16:20:08.594 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20344|: GameBarFTServer.exe |
17:10:49.782 | 968 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16512] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x0 |
17:10:49.783 | 968 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16512|: GameBarFTServer.exe |
18:20:10.750 | 968 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
18:20:11.750 | 968 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
19:18:37.121 | 654 | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
19:18:37.181 | 4158 | 66 | ProcessesMonitor::Stop | stopping PM... |
19:18:37.181 | 6C8 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
19:18:37.199 | 4158 | 527 | ProcessInjector::Unhook | unhook running process |