TimeThreadLineFunctionMessage
21:31:50.62335C874GameListService::CreateProcessMaploading game list...
21:31:50.62535C888GameListService::CreateProcessMap1155, 2 loaded
21:31:50.62635C8369ftw1Loading (pid: 15420)
21:31:50.62835C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XCA440000>6|2|1247872841
21:31:50.62835C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XD1180000>6|2|1247872782
21:31:50.73935C8173DXManager::DetectFound in 0
21:31:50.73935C8209Initialize::GetLocation@ 0X5000|20480
21:31:50.73935C8209Initialize::GetLocation@ 0X692E0|430816
21:31:50.73935C8209Initialize::GetLocation@ 0X24490|148624
21:31:50.73935C8209Initialize::GetLocation@ 0X1DE0|7648
21:31:50.73935C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000
21:31:50.73935C8209Initialize::GetLocation@ 0XF93E8880|-113342336
21:31:50.73935C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000
21:31:50.73935C8209Initialize::GetLocation@ 0XF93EDC50|-113320880
21:31:50.73935C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000
21:31:50.73935C8209Initialize::GetLocation@ 0XF93EC610|-113326576
21:31:50.73935C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XCA440000 <> 0XD1180000
21:31:50.73935C8209Initialize::GetLocation@ 0XF92CAC70|-114512784
21:31:50.75335C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XC3430000>6|2|1247872841
21:31:50.85935C8129DXManager::DetectOK
21:31:50.90535C8186DXManager::DetectDone
21:31:50.90535C8215VTableHolderD3d9::initd3d offsest [sht]: 0x4030 , 0x55a0
21:31:50.90635C8209Initialize::GetLocation@ 0X425A0|271776
21:31:50.90635C8209Initialize::GetLocation@ 0X35C60|220256
21:31:50.90635C8209Initialize::GetLocation@ 0X3E860|256096
21:31:50.90635C8209Initialize::GetLocation@ 0XB8640|755264
21:31:50.90635C8209Initialize::GetLocation@ 0XB8190|754064
21:31:50.90635C8209Initialize::GetLocation@ 0XC6C0|50880
21:31:50.90635C8209Initialize::GetLocation@ 0XB8230|754224
21:31:50.90635C8209Initialize::GetLocation@ 0X1D4F0|120048
21:31:50.90635C8209Initialize::GetLocation@ 0X1FF40|130880
21:31:50.90635C8209Initialize::GetLocation@ 0X28570|165232
21:31:50.90635C8209Initialize::GetLocation@ 0X114BB0|1133488
21:31:50.90635C8209Initialize::GetLocation@ 0X114670|1132144
21:31:50.90635C8209Initialize::GetLocation@ 0X1D3E0|119776
21:31:50.90635C8209Initialize::GetLocation@ 0X1D2F0|119536
21:31:50.90635C8209Initialize::GetLocation@ 0XF080|61568
21:31:50.90635C8209Initialize::GetLocation@ 0X4A4C0|304320
21:31:50.90635C8209Initialize::GetLocation@ 0XC230|49712
21:31:50.90635C8209Initialize::GetLocation@ 0XCF940|850240
21:31:50.90635C8209Initialize::GetLocation@ 0XD0010|851984
21:31:50.90635C8209Initialize::GetLocation@ 0XC230|49712
21:31:50.90635C8209Initialize::GetLocation@ 0XD0B00|854784
21:31:50.90635C8209Initialize::GetLocation@ 0XD1160|856416
21:31:50.93335C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XB9D40000>6|2|1247870977
21:31:50.97735C883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
21:31:50.97735C8209Initialize::GetLocation@ 0X4040|16448
21:31:50.97735C8209Initialize::GetLocation@ 0X6410|25616
21:31:50.97735C8209Initialize::GetLocation@ 0X65C0|26048
21:31:50.98135C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X737A0000>6|2|1247870977
21:31:51.1635C893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
21:31:51.1635C8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
21:31:51.1735C8209Initialize::GetLocation@ 0XA5D0|42448
21:31:51.1735C8209Initialize::GetLocation@ 0XD4D0|54480
21:31:51.1735C8209Initialize::GetLocation@ 0XD290|53904
21:31:51.7835C8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_20115420 opened succesfuly
21:31:51.7835C872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4030 , 0x55a0
21:31:51.7835C8255InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_20115420 close 2147483647 bytes
21:31:51.7935C8305InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.204.0.1\OWExplorer.dll]
21:31:51.8735C8393ftw1OWExplorer injected
21:31:51.88130071Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |124| (w: 0x0): Registry
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |2628| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |3244| (w: 0x0): \Device\HarddiskVolume5\Program Files\ESET\ESET Security\ekrn.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |3400| (w: 0x0): \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_0c50dc64ed3c91bc\Display.NvContainer\NVDisplay.Container.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |3616| (w: 0x0): MemCompression
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |5412| (w: 0x0): C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |6532| (w: 0x0): \Device\HarddiskVolume5\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |6644| (w: 0x0): \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_0c50dc64ed3c91bc\Display.NvContainer\NVDisplay.Container.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |6848| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7240| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7696| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7712| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\CheckPoint\Endpoint Connect\Watchdog\EPWD.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7824| (w: 0x0): \Device\HarddiskVolume5\Program Files\Privax\HMA VPN\VpnSvc.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7880| (w: 0x0): \Device\HarddiskVolume5\Program Files\WindowsApps\Microsoft.GamingServices_5.68.30003.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7884| (w: 0x0): \Device\HarddiskVolume5\Program Files\WindowsApps\Microsoft.GamingServices_5.68.30003.0_x64__8wekyb3d8bbwe\gamingservices.