Time | Thread | Line | Function | Message |
17:43:59.500 | 43AC | 361 | ftw1 | Loading (pid: 6016) |
17:43:59.501 | 43AC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X376C0000>6|2|1247870977 |
17:43:59.501 | 43AC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X3A260000>6|2|1247870977 |
17:43:59.503 | 5C4 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
17:43:59.621 | 43AC | 172 | DXManager::Detect | Found in 0 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0X69160|430432 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0X20410|132112 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
17:43:59.622 | 43AC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X376C0000 <> 0X3A260000 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0XFD588850|-44529584 |
17:43:59.622 | 43AC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X376C0000 <> 0X3A260000 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0XFD58DE80|-44507520 |
17:43:59.622 | 43AC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X376C0000 <> 0X3A260000 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0XFD58C5E0|-44513824 |
17:43:59.622 | 43AC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X376C0000 <> 0X3A260000 |
17:43:59.622 | 43AC | 209 | Initialize::GetLocation | @ 0XFD46A7F0|-45701136 |
17:43:59.642 | 43AC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X31660000>6|2|1247870977 |
17:43:59.746 | 43AC | 129 | DXManager::Detect | OK |
17:43:59.809 | 43AC | 186 | DXManager::Detect | Done |
17:43:59.809 | 43AC | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X3FC10|261136 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X33840|211008 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X3BFA0|245664 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XB70E0|749792 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XB6C30|748592 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XAF40|44864 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XB6CD0|748752 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X20C40|134208 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X16A10|92688 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X2D530|185648 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X113350|1127248 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X112E10|1125904 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X20B30|133936 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X20A40|133696 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XD8D0|55504 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0X466B0|288432 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XAAB0|43696 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XCE2D0|844496 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XCE9A0|846240 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XAAB0|43696 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XCF490|849040 |
17:43:59.810 | 43AC | 209 | Initialize::GetLocation | @ 0XCFAF0|850672 |
17:43:59.841 | 43AC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0XFB70000>6|2|1247870977 |
17:43:59.852 | 43AC | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
17:43:59.852 | 43AC | 209 | Initialize::GetLocation | @ 0X4040|16448 |
17:43:59.852 | 43AC | 209 | Initialize::GetLocation | @ 0X6410|25616 |
17:43:59.852 | 43AC | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
17:43:59.853 | 43AC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XEB50000>6|2|1247870977 |
17:43:59.861 | 43AC | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
17:43:59.861 | 43AC | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
17:43:59.861 | 43AC | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
17:43:59.861 | 43AC | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
17:43:59.861 | 43AC | 209 | Initialize::GetLocation | @ 0XD290|53904 |
17:43:59.926 | 43AC | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_78_13_6016 opened succesfuly |
17:43:59.926 | 43AC | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
17:43:59.926 | 43AC | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_78_13_6016 close 2147483647 bytes |
17:43:59.926 | 43AC | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.148.81.21\OWExplorer.dll] |
17:43:59.928 | 43AC | 385 | ftw1 | OWExplorer injected |
17:44:00.200 | 2370 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
17:44:00.200 | 2370 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
17:44:00.200 | 2370 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
17:44:00.200 | 2370 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [708] [t: 0 w_t_id: 0]- robotaskbaricon-x64.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |708|: robotaskbaricon-x64.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1436] [t: 0 w_t_id: 0]- UnrealCEFSubProcess.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1436|: UnrealCEFSubProcess.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2024] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2024|: NVDisplay.Container.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4432] [t: 0 w_t_id: 0]- Exilence Next.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4432|: Exilence Next.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5344] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5344|: nvcontainer.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5528] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5528|: MsMpEng.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7456] [t: 0 w_t_id: 0]- DTShellHlp.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7456|: DTShellHlp.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8240] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8240|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10012] [t: 0 w_t_id: 0]- Exilence Next.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10012|: Exilence Next.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16160] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16160|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16232] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16232|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16496] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16496|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16516] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16516|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16680] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16680|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17832] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17832|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18844] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18844|: firefox.exe |
17:46:30.922 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18916] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:30.922 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18916|: firefox.exe |
17:46:31.924 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19288] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:46:31.924 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19288|: firefox.exe |
17:48:16.535 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9392] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:48:16.535 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9392|: firefox.exe |
17:49:47.128 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18588] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5 |
17:49:47.128 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18588|: firefox.exe |
18:19:09.349 | 1C3C | 379 | ProcessInjector::DoElevetedInjection | Failed to inject process [11792] 0x57 |
18:19:09.349 | 1C3C | 335 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [11792] [t: 19604 w_t_id: 19604]- WhatsApp.exe (elevated True) 0x57 |
18:19:10.301 | 1C3C | 379 | ProcessInjector::DoElevetedInjection | Failed to inject process [11792] 0x57 |
18:19:10.301 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11792] [t: 19604 w_t_id: 19604]- WhatsApp.exe (elevated True) 0x57 |
18:19:10.301 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11792|: WhatsApp.exe |
18:21:27.227 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4112] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x57 |
18:21:27.227 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4112|: WhatsApp.exe |
18:21:27.227 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5424] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x57 |
18:21:27.227 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5424|: WhatsApp.exe |
18:21:29.242 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10200] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x57 |
18:21:29.242 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10200|: WhatsApp.exe |
19:03:03.406 | 1C3C | 352 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2428] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
19:03:03.406 | 1C3C | 291 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2428|: firefox.exe |
19:05:46.280 | 43AC | 66 | ProcessesMonitor::Stop | stopping PM... |
19:05:46.280 | 2370 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
19:05:52.289 | 43AC | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |