Time | Thread | Line | Function | Message |
16:12:16.133 | 135C | 361 | ftw1 | Loading (pid: 6748) |
16:12:16.158 | 2094 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
16:12:16.159 | 135C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X8F4C0000>6|2|1203373203 |
16:12:16.161 | 135C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X90BF0000>6|2|1203373081 |
16:12:16.231 | 135C | 172 | DXManager::Detect | Found in 0 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0X4660|18016 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0X661F0|418288 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0X19DB0|105904 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0X1350|4944 |
16:12:16.233 | 135C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X8F4C0000 <> 0X90BF0000 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0XFE9F3020|-23121888 |
16:12:16.233 | 135C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X8F4C0000 <> 0X90BF0000 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0XFE9F8060|-23101344 |
16:12:16.233 | 135C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X8F4C0000 <> 0X90BF0000 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0XFE9EE620|-23140832 |
16:12:16.233 | 135C | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X8F4C0000 <> 0X90BF0000 |
16:12:16.233 | 135C | 209 | Initialize::GetLocation | @ 0XFE8DAA80|-24270208 |
16:12:16.260 | 135C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X57400000>6|2|1203373142 |
16:12:16.357 | 135C | 129 | DXManager::Detect | OK |
16:12:16.479 | 135C | 186 | DXManager::Detect | Done |
16:12:16.479 | 135C | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XAE210|713232 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XADD60|712032 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X5880|22656 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XADE00|712192 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X1086D0|1083088 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X108180|1081728 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0X3F3F0|259056 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XF280|62080 |
16:12:16.480 | 135C | 209 | Initialize::GetLocation | @ 0XF430|62512 |
16:12:16.880 | 135C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X6F7A0000>6|2|1203372033 |
16:12:17.20 | 135C | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
16:12:17.20 | 135C | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
16:12:17.20 | 135C | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
16:12:17.20 | 135C | 209 | Initialize::GetLocation | @ 0X6180|24960 |
16:12:17.24 | 135C | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X65EB0000>6|2|1203372033 |
16:12:17.97 | 135C | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
16:12:17.98 | 135C | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
16:12:17.100 | 135C | 209 | Initialize::GetLocation | @ 0X10000|65536 |
16:12:17.100 | 135C | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
16:12:17.100 | 135C | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
16:12:17.158 | 135C | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_6748 opened succesfuly |
16:12:17.158 | 135C | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
16:12:17.158 | 135C | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_6748 close 2147483647 bytes |
16:12:17.158 | 135C | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.162.0.13\OWExplorer.dll] |
16:12:17.193 | 135C | 385 | ftw1 | OWExplorer injected |
16:12:21.123 | 3698 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
16:12:21.123 | 3698 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
16:12:21.123 | 3698 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
16:12:21.123 | 3698 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
16:12:21.172 | 28A0 | 629 | ProcessInjector::InjectProcess | process |wsc_proxy.exe| missing h |
16:12:21.172 | 28A0 | 629 | ProcessInjector::InjectProcess | process |RtkAudioService64.exe| missing h |
16:12:21.173 | 28A0 | 629 | ProcessInjector::InjectProcess | process |RAVBg64.exe| missing h |
16:12:21.216 | 28A0 | 629 | ProcessInjector::InjectProcess | process |RAVBg64.exe| missing h |
16:12:21.260 | 28A0 | 629 | ProcessInjector::InjectProcess | process |AVGSvc.exe| missing h |
16:12:21.260 | 28A0 | 629 | ProcessInjector::InjectProcess | process |avgToolsSvc.exe| missing h |
16:12:21.260 | 28A0 | 629 | ProcessInjector::InjectProcess | process |TuneupSvc.exe| missing h |
16:12:21.349 | 28A0 | 629 | ProcessInjector::InjectProcess | process |aswEngSrv.exe| missing h |
16:12:21.349 | 28A0 | 629 | ProcessInjector::InjectProcess | process |aswidsagent.exe| missing h |
16:12:21.393 | 28A0 | 629 | ProcessInjector::InjectProcess | process |DDVRulesProcessor.exe| missing h |
16:12:21.482 | 28A0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:12:21.570 | 28A0 | 629 | ProcessInjector::InjectProcess | process |LMS.exe| missing h |
16:12:21.570 | 28A0 | 629 | ProcessInjector::InjectProcess | process |RichVideo.exe| missing h |
