Time | Thread | Line | Function | Message |
12:53:35.933 | 2FE0 | 361 | ftw1 | Loading (pid: 13068) |
12:53:35.933 | 428C | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
12:53:35.934 | 2FE0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XB8720000>6|2|1247871522 |
12:53:35.935 | 2FE0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XBAC20000>6|2|1247871522 |
12:53:36.52 | 2FE0 | 172 | DXManager::Detect | Found in 0 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0X69640|431680 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
12:53:36.53 | 2FE0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0XFDC28860|-37582752 |
12:53:36.53 | 2FE0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0XFDC2DC30|-37561296 |
12:53:36.53 | 2FE0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0XFDC2C5F0|-37566992 |
12:53:36.53 | 2FE0 | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000 |
12:53:36.53 | 2FE0 | 209 | Initialize::GetLocation | @ 0XFDB0A7F0|-38754320 |
12:53:36.67 | 2FE0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XB5AF0000>6|2|1247871638 |
12:53:36.161 | 2FE0 | 129 | DXManager::Detect | OK |
12:53:36.203 | 2FE0 | 186 | DXManager::Detect | Done |
12:53:36.203 | 2FE0 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X41B90|269200 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X33E20|212512 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X3D6C0|251584 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XB8E10|757264 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XB8960|756064 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XACF0|44272 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XB8A00|756224 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X1B6B0|112304 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X1E100|123136 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X26730|157488 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X1146B0|1132208 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X114170|1130864 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X1B5A0|112032 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X1B4B0|111792 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD680|54912 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0X493C0|299968 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XA860|43104 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD0000|851968 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD06D0|853712 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XA860|43104 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD11C0|856512 |
12:53:36.204 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD1820|858144 |
12:53:36.223 | 2FE0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X98170000>6|2|1247870977 |
12:53:36.246 | 2FE0 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
12:53:36.246 | 2FE0 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
12:53:36.246 | 2FE0 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
12:53:36.246 | 2FE0 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
12:53:36.247 | 2FE0 | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X807E0000>6|2|1247870977 |
12:53:36.258 | 2FE0 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
12:53:36.258 | 2FE0 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
12:53:36.258 | 2FE0 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
12:53:36.258 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
12:53:36.258 | 2FE0 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
12:53:36.317 | 2FE0 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_13068 opened succesfuly |
12:53:36.317 | 2FE0 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
12:53:36.317 | 2FE0 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_83_1_13068 close 2147483647 bytes |
12:53:36.317 | 2FE0 | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.162.0.8\OWExplorer.dll] |
12:53:36.322 | 2FE0 | 385 | ftw1 | OWExplorer injected |
12:53:36.564 | 2FC4 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
12:53:36.564 | 2FC4 | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
12:53:36.564 | 2FC4 | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
12:53:36.564 | 2FC4 | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
12:53:36.572 | 41E0 | 629 | ProcessInjector::InjectProcess | process |wmpnetwk.exe| missing h |
12:53:36.572 | 41E0 | 629 | ProcessInjector::InjectProcess | process |LEDKeeper2.exe| missing h |
12:53:36.572 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MSI.CentralServer.exe| missing h |
12:53:36.572 | 41E0 | 629 | ProcessInjector::InjectProcess | process |CC_Engine_x64.exe| missing h |
12:53:36.572 | 41E0 | 629 | ProcessInjector::InjectProcess | process |lghub_updater.exe| missing h |
12:53:36.572 | 41E0 | 629 | ProcessInjector::InjectProcess | process |spd.exe| missing h |
12:53:36.637 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
12:53:36.700 | 41E0 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
12:53:36.700 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
