Time | Thread | Line | Function | Message |
13:33:48.13 | 6EEC | 361 | ftw1 | Loading (pid: 16888) |
13:33:48.13 | 6FB8 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
13:33:48.14 | 6EEC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X45DF0000>6|2|1247871522 |
13:33:48.15 | 6EEC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X48C40000>6|2|1247871522 |
13:33:48.237 | 6EEC | 172 | DXManager::Detect | Found in 0 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0X69640|431680 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
13:33:48.238 | 6EEC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X45DF0000 <> 0X48C40000 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0XFD2D8860|-47347616 |
13:33:48.238 | 6EEC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X45DF0000 <> 0X48C40000 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0XFD2DDC30|-47326160 |
13:33:48.238 | 6EEC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X45DF0000 <> 0X48C40000 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0XFD2DC5F0|-47331856 |
13:33:48.238 | 6EEC | 111 | Update::Caught | C:\WINDOWS\SYSTEM32\d3d11.dll|0X45DF0000 <> 0X48C40000 |
13:33:48.238 | 6EEC | 209 | Initialize::GetLocation | @ 0XFD1BA7F0|-48519184 |
13:33:48.256 | 6EEC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X293B0000>6|2|1247871638 |
13:33:48.399 | 6EEC | 129 | DXManager::Detect | OK |
13:33:48.454 | 6EEC | 186 | DXManager::Detect | Done |
13:33:48.454 | 6EEC | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X41B90|269200 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X33E20|212512 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X3D6C0|251584 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XB8E10|757264 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XB8960|756064 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XACF0|44272 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XB8A00|756224 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X1B6B0|112304 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X1E100|123136 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X26730|157488 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X1146B0|1132208 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X114170|1130864 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X1B5A0|112032 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X1B4B0|111792 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XD680|54912 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0X493C0|299968 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XA860|43104 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XD0000|851968 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XD06D0|853712 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XA860|43104 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XD11C0|856512 |
13:33:48.456 | 6EEC | 209 | Initialize::GetLocation | @ 0XD1820|858144 |
13:33:48.472 | 6EEC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput.dll) <0X17FC0000>6|2|1247870977 |
13:33:48.500 | 6EEC | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
13:33:48.500 | 6EEC | 209 | Initialize::GetLocation | @ 0X4040|16448 |
13:33:48.500 | 6EEC | 209 | Initialize::GetLocation | @ 0X6410|25616 |
13:33:48.500 | 6EEC | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
13:33:48.501 | 6EEC | 48 | Update::Detect | Env (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X17F70000>6|2|1247870977 |
13:33:48.521 | 6EEC | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
13:33:48.521 | 6EEC | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
13:33:48.521 | 6EEC | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
13:33:48.521 | 6EEC | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
13:33:48.521 | 6EEC | 209 | Initialize::GetLocation | @ 0XD290|53904 |
13:33:48.574 | 6EEC | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_82_5_16888 opened succesfuly |
13:33:48.574 | 6EEC | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
13:33:48.574 | 6EEC | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_82_5_16888 close 2147483647 bytes |
13:33:48.574 | 6EEC | 297 | InjectOWExplorer | Explorer file name [C:\Program Files (x86)\Overwolf\0.159.0.31\OWExplorer.dll] |
13:33:48.582 | 6EEC | 385 | ftw1 | OWExplorer injected |
13:33:48.978 | 501C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
13:33:48.978 | 501C | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
13:33:48.978 | 501C | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
13:33:48.978 | 501C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
13:33:48.990 | 5014 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
13:33:48.990 | 5014 | 629 | ProcessInjector::InjectProcess | process |RogueKillerSvc.exe| missing h |
13:33:49.115 | 5014 | 629 | ProcessInjector::InjectProcess | process |RogueKiller64.exe| missing h |
13:33:49.534 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:33:51.599 | 5014 | 629 | ProcessInjector::InjectProcess | process |owver64.exe| missing h |
13:33:52.594 | 5014 | 629 | ProcessInjector::InjectProcess | process |LiveHelpDesk.exe| missing h |
13:34:12.600 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfSetup.exe| missing h |
13:34:12.600 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfSetup.exe| missing h |
13:34:15.600 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:34:15.600 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:35:00.595 | 5014 | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
13:35:06.594 | 5014 | 629 | ProcessInjector::InjectProcess | process |wmpnetwk.exe| missing h |
13:35:10.594 | 5014 | 629 | ProcessInjector::InjectProcess | process |EasyAntiCheat.exe| missing h |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2232] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2232|: NVDisplay.Container.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4312] [t: 0 w_t_id: 0]- RogueKillerSvc.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4312|: RogueKillerSvc.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4328] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4328|: nvcontainer.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4344] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4344|: MsMpEng.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14592] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14592|: splwow64.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17504] [t: 0 w_t_id: 0]- NZXT CAM Beta.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17504|: NZXT CAM Beta.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19500] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19500|: EpicWebHelper.exe |
13:36:19.594 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20224] [t: 0 w_t_id: 0]- cam_helper.exe (elevated True) 0x0 |
13:36:19.594 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20224|: cam_helper.exe |
13:36:35.593 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [24668] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0 |
13:36:35.593 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |24668|: EpicWebHelper.exe |
13:37:36.591 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10488] [t: 0 w_t_id: 0]- wmpnetwk.exe (elevated True) 0x0 |
13:37:36.591 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10488|: wmpnetwk.exe |
13:37:40.592 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22884] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0 |
13:37:40.592 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22884|: EasyAntiCheat.exe |
13:38:40.596 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:38:41.595 | 5014 | 629 | ProcessInjector::InjectProcess | process |OverwolfUpdater.exe| missing h |
13:41:43.601 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [20804] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5a4 |
13:41:43.601 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |20804|: owobs-ffmpeg-mux.exe |
13:42:00.613 | 5014 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
13:42:00.613 | 5014 | 629 | ProcessInjector::InjectProcess | process |CCUpdate.exe| missing h |
13:42:00.613 | 5014 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
13:42:00.613 | 5014 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
13:42:00.613 | 5014 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
13:42:00.613 | 5014 | 629 | ProcessInjector::InjectProcess | process |GoogleCrashHandler.exe| missing h |
13:42:02.607 | 5014 | 629 | ProcessInjector::InjectProcess | process |CCleaner64.exe| missing h |
13:42:04.609 | 5014 | 629 | ProcessInjector::InjectProcess | process |MicrosoftEdgeUpdate.exe| missing h |
13:42:48.607 | 5014 | 629 | ProcessInjector::InjectProcess | process |GoogleUpdate.exe| missing h |
13:43:04.608 | 5014 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
13:43:04.608 | 5014 | 629 | ProcessInjector::InjectProcess | process |MpCmdRun.exe| missing h |
13:44:30.607 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [11232] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0 |
13:44:30.607 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |11232|: MicrosoftEdgeUpdate.exe |
13:44:30.607 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [19668] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0 |
13:44:30.607 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |19668|: GoogleUpdate.exe |
13:53:43.603 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [18380] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0 |
13:53:43.603 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |18380|: owobs-ffmpeg-mux.exe |
14:07:36.622 | 5014 | 441 | ProcessInjector::HandleElevatedProcess | Fail injection to process [22116] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0 |
14:07:36.622 | 5014 | 380 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |22116|: owobs-ffmpeg-mux.exe |