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |8004| (w: 0x0): \Device\HarddiskVolume5\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |8468| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |8564| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |8628| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnsrc.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |11304| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.UserSessionHelper.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |13596| (w: 0x0): C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |15336| (w: 0x0): C:\Program Files\Riot Vanguard\vgtray.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |17136| (w: 0x0): \Device\HarddiskVolume5\Program Files\Parsec\parsecd.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |17928| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22062.543.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |18364| (w: 0x0): C:\Program Files\ESET\ESET Security\eguiProxy.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |19772| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
21:33:51.9214964280ProcessInjector::HandlePendingProccesssprocess detection skipped |22208| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
21:36:11.8964964280ProcessInjector::HandlePendingProccesssprocess detection skipped |8716| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe
21:38:13.8804964280ProcessInjector::HandlePendingProccesssprocess detection skipped |4888| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe
21:38:13.8804964280ProcessInjector::HandlePendingProccesssprocess detection skipped |18044| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe
21:38:13.8804964280ProcessInjector::HandlePendingProccesssprocess detection skipped |23368| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe
21:38:14.8934964280ProcessInjector::HandlePendingProccesssprocess detection skipped |2380| (w: 0x0): C:\Users\Eliran lanzer\AppData\Local\Google\Chrome\User Data\SwReporter\104.288.200\software_reporter_tool.exe
21:47:52.2374964612ProcessInjector::InjectExplorerToProcessInjected to process 22372 [mt 22816] 0xc008a
21:49:37.3054964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7744| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
21:53:02.8544964612ProcessInjector::InjectExplorerToProcessInjected to process 18700 [mt 3020] 0xff0822
21:54:46.7024964280ProcessInjector::HandlePendingProccesssprocess detection skipped |3424| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBar.exe
22:07:39.3804964280ProcessInjector::HandlePendingProccesssprocess detection skipped |12320| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2022.30070.26007.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
03:23:45.5674964280ProcessInjector::HandlePendingProccesssprocess detection skipped |4024| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe
03:23:45.5674964280ProcessInjector::HandlePendingProccesssprocess detection skipped |22132| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe
03:23:49.5984964280ProcessInjector::HandlePendingProccesssprocess detection skipped |10832| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:47:37.6024964280ProcessInjector::HandlePendingProccesssprocess detection skipped |21372| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
12:38:28.1704964280ProcessInjector::HandlePendingProccesssprocess detection skipped |24924| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\GPUPowerSavingPlugin\GPU Power Saving.exe
13:42:17.7404964280ProcessInjector::HandlePendingProccesssprocess detection skipped |16288| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\GPUPowerSavingPlugin\GPU Power Saving.exe
14:03:33.3654964280ProcessInjector::HandlePendingProccesssprocess detection skipped |9568| (w: 0x0): C:\Program Files\ASUS\ARMOURY CRATE Service\GPUPowerSavingPlugin\GPU Power Saving.exe
18:07:28.3024964280ProcessInjector::HandlePendingProccesssprocess detection skipped |26208| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe
20:48:27.214964612ProcessInjector::InjectExplorerToProcessInjected to process 24756 [mt 19336] 0x110ba4
20:50:12.3384964280ProcessInjector::HandlePendingProccesssprocess detection skipped |25920| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
03:23:45.3274964280ProcessInjector::HandlePendingProccesssprocess detection skipped |25344| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\Google\Update\GoogleUpdate.exe
09:19:29.2544964280ProcessInjector::HandlePendingProccesssprocess detection skipped |1828| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
10:48:05.8814964280ProcessInjector::HandlePendingProccesssprocess detection skipped |13692| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
18:07:28.4344964280ProcessInjector::HandlePendingProccesssprocess detection skipped |12884| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe
10:49:56.7954964280ProcessInjector::HandlePendingProccesssprocess detection skipped |2980| (w: 0x0): \Device\HarddiskVolume5\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
18:07:27.7374964280ProcessInjector::HandlePendingProccesssprocess detection skipped |23768| (w: 0x0): \Device\HarddiskVolume5\Program Files (x86)\ASUS\Update\AsusUpdate.exe
23:00:53.1824964612ProcessInjector::InjectExplorerToProcessInjected to process 18952 [mt 6368] 0x850268
23:02:24.944964280ProcessInjector::HandlePendingProccesssprocess detection skipped |7756| (w: 0x0): C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.822.6271.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
00:25:13.524130076Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
00:25:13.55735C866ProcessesMonitor::Stopstopping PM...
00:25:13.5573F90126ProcessesMonitor::ProcessEnumerateThreadexit process listener
00:25:13.55935C8420ProcessInjector::Unhookunhook running process
00:25:19.56835C866ProcessesMonitor::Stopstopping PM...