Time | Thread | Line | Function | Message |
13:57:25.321 | 3098 | 365 | ftw1 | Loading (pid: 11404) |
13:57:25.325 | 3098 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X22C60000>6|2|1247872178 |
13:57:25.326 | 3098 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X289C0000>6|2|1247872242 |
13:57:25.576 | 3098 | 173 | DXManager::Detect | Found in 0 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0X2A40|10816 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0X6AA70|436848 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0X21390|136080 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0X3C60|15456 |
13:57:25.577 | 3098 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X22C60000 <> 0X289C0000 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0XFA3C8860|-96696224 |
13:57:25.577 | 3098 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X22C60000 <> 0X289C0000 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0XFA3CDC30|-96674768 |
13:57:25.577 | 3098 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X22C60000 <> 0X289C0000 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0XFA3CC5F0|-96680464 |
13:57:25.577 | 3098 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X22C60000 <> 0X289C0000 |
13:57:25.577 | 3098 | 209 | Initialize::GetLocation | @ 0XFA2AA7F0|-97867792 |
13:57:25.602 | 3098 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XDC370000>6|2|1247871904 |
13:57:25.719 | 3098 | 129 | DXManager::Detect | OK |
13:57:25.742 | 3098 | 186 | DXManager::Detect | Done |
13:57:25.742 | 3098 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
13:57:25.743 | 3098 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
13:57:25.791 | 3098 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0XE9C80000>6|2|1247870977 |
13:57:29.2 | 3098 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
13:57:29.2 | 3098 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
13:57:29.2 | 3098 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
13:57:29.2 | 3098 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
13:57:29.13 | 3098 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XC5470000>6|2|1247870977 |
13:57:29.794 | 3098 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
13:57:29.794 | 3098 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
13:57:29.795 | 3098 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
13:57:29.795 | 3098 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
13:57:29.795 | 3098 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
13:57:29.861 | 3098 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_181_1_11404 opened succesfuly |
13:57:29.862 | 3098 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
13:57:29.862 | 3098 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_181_1_11404 close 2147483647 bytes |
13:57:29.862 | 3098 | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.181.0.11\OWExplorer.dll] |
13:57:30.198 | 3098 | 389 | ftw1 | OWExplorer injected |
13:57:30.199 | 3734 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
13:57:30.784 | 3730 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
13:57:30.784 | 3730 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
13:57:30.784 | 3730 | 56 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
13:57:30.784 | 3730 | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |72|: |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |132|: Registry |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3676|: C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3370.0_x64__8j3eq9eme6ctt\IGCC.exe |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |3940|: MemCompression |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |9272|: C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3370.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10408|: \Device\HarddiskVolume3\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10428|: \Device\HarddiskVolume3\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe |
13:58:31.657 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11900|: C:\Program Files\Riot Vanguard\vgtray.exe |
13:59:59.406 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13548|: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe |
13:59:59.406 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13768|: \Device\HarddiskVolume3\Program Files\HPCommRecovery\HPCommRecovery.exe |
13:59:59.406 | 3738 | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |15012|: \Device\HarddiskVolume3\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe |
14:09:35.743 | 3738 | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 10904 [mt 10132] 0x1051c |
14:10:11.278 | 3734 | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
14:10:14.49 | 3098 | 66 | ProcessesMonitor::Stop | stopping PM... |
14:10:14.49 | 3730 | 126 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
14:10:14.50 | 3098 | 394 | ProcessInjector::Unhook | unhook running process |
14:10:20.85 | 3098 | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |