Time | Thread | Line | Function | Message |
15:49:10.512 | 3520 | 365 | ftw1 | Loading (pid: 12972) |
15:49:10.512 | 3564 | 147 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
15:49:10.687 | 3520 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X44C10000>6|2|1203372419 |
15:49:10.687 | 3520 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X45E90000>6|2|1203372847 |
15:49:10.706 | 3520 | 172 | DXManager::Detect | Found in 0 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0X4670|18032 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0X66400|418816 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0X19DE0|105952 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0X1350|4944 |
15:49:10.706 | 3520 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X44C10000 <> 0X45E90000 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0XFEEA2E80|-18207104 |
15:49:10.706 | 3520 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X44C10000 <> 0X45E90000 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0XFEEA7F80|-18186368 |
15:49:10.706 | 3520 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X44C10000 <> 0X45E90000 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0XFEE9E620|-18225632 |
15:49:10.706 | 3520 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X44C10000 <> 0X45E90000 |
15:49:10.706 | 3520 | 209 | Initialize::GetLocation | @ 0XFED8AD10|-19354352 |
15:49:10.711 | 3520 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XCE60000>6|2|1203372419 |
15:49:10.727 | 3520 | 129 | DXManager::Detect | OK |
15:49:10.737 | 3520 | 186 | DXManager::Detect | Done |
15:49:10.737 | 3520 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X3AC00|240640 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X2C5B0|181680 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X36D00|224512 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XAE020|712736 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XADB70|711536 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X5880|22656 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XADC10|711696 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X20FF0|135152 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X1CA60|117344 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X1C8E0|116960 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X1084E0|1082592 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X107F90|1081232 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X248B0|149680 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X247A0|149408 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X2C440|181312 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0X3F210|258576 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XF4E0|62688 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XF5D0|62928 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XF3E0|62432 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XF280|62080 |
15:49:10.737 | 3520 | 209 | Initialize::GetLocation | @ 0XF430|62512 |
15:49:10.745 | 3520 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X16A90000>6|2|1203372033 |
15:49:10.827 | 3520 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
15:49:10.827 | 3520 | 209 | Initialize::GetLocation | @ 0X3CC0|15552 |
15:49:10.827 | 3520 | 209 | Initialize::GetLocation | @ 0X5FD0|24528 |
15:49:10.827 | 3520 | 209 | Initialize::GetLocation | @ 0X6180|24960 |
15:49:10.828 | 3520 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XE6ED0000>6|2|1203372033 |
15:49:10.849 | 3520 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
15:49:10.849 | 3520 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
15:49:10.850 | 3520 | 209 | Initialize::GetLocation | @ 0X10000|65536 |
15:49:10.850 | 3520 | 209 | Initialize::GetLocation | @ 0X12C80|76928 |
15:49:10.850 | 3520 | 209 | Initialize::GetLocation | @ 0X12A60|76384 |
15:49:10.902 | 3520 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_85_4_12972 opened succesfuly |
15:49:10.902 | 3520 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
15:49:10.902 | 3520 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_85_4_12972 close 2147483647 bytes |
15:49:10.902 | 3520 | 301 | InjectOWExplorer | Explorer file name [C:\Users\User\Desktop\Overwolf\0.169.0.22\OWExplorer.dll] |
15:49:10.911 | 3520 | 389 | ftw1 | OWExplorer injected |
15:49:10.912 | 2620 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
15:49:11.209 | 754 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
15:49:11.210 | 754 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
15:49:11.210 | 754 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
15:49:11.210 | 754 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
15:49:11.220 | 35D8 | 669 | ProcessInjector::InjectProcess | process |EvtEng.exe| missing h |
15:49:11.221 | 35D8 | 669 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
15:49:11.221 | 35D8 | 669 | ProcessInjector::InjectProcess | process |mDNSResponder.exe| missing h |
15:49:11.221 | 35D8 | 669 | ProcessInjector::InjectProcess | process |gameinputsvc.exe| missing h |
15:49:11.221 | 35D8 | 669 | ProcessInjector::InjectProcess | process |servicehost.exe| missing h |
15:49:11.221 | 35D8 | 669 | ProcessInjector::InjectProcess | process |rtop_svc.exe| missing h |
15:49:11.221 | 35D8 | 669 | ProcessInjector::InjectProcess | process |GamingServices.exe| missing h |
15:49:11.224 | 35D8 | 669 | ProcessInjector::InjectProcess | process |GamingServicesNet.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |IAStorDataMgrSvc.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |LMS.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |DiscoverySrv.exe| missing h |
15:49:11.228 | 35D8 | 669 | ProcessInjector::InjectProcess | process |GoogleCrashHandler64.exe| missing h |
15:49:11.387 | 35D8 | 669 | ProcessInjector::InjectProcess | process |parsecd.exe| missing h |
15:51:21.936 | 35D8 | 669 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1152] [t: 0 w_t_id: 0]- FAHWindow64.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1152|: FAHWindow64.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1500] [t: 0 w_t_id: 0]- browserhost.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1500|: browserhost.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1756] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1756|: MicrosoftEdgeUpdate.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2112] [t: 0 w_t_id: 0]- ByteFence.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2112|: ByteFence.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2908] [t: 0 w_t_id: 0]- DiscoverySrv.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2908|: DiscoverySrv.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4116] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4116|: GoogleCrashHandler.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4192] [t: 0 w_t_id: 0]- EvtEng.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4192|: EvtEng.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4208] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4208|: gameinputsvc.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4312] [t: 0 w_t_id: 0]- mDNSResponder.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4312|: mDNSResponder.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4668] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4668|: gameinputsvc.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4764] [t: 0 w_t_id: 0]- rtop_svc.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4764|: rtop_svc.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4780] [t: 0 w_t_id: 0]- servicehost.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4780|: servicehost.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5304] [t: 0 w_t_id: 0]- IAStorDataMgrSvc.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5304|: IAStorDataMgrSvc.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7660] [t: 0 w_t_id: 0]- uihost.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7660|: uihost.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8188] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8188|: LMS.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8388] [t: 0 w_t_id: 0]- ChromiumUpdate.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8388|: ChromiumUpdate.exe |
15:51:41.930 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9352] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0 |
15:51:41.930 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9352|: GoogleCrashHandler64.exe |
15:52:35.946 | 35D8 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:52:39.941 | 35D8 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:54:07.937 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6348] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
15:54:07.937 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6348|: software_reporter_tool.exe |
15:54:27.942 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12412] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
15:54:27.942 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12412|: software_reporter_tool.exe |
15:54:47.956 | 35D8 | 386 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14688] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0 |
15:54:47.956 | 35D8 | 318 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14688|: software_reporter_tool.exe |
16:58:00.606 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
17:58:06.885 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
18:58:07.429 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
19:52:36.942 | 35D8 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
19:52:38.930 | 35D8 | 669 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
19:58:09.6 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
20:58:08.732 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
20:58:35.732 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |
21:58:08.739 | 35D8 | 669 | ProcessInjector::InjectProcess | process |ChromiumUpdate.exe| missing h |