Time | Thread | Line | Function | Message |
12:16:53.557 | 3BE8 | 361 | ftw1 | Loading (pid: 4712) |
12:16:53.557 | DA4 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
12:16:53.558 | 3BE8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X14800000>6|2|1247871522 |
12:16:53.558 | 3BE8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X17760000>6|2|1247871522 |
12:16:53.670 | 3BE8 | 172 | DXManager::Detect | Found in 0 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0X69640|431680 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
12:16:53.672 | 3BE8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0XFD1C8860|-48461728 |
12:16:53.672 | 3BE8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0XFD1CDC30|-48440272 |
12:16:53.672 | 3BE8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0XFD1CC5F0|-48445968 |
12:16:53.672 | 3BE8 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000 |
12:16:53.672 | 3BE8 | 209 | Initialize::GetLocation | @ 0XFD0AA7F0|-49633296 |
12:16:53.745 | 3BE8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XF4BD0000>6|2|1247871638 |
12:16:53.820 | 3BE8 | 129 | DXManager::Detect | OK |
12:16:53.866 | 3BE8 | 186 | DXManager::Detect | Done |
12:16:53.866 | 3BE8 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X41B90|269200 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X33E20|212512 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X3D6C0|251584 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XB8E10|757264 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XB8960|756064 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XACF0|44272 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XB8A00|756224 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X1B6B0|112304 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X1E100|123136 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X26730|157488 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X1146B0|1132208 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X114170|1130864 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X1B5A0|112032 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X1B4B0|111792 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD680|54912 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0X493C0|299968 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XA860|43104 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD0000|851968 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD06D0|853712 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XA860|43104 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD11C0|856512 |
12:16:53.867 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD1820|858144 |
12:16:53.898 | 3BE8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0XE3A40000>6|2|1247870977 |
12:16:53.914 | 3BE8 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
12:16:53.914 | 3BE8 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
12:16:53.914 | 3BE8 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
12:16:53.914 | 3BE8 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
12:16:53.918 | 3BE8 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XE39F0000>6|2|1247870977 |
12:16:53.929 | 3BE8 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
12:16:53.929 | 3BE8 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
12:16:53.929 | 3BE8 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
12:16:53.929 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
12:16:53.929 | 3BE8 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
12:16:53.989 | 3BE8 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_4712 opened succesfuly |
12:16:53.989 | 3BE8 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
12:16:53.989 | 3BE8 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_4712 close 2147483647 bytes |
12:16:53.990 | 3BE8 | 297 | InjectOWExplorer | Explorer file name [D:\Programs\Overwolf\0.162.0.8\OWExplorer.dll] |
12:16:54.138 | 3BE8 | 385 | ftw1 | OWExplorer injected |
12:16:54.568 | 3678 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
12:16:54.568 | 3678 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
12:16:54.568 | 3678 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
12:16:54.568 | 3678 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
12:16:54.578 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officeclicktorun.exe| missing h |
12:16:54.578 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |hamachi-2.exe| missing h |
12:16:54.578 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |lghub_updater.exe| missing h |
12:16:54.578 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |LMIGuardianSvc.exe| missing h |
12:16:54.578 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
12:16:54.578 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
12:16:54.641 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
12:17:16.329 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
12:17:16.330 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [232] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |232|: MicrosoftEdgeUpdate.exe |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4084] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4084|: GoogleUpdate.exe |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4588] [t: 0 w_t_id: 0]- officeclicktorun.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4588|: officeclicktorun.exe |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4720] [t: 0 w_t_id: 0]- hamachi-2.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4720|: hamachi-2.exe |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4804] [t: 0 w_t_id: 0]- lghub_updater.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4804|: lghub_updater.exe |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4824] [t: 0 w_t_id: 0]- LMIGuardianSvc.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4824|: LMIGuardianSvc.exe |
12:19:24.572 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5084] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
12:19:24.572 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5084|: MsMpEng.exe |
12:21:38.660 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
12:21:39.676 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
12:24:15.969 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
12:29:26.669 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
12:59:26.335 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
13:29:26.567 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
13:31:32.601 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
13:43:44.206 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16572] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0 |
13:43:44.206 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16572|: owobs-ffmpeg-mux.exe |
13:56:43.109 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14856] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0 |
13:56:43.109 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14856|: owobs-ffmpeg-mux.exe |
14:20:56.47 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
14:40:41.664 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |officec2rclient.exe| missing h |
14:45:48.25 | 2EB4 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
15:19:05.214 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8564] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0 |
15:19:05.214 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8564|: EpicWebHelper.exe |
15:19:19.286 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [6452] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0 |
15:19:19.286 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |6452|: EpicWebHelper.exe |
15:19:19.286 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14960] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0 |
15:19:19.286 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14960|: EpicWebHelper.exe |
15:21:19.132 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [896] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:21:19.132 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |896|: firefox.exe |
15:21:19.132 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17568] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:21:19.132 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17568|: firefox.exe |
15:21:22.146 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2068] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:21:22.146 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2068|: firefox.exe |
15:21:35.194 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
15:21:35.194 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4132|: firefox.exe |
15:33:40.369 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16972] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x578 |
15:33:40.369 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16972|: EpicWebHelper.exe |
15:38:05.421 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18372] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578 |
15:38:05.421 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18372|: firefox.exe |
15:38:15.517 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578 |
15:38:15.517 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11632|: firefox.exe |
15:41:18.105 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9100] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578 |
15:41:18.105 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9100|: firefox.exe |
15:46:32.886 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18128] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x578 |
15:46:32.886 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18128|: EpicWebHelper.exe |
15:46:54.63 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13200] [t: 0 w_t_id: 0]- EOSOverlayRenderer-Win64-Shipping.exe (elevated True) 0x578 |
15:46:54.63 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13200|: EOSOverlayRenderer-Win64-Shipping.exe |
15:47:00.136 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12848] [t: 0 w_t_id: 0]- EOSOverlayRenderer-Win64-Shipping.exe (elevated True) 0x578 |
15:47:00.136 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12848|: EOSOverlayRenderer-Win64-Shipping.exe |
15:50:15.555 | 2EB4 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [952] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x578 |
15:50:15.555 | 2EB4 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |952|: EpicWebHelper.exe |