TimeThreadLineFunctionMessage
18:07:16.57330D0365ftw1Loading (pid: 21876)
18:07:16.57530D048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X660E0000>6|2|1247872178
18:07:16.57530D048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X68860000>6|2|1247872242
18:07:16.69630D0173DXManager::DetectFound in 0
18:07:16.69830D0209Initialize::GetLocation@ 0X2A40|10816
18:07:16.69830D0209Initialize::GetLocation@ 0X6AA70|436848
18:07:16.69830D0209Initialize::GetLocation@ 0X21390|136080
18:07:16.69830D0209Initialize::GetLocation@ 0X3C60|15456
18:07:16.69830D0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000
18:07:16.69830D0209Initialize::GetLocation@ 0XFD9A8860|-40204192
18:07:16.69830D0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000
18:07:16.69830D0209Initialize::GetLocation@ 0XFD9ADC30|-40182736
18:07:16.69830D0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000
18:07:16.69830D0209Initialize::GetLocation@ 0XFD9AC5F0|-40188432
18:07:16.69830D0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000
18:07:16.69830D0209Initialize::GetLocation@ 0XFD88A7F0|-41375760
18:07:16.71530D048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X5C0A0000>6|2|1247871904
18:07:16.80830D0129DXManager::DetectOK
18:07:16.85330D0186DXManager::DetectDone
18:07:16.85330D0215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
18:07:16.85430D0209Initialize::GetLocation@ 0X41090|266384
18:07:16.85430D0209Initialize::GetLocation@ 0X33320|209696
18:07:16.85430D0209Initialize::GetLocation@ 0X3CBC0|248768
18:07:16.85430D0209Initialize::GetLocation@ 0XB76A0|751264
18:07:16.85430D0209Initialize::GetLocation@ 0XB71F0|750064
18:07:16.85430D0209Initialize::GetLocation@ 0XA1F0|41456
18:07:16.85430D0209Initialize::GetLocation@ 0XB7290|750224
18:07:16.85430D0209Initialize::GetLocation@ 0X1ABB0|109488
18:07:16.85430D0209Initialize::GetLocation@ 0X1D600|120320
18:07:16.85430D0209Initialize::GetLocation@ 0X25C30|154672
18:07:16.85430D0209Initialize::GetLocation@ 0X113920|1128736
18:07:16.85430D0209Initialize::GetLocation@ 0X1133E0|1127392
18:07:16.85430D0209Initialize::GetLocation@ 0X1AAA0|109216
18:07:16.85430D0209Initialize::GetLocation@ 0X1A9B0|108976
18:07:16.85430D0209Initialize::GetLocation@ 0XCB80|52096
18:07:16.85430D0209Initialize::GetLocation@ 0X48030|294960
18:07:16.85430D0209Initialize::GetLocation@ 0X9D60|40288
18:07:16.85430D0209Initialize::GetLocation@ 0XCE890|845968
18:07:16.85430D0209Initialize::GetLocation@ 0XCEF60|847712
18:07:16.85430D0209Initialize::GetLocation@ 0X9D60|40288
18:07:16.85430D0209Initialize::GetLocation@ 0XCFA50|850512
18:07:16.85430D0209Initialize::GetLocation@ 0XD00B0|852144
18:07:16.86730D048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X41790000>6|2|1247870977
18:07:16.88030D083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
18:07:16.88030D0209Initialize::GetLocation@ 0X4040|16448
18:07:16.88030D0209Initialize::GetLocation@ 0X6410|25616
18:07:16.88030D0209Initialize::GetLocation@ 0X65C0|26048
18:07:16.88130D048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X3EF20000>6|2|1247870977
18:07:16.89130D093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
18:07:16.89130D0110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
18:07:16.89130D0209Initialize::GetLocation@ 0XA5D0|42448
18:07:16.89130D0209Initialize::GetLocation@ 0XD4D0|54480
18:07:16.89130D0209Initialize::GetLocation@ 0XD290|53904
18:07:16.95330D0225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_181_1_21876 opened succesfuly
18:07:16.95330D072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
18:07:16.95330D0255InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_181_1_21876 close 2147483647 bytes
18:07:16.95330D0301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.181.0.11\OWExplorer.dll]
18:07:16.95530D0389ftw1OWExplorer injected
18:07:16.9562AD871Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
18:07:17.153495C53`anonymous-namespace'::CreateProviderInitialize provider: NET
18:07:17.153495C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
18:07:17.153495C56`anonymous-namespace'::CreateProviderFail to initlized provider: NET
18:07:17.153495C53`anonymous-namespace'::CreateProviderInitialize provider: GPU
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |108|: Registry
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |2100|: \Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |2384|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_44dc4eefedc0d082\Display.NvContainer\NVDisplay.Container.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |2572|: MemCompression
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |2824|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_44dc4eefedc0d082\Display.NvContainer\NVDisplay.Container.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |4348|: C:\Program Files\Riot Vanguard\vgtray.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |4720|: \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome Remote Desktop\94.0.4606.27\remoting_host.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |4748|: \Device\HarddiskVolume4\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |4912|: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |5004|: \Device\HarddiskVolume4\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |6876|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21092.145.0_x64__8wekyb3d8bbwe\YourPhone.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |7960|: C:\Program Files\Logitech Gaming Software\LCore.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |8020|: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |8176|: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21090.10008.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |10624|: C:\Program Files\ESET\ESET Security\eguiProxy.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |20436|: C:\Windows\HelpPane.exe
18:08:17.5154B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |20596|: \Device\HarddiskVolume4\Program Files\PCHealthCheck\PCHealthCheck.exe
10:19:27.6334B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |15200|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:20:29.2524B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |22552|: \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome Remote Desktop\96.0.4664.39\remoting_host.exe
21:45:03.4064B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |2328|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21092.149.0_x64__8wekyb3d8bbwe\YourPhone.exe
11:16:18.4784B2C564ProcessInjector::InjectExplorerToProcessInjected to process 15860 [mt 19824] 0x521a62
11:16:46.8124B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |5600|: \Device\HarddiskVolume4\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
11:24:35.2674B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |11136|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe
11:24:35.2674B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |16536|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe
11:24:40.3114B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |1740|: C:\Users\Eliran\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
11:31:58.2354B2C333ProcessInjector::DoElevetedInjectionFailed to inject process [13632 mt:7480 h:0x5827ca] 0x57
11:31:59.2534B2C546ProcessInjector::InjectExplorerToProcessInject to process 13632 error. can't find thread
11:33:09.1524B2C564ProcessInjector::InjectExplorerToProcessInjected to process 14500 [mt 16488] 0x370e7e
11:33:41.6044B2C258ProcessInjector::HandlePendingProccesssprocess detection skipped |13748|: \Device\HarddiskVolume4\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
11:33:47.6442AD876Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
11:33:49.51230D066ProcessesMonitor::Stopstopping PM...
11:33:49.512495C126ProcessesMonitor::ProcessEnumerateThreadexit process listener
11:33:49.51330D0394ProcessInjector::Unhookunhook running process
11:33:55.52030D066ProcessesMonitor::Stopstopping PM...