TimeThreadLineFunctionMessage
13:35:19.6604C20361ftw1Loading (pid: 16980)
13:35:19.6624C2048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X58DE0000>6|2|1247871522
13:35:19.6624C2048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X5BDA0000>6|2|1247871522
13:35:19.66444EC146ProcessHardwareRecorder::CommandThreadstarting recorder thread
13:35:19.9184C20172DXManager::DetectFound in 0
13:35:19.9194C20209Initialize::GetLocation@ 0X4F80|20352
13:35:19.9194C20209Initialize::GetLocation@ 0X69640|431680
13:35:19.9194C20209Initialize::GetLocation@ 0X206F0|132848
13:35:19.9194C20209Initialize::GetLocation@ 0X1DE0|7648
13:35:19.9194C20111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58DE0000 <> 0X5BDA0000
13:35:19.9194C20209Initialize::GetLocation@ 0XFD168860|-48854944
13:35:19.9194C20111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58DE0000 <> 0X5BDA0000
13:35:19.9194C20209Initialize::GetLocation@ 0XFD16DC30|-48833488
13:35:19.9194C20111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58DE0000 <> 0X5BDA0000
13:35:19.9194C20209Initialize::GetLocation@ 0XFD16C5F0|-48839184
13:35:19.9194C20111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58DE0000 <> 0X5BDA0000
13:35:19.9194C20209Initialize::GetLocation@ 0XFD04A7F0|-50026512
13:35:19.9394C2048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X3C120000>6|2|1247871638
13:35:20.1094C20129DXManager::DetectOK
13:35:20.1874C20186DXManager::DetectDone
13:35:20.1874C20215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
13:35:20.1884C20209Initialize::GetLocation@ 0X41B90|269200
13:35:20.1884C20209Initialize::GetLocation@ 0X33E20|212512
13:35:20.1884C20209Initialize::GetLocation@ 0X3D6C0|251584
13:35:20.1884C20209Initialize::GetLocation@ 0XB8E10|757264
13:35:20.1884C20209Initialize::GetLocation@ 0XB8960|756064
13:35:20.1884C20209Initialize::GetLocation@ 0XACF0|44272
13:35:20.1884C20209Initialize::GetLocation@ 0XB8A00|756224
13:35:20.1884C20209Initialize::GetLocation@ 0X1B6B0|112304
13:35:20.1884C20209Initialize::GetLocation@ 0X1E100|123136
13:35:20.1884C20209Initialize::GetLocation@ 0X26730|157488
13:35:20.1884C20209Initialize::GetLocation@ 0X1146B0|1132208
13:35:20.1884C20209Initialize::GetLocation@ 0X114170|1130864
13:35:20.1884C20209Initialize::GetLocation@ 0X1B5A0|112032
13:35:20.1884C20209Initialize::GetLocation@ 0X1B4B0|111792
13:35:20.1884C20209Initialize::GetLocation@ 0XD680|54912
13:35:20.1884C20209Initialize::GetLocation@ 0X493C0|299968
13:35:20.1884C20209Initialize::GetLocation@ 0XA860|43104
13:35:20.1884C20209Initialize::GetLocation@ 0XD0000|851968
13:35:20.1884C20209Initialize::GetLocation@ 0XD06D0|853712
13:35:20.1884C20209Initialize::GetLocation@ 0XA860|43104
13:35:20.1884C20209Initialize::GetLocation@ 0XD11C0|856512
13:35:20.1884C20209Initialize::GetLocation@ 0XD1820|858144
13:35:20.2114C2048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XC7D0000>6|2|1247870977
13:35:20.2294C2083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
13:35:20.2294C20209Initialize::GetLocation@ 0X4040|16448
13:35:20.2294C20209Initialize::GetLocation@ 0X6410|25616
13:35:20.2294C20209Initialize::GetLocation@ 0X65C0|26048
13:35:20.2304C2048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XC5E0000>6|2|1247870977
13:35:20.2454C2093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
13:35:20.2454C20110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
13:35:20.2464C20209Initialize::GetLocation@ 0XA5D0|42448
13:35:20.2464C20209Initialize::GetLocation@ 0XD4D0|54480
13:35:20.2464C20209Initialize::GetLocation@ 0XD290|53904
13:35:20.3024C20225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_16980 opened succesfuly
13:35:20.3024C2072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
13:35:20.3024C20256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_16980 close 2147483647 bytes
13:35:20.3024C20297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.31\OWExplorer.dll]
13:35:20.3114C20385ftw1OWExplorer injected
13:35:20.75052AC51`anonymous-namespace'::CreateProviderInitialize provider: NET
13:35:20.75052AC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
13:35:20.75052AC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
13:35:20.75052AC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
13:35:20.76352B0629ProcessInjector::InjectProcessprocess |RogueKillerSvc.exe| missing h
13:35:24.34252B0629ProcessInjector::InjectProcessprocess |LiveHelpDesk.exe| missing h
13:35:37.44552B0629ProcessInjector::InjectProcessprocess |RogueKiller64.exe| missing h
13:36:32.85252B0629ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
13:36:37.92352B0629ProcessInjector::InjectProcessprocess |wmpnetwk.exe| missing h
