Time | Thread | Line | Function | Message |
21:31:50.623 | 35C8 | 74 | GameListService::CreateProcessMap | loading game list... |
21:31:50.625 | 35C8 | 88 | GameListService::CreateProcessMap | 1155, 2 loaded |
21:31:50.626 | 35C8 | 369 | ftw1 | Loading (pid: 15420) |
21:31:50.628 | 35C8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XCA440000>6|2|1247872841 |
21:31:50.628 | 35C8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XD1180000>6|2|1247872782 |
21:31:50.739 | 35C8 | 173 | DXManager::Detect | Found in 0 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0X5000|20480 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0X692E0|430816 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0X24490|148624 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
21:31:50.739 | 35C8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0XF93E8880|-113342336 |
21:31:50.739 | 35C8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0XF93EDC50|-113320880 |
21:31:50.739 | 35C8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0XF93EC610|-113326576 |
21:31:50.739 | 35C8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000 |
21:31:50.739 | 35C8 | 209 | Initialize::GetLocation | @ 0XF92CAC70|-114512784 |
21:31:50.753 | 35C8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XC3430000>6|2|1247872841 |
21:31:50.859 | 35C8 | 129 | DXManager::Detect | OK |
21:31:50.905 | 35C8 | 186 | DXManager::Detect | Done |
21:31:50.905 | 35C8 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4030 , 0x55a0 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X425A0|271776 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X35C60|220256 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X3E860|256096 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XB8640|755264 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XB8190|754064 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XC6C0|50880 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XB8230|754224 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X1D4F0|120048 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X1FF40|130880 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X28570|165232 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X114BB0|1133488 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X114670|1132144 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X1D3E0|119776 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X1D2F0|119536 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XF080|61568 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0X4A4C0|304320 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XC230|49712 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XCF940|850240 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XD0010|851984 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XC230|49712 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XD0B00|854784 |
21:31:50.906 | 35C8 | 209 | Initialize::GetLocation | @ 0XD1160|856416 |
21:31:50.933 | 35C8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0XB9D40000>6|2|1247870977 |
21:31:50.977 | 35C8 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
21:31:50.977 | 35C8 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
21:31:50.977 | 35C8 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
21:31:50.977 | 35C8 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
21:31:50.981 | 35C8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X737A0000>6|2|1247870977 |
21:31:51.16 | 35C8 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
21:31:51.16 | 35C8 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
21:31:51.17 | 35C8 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
21:31:51.17 | 35C8 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
21:31:51.17 | 35C8 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
21:31:51.78 | 35C8 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_20115420 opened succesfuly |
21:31:51.78 | 35C8 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4030 , 0x55a0 |
21:31:51.78 | 35C8 | 255 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_20115420 close 2147483647 bytes |
21:31:51.79 | 35C8 | 305 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.204.0.1\OWExplorer.dll] |
21:31:51.87 | 35C8 | 393 | ftw1 | OWExplorer injected |
21:31:51.88 | 1300 | 71 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnected | connected to process tracker server |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |124| (w: 0x0): Registry |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |2628| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |3244| (w: 0x0): \Device\HarddiskVolume5\Program Files\ESET\ESET Security\ekrn.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |3400| (w: 0x0): \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_0c50dc64ed3c91bc\Display.NvContainer\NVDisplay.Container.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |3616| (w: 0x0): MemCompression |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |5412| (w: 0x0): C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |6532| (w: 0x0): \Device\HarddiskVolume5\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |6644| (w: 0x0): \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_0c50dc64ed3c91bc\Display.NvContainer\NVDisplay.Container.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |6848| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7240| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7696| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7712| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\CheckPoint\Endpoint Connect\Watchdog\EPWD.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7824| (w: 0x0): \Device\HarddiskVolume5\Program Files\Privax\HMA VPN\VpnSvc.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7880| (w: 0x0): \Device\HarddiskVolume5\Program Files\WindowsApps\Microsoft.GamingServices_5.68.30003.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7884| (w: 0x0): \Device\HarddiskVolume5\Program Files\WindowsApps\Microsoft.GamingServices_5.68.30003.0_x64__8wekyb3d8bbwe\gamingservices.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |8004| (w: 0x0): \Device\HarddiskVolume5\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |8468| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |8564| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |8628| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnsrc.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |11304| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.UserSessionHelper.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |13596| (w: 0x0): C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |15336| (w: 0x0): C:\Program Files\Riot Vanguard\vgtray.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |17136| (w: 0x0): \Device\HarddiskVolume5\Program Files\Parsec\parsecd.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |17928| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22062.543.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |18364| (w: 0x0): C:\Program Files\ESET\ESET Security\eguiProxy.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |19772| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe |
21:33:51.921 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |22208| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe |
21:36:11.896 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |8716| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe |
21:38:13.880 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |4888| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe |
21:38:13.880 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |18044| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe |
21:38:13.880 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |23368| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe |
21:38:14.893 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |2380| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe |
21:47:52.237 | 4964 | 612 | ProcessInjector::InjectExplorerToProcess | Injected to process 22372 [mt 22816] 0xc008a |
21:49:37.305 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7744| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
21:53:02.854 | 4964 | 612 | ProcessInjector::InjectExplorerToProcess | Injected to process 18700 [mt 3020] 0xff0822 |
21:54:46.702 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |3424| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBar.exe |
22:07:39.380 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |12320| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2022.30070.26007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe |
03:23:45.567 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |4024| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe |
03:23:45.567 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |22132| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe |
03:23:49.598 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |10832| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe |
10:47:37.602 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |21372| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe |
12:38:28.170 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |24924| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\GPUPowerSavingPlugin\GPU Power Saving.exe |
13:42:17.740 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |16288| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\GPUPowerSavingPlugin\GPU Power Saving.exe |
14:03:33.365 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |9568| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\GPUPowerSavingPlugin\GPU Power Saving.exe |
18:07:28.302 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |26208| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe |
20:48:27.21 | 4964 | 612 | ProcessInjector::InjectExplorerToProcess | Injected to process 24756 [mt 19336] 0x110ba4 |
20:50:12.338 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |25920| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
03:23:45.327 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |25344| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe |
09:19:29.254 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |1828| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
10:48:05.881 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |13692| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe |
18:07:28.434 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |12884| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe |
10:49:56.795 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |2980| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe |
18:07:27.737 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |23768| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe |
23:00:53.182 | 4964 | 612 | ProcessInjector::InjectExplorerToProcess | Injected to process 18952 [mt 6368] 0x850268 |
23:02:24.94 | 4964 | 280 | ProcessInjector::HandlePendingProccesss | process detection skipped |7756| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe |
00:25:13.524 | 1300 | 76 | Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnected | disconnected to process tracker server |
00:25:13.557 | 35C8 | 66 | ProcessesMonitor::Stop | stopping PM... |
00:25:13.557 | 3F90 | 126 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |
00:25:13.559 | 35C8 | 420 | ProcessInjector::Unhook | unhook running process |
00:25:19.568 | 35C8 | 66 | ProcessesMonitor::Stop | stopping PM... |
| | | | |