12:53:36.955 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3440] [t: 0 w_t_id: 0]- LEDKeeper2.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3440|: LEDKeeper2.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3700] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3700|: MsMpEng.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4028] [t: 0 w_t_id: 0]- wmpnetwk.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4028|: wmpnetwk.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [7528] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |7528|: NVDisplay.Container.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8920] [t: 0 w_t_id: 0]- MSI.CentralServer.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8920|: MSI.CentralServer.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12440] [t: 0 w_t_id: 0]- CC_Engine_x64.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12440|: CC_Engine_x64.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [13604] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |13604|: GoogleUpdate.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14860] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14860|: MicrosoftEdgeUpdate.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16052] [t: 0 w_t_id: 0]- spd.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16052|: spd.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17632] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17632|: nvcontainer.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18964] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18964|: lghub.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19780] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19780|: lghub.exe |
12:56:07.404 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19856] [t: 0 w_t_id: 0]- lghub_updater.exe (elevated True) 0x0 |
12:56:07.404 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19856|: lghub_updater.exe |
12:56:11.431 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [9396] [t: 0 w_t_id: 0]- wdsync.exe (elevated True) 0x0 |
12:56:11.431 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |9396|: wdsync.exe |
12:56:11.431 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10412] [t: 0 w_t_id: 0]- kdd (elevated True) 0x0 |
12:56:11.431 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10412|: kdd |
12:56:14.454 | 41E0 | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
12:56:41.665 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5900] [t: 0 w_t_id: 0]- wdsync-inotify.exe (elevated True) 0x0 |
12:56:41.665 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5900|: wdsync-inotify.exe |
12:56:41.665 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12800] [t: 0 w_t_id: 0]- wdsync.exe (elevated True) 0x0 |
12:56:41.665 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12800|: wdsync.exe |
12:56:41.665 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15632] [t: 0 w_t_id: 0]- wdsync.exe (elevated True) 0x0 |
12:56:41.665 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15632|: wdsync.exe |
12:58:30.487 | 41E0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:03:13.927 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
13:03:13.927 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
14:05:37.630 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
14:05:37.630 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
14:05:37.630 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
14:13:36.605 | 41E0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
14:16:45.99 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19900] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0 |
14:16:45.99 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19900|: owobs-ffmpeg-mux.exe |
14:49:28.966 | 41E0 | 468 | ProcessInjector::DoElevetedInjection | Failed to inject process [1988] 0x57 |
14:49:28.966 | 41E0 | 424 | ProcessInjector::HandleElevatedProcess | Fail injection to process (will retry again in 5 ses) [1988] [t: 8496 w_t_id: 8496]- conhost.exe (elevated True) 0x57 |
14:49:29.895 | 41E0 | 468 | ProcessInjector::DoElevetedInjection | Failed to inject process [1988] 0x57 |
14:49:29.895 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1988] [t: 8496 w_t_id: 8496]- conhost.exe (elevated True) 0x57 |
14:49:29.895 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1988|: conhost.exe |
15:27:20.224 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16248] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x57 |
15:27:20.224 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16248|: owobs-ffmpeg-mux.exe |
15:34:13.613 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
15:34:13.613 | 41E0 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
16:19:46.907 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17164] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x57 |
16:19:46.907 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17164|: owobs-ffmpeg-mux.exe |
16:43:08.394 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [1744] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5 |
16:43:08.394 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |1744|: owobs-ffmpeg-mux.exe |
16:58:31.232 | 41E0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
17:19:38.461 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11284] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5 |
17:19:38.461 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11284|: owobs-ffmpeg-mux.exe |
17:33:59.441 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8360] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5 |
17:33:59.441 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8360|: owobs-ffmpeg-mux.exe |
17:51:05.755 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14692] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5 |
17:51:05.755 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14692|: owobs-ffmpeg-mux.exe |
17:52:14.354 | 41E0 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
18:10:26.893 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15116] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5 |
18:10:26.893 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15116|: owobs-ffmpeg-mux.exe |
18:13:37.448 | 41E0 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
18:46:38.514 | 41E0 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14868] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5 |
18:46:38.514 | 41E0 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14868|: owobs-ffmpeg-mux.exe |
19:21:06.611 | 2FE0 | 66 | ProcessesMonitor::Stop | stopping PM... |
19:21:06.611 | 2FC4 | 119 | ProcessesMonitor::ProcessEnumerateThread | exit process listener |