Time | Thread | Line | Function | Message |
18:07:16.573 | 30D0 | 365 | ftw1 | Loading (pid: 21876) |
18:07:16.575 | 30D0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X660E0000>6|2|1247872178 |
18:07:16.575 | 30D0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X68860000>6|2|1247872242 |
18:07:16.696 | 30D0 | 173 | DXManager::Detect | Found in 0 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0X2A40|10816 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0X6AA70|436848 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0X21390|136080 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0X3C60|15456 |
18:07:16.698 | 30D0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0XFD9A8860|-40204192 |
18:07:16.698 | 30D0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0XFD9ADC30|-40182736 |
18:07:16.698 | 30D0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0XFD9AC5F0|-40188432 |
18:07:16.698 | 30D0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X660E0000 <> 0X68860000 |
18:07:16.698 | 30D0 | 209 | Initialize::GetLocation | @ 0XFD88A7F0|-41375760 |
18:07:16.715 | 30D0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X5C0A0000>6|2|1247871904 |
18:07:16.808 | 30D0 | 129 | DXManager::Detect | OK |
18:07:16.853 | 30D0 | 186 | DXManager::Detect | Done |
18:07:16.853 | 30D0 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X41090|266384 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X3CBC0|248768 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XB76A0|751264 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XB71F0|750064 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XB7290|750224 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X113920|1128736 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X1133E0|1127392 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X48030|294960 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XCE890|845968 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XCEF60|847712 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XCFA50|850512 |
18:07:16.854 | 30D0 | 209 | Initialize::GetLocation | @ 0XD00B0|852144 |
18:07:16.867 | 30D0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X41790000>6|2|1247870977 |
18:07:16.880 | 30D0 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
18:07:16.880 | 30D0 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
18:07:16.880 | 30D0 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
18:07:16.880 | 30D0 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
18:07:16.881 | 30D0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X3EF20000>6|2|1247870977 |
18:07:16.891 | 30D0 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
18:07:16.891 | 30D0 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
18:07:16.891 | 30D0 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
18:07:16.891 | 30D0 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
18:07:16.891 | 30D0 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
18:07:16.953 | 30D0 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_181_1_21876 opened succesfuly |
18:07:16.953 | 30D0 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
18:07:16.953 | 30D0 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_181_1_21876 close 2147483647 bytes |
18:07:16.953 | 30D0 | 301 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.181.0.11\OWExplorer.dll] |
18:07:16.955 | 30D0 | 389 | ftw1 | OWExplorer injected |
18:07:16.956 | 2AD8 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
18:07:17.153 | 495C | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
18:07:17.153 | 495C | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
18:07:17.153 | 495C | 56 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
18:07:17.153 | 495C | 53 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |108|: Registry |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2100|: \Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2384|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_44dc4eefedc0d082\Display.NvContainer\NVDisplay.Container.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2572|: MemCompression |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2824|: \Device\HarddiskVolume4\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_44dc4eefedc0d082\Display.NvContainer\NVDisplay.Container.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4348|: C:\Program Files\Riot Vanguard\vgtray.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4720|: \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome Remote Desktop\94.0.4606.27\remoting_host.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4748|: \Device\HarddiskVolume4\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |4912|: \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5004|: \Device\HarddiskVolume4\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |6876|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21092.145.0_x64__8wekyb3d8bbwe\YourPhone.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |7960|: C:\Program Files\Logitech Gaming Software\LCore.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |8020|: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |8176|: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2021.21090.10008.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |10624|: C:\Program Files\ESET\ESET Security\eguiProxy.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20436|: C:\Windows\HelpPane.exe |
18:08:17.515 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |20596|: \Device\HarddiskVolume4\Program Files\PCHealthCheck\PCHealthCheck.exe |
10:19:27.633 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |15200|: \Device\HarddiskVolume4\Program Files (x86)\Google\Update\GoogleUpdate.exe |
10:20:29.252 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |22552|: \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome Remote Desktop\96.0.4664.39\remoting_host.exe |
21:45:03.406 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |2328|: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21092.149.0_x64__8wekyb3d8bbwe\YourPhone.exe |
11:16:18.478 | 4B2C | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 15860 [mt 19824] 0x521a62 |
11:16:46.812 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |5600|: \Device\HarddiskVolume4\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe |
11:24:35.267 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |11136|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe |
11:24:35.267 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |16536|: C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe |
11:24:40.311 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |1740|: C:\Users\Eliran\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe |
11:31:58.235 | 4B2C | 333 | ProcessInjector::DoElevetedInjection | Failed to inject process [13632 mt:7480 h:0x5827ca] 0x57 |
11:31:59.253 | 4B2C | 546 | ProcessInjector::InjectExplorerToProcess | Inject to process 13632 error. can't find thread |
11:33:09.152 | 4B2C | 564 | ProcessInjector::InjectExplorerToProcess | Injected to process 14500 [mt 16488] 0x370e7e |
11:33:41.604 | 4B2C | 258 | ProcessInjector::HandlePendingProccesss | process detection skipped |13748|: \Device\HarddiskVolume4\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe |
11:33:47.644 | 2AD8 | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
11:33:49.512 | 30D0 | 66 | ProcessesMonitor::Stop | stopping PM... |
11:33:49.512 | 495C | 126 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
11:33:49.513 | 30D0 | 394 | ProcessInjector::Unhook | unhook running process |
11:33:55.520 | 30D0 | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |