Time | Thread | Line | Function | Message |
20:08:22.183 | 12E0 | 361 | ftw1 | Loading (pid: 8664) |
20:08:22.185 | 3318 | 146 | ProcessHardwareRecorder::CommandThread | starting recorder thread |
20:08:22.185 | 12E0 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d11.dll) <0X9DEB0000>6|2|1247871522 |
20:08:22.185 | 12E0 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dxgi.dll) <0XA0760000>6|2|1247871522 |
20:08:22.293 | 12E0 | 172 | DXManager::Detect | Found in 0 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0X4F80|20352 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0X69640|431680 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0X206F0|132848 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0X1DE0|7648 |
20:08:22.303 | 12E0 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X9DEB0000 <> 0XA0760000 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0XFD878860|-41449376 |
20:08:22.303 | 12E0 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X9DEB0000 <> 0XA0760000 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0XFD87DC30|-41427920 |
20:08:22.303 | 12E0 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X9DEB0000 <> 0XA0760000 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0XFD87C5F0|-41433616 |
20:08:22.303 | 12E0 | 111 | Update::Caught | C:\Windows\SYSTEM32\d3d11.dll|0X9DEB0000 <> 0XA0760000 |
20:08:22.303 | 12E0 | 209 | Initialize::GetLocation | @ 0XFD75A7F0|-42620944 |
20:08:22.340 | 12E0 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\d3d9.dll) <0X989A0000>6|2|1247871522 |
20:08:22.464 | 12E0 | 129 | DXManager::Detect | OK |
20:08:22.508 | 12E0 | 186 | DXManager::Detect | Done |
20:08:22.509 | 12E0 | 215 | VTableHolderD3d9::init | d3d offsest [sht]: 0x4060 , 0x53c0 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X41060|266336 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X33320|209696 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X3CB90|248720 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XB75B0|751024 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XB7100|749824 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XA1F0|41456 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XB71A0|749984 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X1ABB0|109488 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X1D600|120320 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X25C30|154672 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X113820|1128480 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X1132E0|1127136 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X1AAA0|109216 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X1A9B0|108976 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XCB80|52096 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X47F90|294800 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XCE7A0|845728 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XCEE70|847472 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0X9D60|40288 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XCF960|850272 |
20:08:22.509 | 12E0 | 209 | Initialize::GetLocation | @ 0XCFFC0|851904 |
20:08:22.530 | 12E0 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput.dll) <0X1FB10000>6|2|1247870977 |
20:08:22.550 | 12E0 | 83 | VTableHolderDInput::init | m_pDIW->CreateDevice - succeded. |
20:08:22.551 | 12E0 | 209 | Initialize::GetLocation | @ 0X4040|16448 |
20:08:22.551 | 12E0 | 209 | Initialize::GetLocation | @ 0X6410|25616 |
20:08:22.551 | 12E0 | 209 | Initialize::GetLocation | @ 0X65C0|26048 |
20:08:22.554 | 12E0 | 48 | Update::Detect | Env (C:\Windows\SYSTEM32\dinput8.dll) <0XFF670000>6|2|1247870977 |
20:08:22.576 | 12E0 | 93 | VTableHolderDInput8::init | m_pDI8W->CreateDevice - succeded. |
20:08:22.577 | 12E0 | 110 | VTableHolderDInput8::init | m_pDI8A->CreateDevice - succeded. |
20:08:22.577 | 12E0 | 209 | Initialize::GetLocation | @ 0XA5D0|42448 |
20:08:22.577 | 12E0 | 209 | Initialize::GetLocation | @ 0XD4D0|54480 |
20:08:22.577 | 12E0 | 209 | Initialize::GetLocation | @ 0XD290|53904 |
20:08:22.634 | 12E0 | 225 | InterProcessElement::open | InterProcess Overwolf_SHARED_MEMORY_2_2_81_2_8664 opened succesfuly |
20:08:22.634 | 12E0 | 72 | HookFunctionsTableInitializer::SetHookFunctionsData | D3D9 Sht offsets 0x4060 , 0x53c0 |
20:08:22.634 | 12E0 | 256 | InterProcessElement::close | InterProcess Overwolf_SHARED_MEMORY_2_2_81_2_8664 close 2147483647 bytes |
20:08:22.634 | 12E0 | 297 | InjectOWExplorer | Explorer file name [E:\Apps\Overwolf\0.158.1.1\OWExplorer.dll] |
20:08:22.757 | 12E0 | 385 | ftw1 | OWExplorer injected |
20:08:23.294 | 113C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: NET |
20:08:23.294 | 113C | 117 | libprocess::NetworkTracer::Initialize | init res:0x5 [started:0 active:0 enbaled:0] |
20:08:23.294 | 113C | 54 | `anonymous-namespace'::CreateProvider | Fail to initlized provider: NET |
20:08:23.294 | 113C | 51 | `anonymous-namespace'::CreateProvider | Initialize provider: GPU |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [2816] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |2816|: NVDisplay.Container.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [3240] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |3240|: fsnotifier64.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [4892] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |4892|: MsMpEng.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [5080] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |5080|: firefox.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [10496] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |10496|: firefox.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14452] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14452|: dotnet.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15032] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15032|: dotnet.exe |
20:10:53.787 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15760] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
20:10:53.787 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15760|: dotnet.exe |
20:12:00.798 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [17384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:12:00.798 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |17384|: firefox.exe |
20:12:16.802 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [12440] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:12:16.802 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |12440|: firefox.exe |
20:13:25.810 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [15376] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0 |
20:13:25.810 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |15376|: firefox.exe |
20:16:51.926 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [8712] [t: 0 w_t_id: 0]- dotnet.exe (elevated True) 0x0 |
20:16:51.926 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |8712|: dotnet.exe |
20:18:11.956 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [16012] [t: 0 w_t_id: 0]- fsnotifier64.exe (elevated True) 0x578 |
20:18:11.956 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |16012|: fsnotifier64.exe |
20:18:21.959 | 2884 | 394 | ProcessInjector::HandleElevatedProcess | Fail injection to process [14144] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x578 |
20:18:21.959 | 2884 | 333 | ProcessInjector::HandlePendingProccesss | Fail to inject pending process |14144|: node.exe |