16:12:21.570 | 28A0 | 629 | ProcessInjector::InjectProcess | process |DDVDataCollector.exe| missing h |
16:12:21.570 | 28A0 | 629 | ProcessInjector::InjectProcess | process |DDVCollectorSvcApi.exe| missing h |
16:12:21.660 | 28A0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
16:14:52.106 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2144] [t: 0 w_t_id: 0]- DDVDataCollector.exe (elevated True) 0x0 |
16:14:52.106 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2144|: DDVDataCollector.exe |
16:14:52.106 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2148] [t: 0 w_t_id: 0]- TuneupSvc.exe (elevated True) 0x0 |
16:14:52.106 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2148|: TuneupSvc.exe |
16:14:52.106 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2248] [t: 0 w_t_id: 0]- wsc_proxy.exe (elevated True) 0x0 |
16:14:52.106 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2248|: wsc_proxy.exe |
16:14:52.106 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3052] [t: 0 w_t_id: 0]- TuneupUI.exe (elevated True) 0x0 |
16:14:52.106 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3052|: TuneupUI.exe |
16:14:52.106 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3348] [t: 0 w_t_id: 0]- RtkAudioService64.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3348|: RtkAudioService64.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3920] [t: 0 w_t_id: 0]- AVGSvc.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3920|: AVGSvc.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4216] [t: 0 w_t_id: 0]- avgToolsSvc.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4216|: avgToolsSvc.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7988] [t: 0 w_t_id: 0]- aswEngSrv.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7988|: aswEngSrv.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8512] [t: 0 w_t_id: 0]- DDVRulesProcessor.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8512|: DDVRulesProcessor.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8684] [t: 0 w_t_id: 0]- aswidsagent.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8684|: aswidsagent.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8884] [t: 0 w_t_id: 0]- UnityCrashHandler64.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8884|: UnityCrashHandler64.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9516] [t: 0 w_t_id: 0]- RichVideo.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9516|: RichVideo.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9864] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9864|: DropboxUpdate.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11452] [t: 0 w_t_id: 0]- AVGUI.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11452|: AVGUI.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11960] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11960|: LMS.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12272] [t: 0 w_t_id: 0]- DDVCollectorSvcApi.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12272|: DDVCollectorSvcApi.exe |
16:14:52.107 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13116] [t: 0 w_t_id: 0]- AVGUI.exe (elevated True) 0x0 |
16:14:52.107 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13116|: AVGUI.exe |
16:16:12.758 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9524] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0 |
16:16:12.758 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9524|: msedge.exe |
16:16:46.964 | 28A0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
16:16:52.220 | 28A0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
16:17:01.101 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12296] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0 |
16:17:01.102 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12296|: msedge.exe |
16:17:01.102 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13336] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0 |
16:17:01.102 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13336|: msedge.exe |
16:18:39.493 | 28A0 | 629 | ProcessInjector::InjectProcess | process |MTGA.exe| missing h |
16:21:09.928 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7224] [t: 0 w_t_id: 0]- MTGA.exe (elevated True) 0x0 |
16:21:09.928 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7224|: MTGA.exe |
16:27:24.268 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2940] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0 |
16:27:24.268 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2940|: msedge.exe |
16:29:24.251 | 28A0 | 629 | ProcessInjector::InjectProcess | process |DropboxUpdate.exe| missing h |
16:36:44.448 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6196] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0 |
16:36:44.448 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6196|: msedge.exe |
16:36:52.449 | 28A0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14256] [t: 0 w_t_id: 0]- UnityCrashHandler64.exe (elevated True) 0x0 |
16:36:52.449 | 28A0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14256|: UnityCrashHandler64.exe |