13:37:32.28052B0629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:37:32.28052B0629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:37:32.28052B0629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:37:32.28052B0629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:37:32.28052B0629ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
13:37:51.43352B0441ProcessInjector::HandleElevatedProcessFail injection to process [2272] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x5
13:37:51.43352B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |2272|: NVDisplay.Container.exe
13:37:51.43352B0441ProcessInjector::HandleElevatedProcessFail injection to process [4520] [t: 0 w_t_id: 0]- RogueKillerSvc.exe (elevated True) 0x5
13:37:51.43452B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |4520|: RogueKillerSvc.exe
13:37:51.43452B0441ProcessInjector::HandleElevatedProcessFail injection to process [4528] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x5
13:37:51.43452B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |4528|: nvcontainer.exe
13:37:51.43452B0441ProcessInjector::HandleElevatedProcessFail injection to process [4660] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
13:37:51.43452B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |4660|: MsMpEng.exe
13:37:51.43452B0441ProcessInjector::HandleElevatedProcessFail injection to process [11312] [t: 0 w_t_id: 0]- NZXT CAM Beta.exe (elevated True) 0x5
13:37:51.43452B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |11312|: NZXT CAM Beta.exe
13:37:51.43452B0441ProcessInjector::HandleElevatedProcessFail injection to process [15452] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x5
13:37:51.43452B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |15452|: splwow64.exe
13:37:52.43952B0441ProcessInjector::HandleElevatedProcessFail injection to process [19504] [t: 0 w_t_id: 0]- cam_helper.exe (elevated True) 0x5
13:37:52.43952B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |19504|: cam_helper.exe
13:37:52.43952B0441ProcessInjector::HandleElevatedProcessFail injection to process [19716] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x5
13:37:52.43952B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |19716|: EpicWebHelper.exe
13:37:56.48852B0629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:38:12.61052B0441ProcessInjector::HandleElevatedProcessFail injection to process [26656] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x5
13:38:12.61052B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |26656|: EpicWebHelper.exe
13:38:24.68452B0629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:39:08.1252B0441ProcessInjector::HandleElevatedProcessFail injection to process [22620] [t: 0 w_t_id: 0]- wmpnetwk.exe (elevated True) 0x0
13:39:08.1252B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |22620|: wmpnetwk.exe
13:40:02.40752B0441ProcessInjector::HandleElevatedProcessFail injection to process [21484] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
13:40:02.40752B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |21484|: MicrosoftEdgeUpdate.exe
13:40:02.40752B0441ProcessInjector::HandleElevatedProcessFail injection to process [26012] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
13:40:02.40752B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |26012|: GoogleUpdate.exe
13:40:13.49152B0629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:40:51.73852B0441ProcessInjector::HandleElevatedProcessFail injection to process [7176] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:40:51.73852B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |7176|: firefox.exe
13:40:51.73852B0441ProcessInjector::HandleElevatedProcessFail injection to process [17516] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:40:51.73852B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |17516|: firefox.exe
13:40:51.73852B0441ProcessInjector::HandleElevatedProcessFail injection to process [23764] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:40:51.73852B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |23764|: firefox.exe
13:41:50.24152B0441ProcessInjector::HandleElevatedProcessFail injection to process [24392] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
13:41:50.24152B0380ProcessInjector::HandlePendingProccesssFail to inject pending process |24392|: firefox.exe
13:44:36.51152B0629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:44:36.51152B0629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
14:08:52.5024C2066ProcessesMonitor::Stopstopping PM...
14:08:52.50252AC119ProcessesMonitor::ProcessEnumerateThreadexit process listener