TimeThreadLineFunctionMessage
18:33:40.7311438146ProcessHardwareRecorder::CommandThreadstarting recorder thread
18:33:40.7312BC361ftw1Loading (pid: 3412)
18:33:40.7322BC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XDBD00000>6|2|1164117043
18:33:40.7322BC48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XDD9C0000>6|2|1164117043
18:33:40.7932BC172DXManager::DetectFound in 0
18:33:40.7932BC209Initialize::GetLocation@ 0X4910|18704
18:33:40.7932BC209Initialize::GetLocation@ 0X632A0|406176
18:33:40.7932BC209Initialize::GetLocation@ 0X1EF30|126768
18:33:40.7932BC209Initialize::GetLocation@ 0X1D70|7536
18:33:40.7932BC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDBD00000 <> 0XDD9C0000
18:33:40.7932BC209Initialize::GetLocation@ 0XFE46AB00|-28923136
18:33:40.7932BC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDBD00000 <> 0XDD9C0000
18:33:40.7932BC209Initialize::GetLocation@ 0XFE471400|-28896256
18:33:40.7932BC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDBD00000 <> 0XDD9C0000
18:33:40.7932BC209Initialize::GetLocation@ 0XFE466DE0|-28938784
18:33:40.7932BC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDBD00000 <> 0XDD9C0000
18:33:40.7932BC209Initialize::GetLocation@ 0XFE34E9B0|-30086736
18:33:40.8042BC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0XD5C30000>6|2|1164117043
18:33:40.8762BC129DXManager::DetectOK
18:33:40.9082BC186DXManager::DetectDone
18:33:40.9082BC215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
18:33:40.9092BC209Initialize::GetLocation@ 0X3A0A0|237728
18:33:40.9092BC209Initialize::GetLocation@ 0X2DE30|187952
18:33:40.9092BC209Initialize::GetLocation@ 0X35CA0|220320
18:33:40.9092BC209Initialize::GetLocation@ 0XAA4C0|697536
18:33:40.9092BC209Initialize::GetLocation@ 0XAA010|696336
18:33:40.9092BC209Initialize::GetLocation@ 0X62B0|25264
18:33:40.9092BC209Initialize::GetLocation@ 0XAA0B0|696496
18:33:40.9092BC209Initialize::GetLocation@ 0X25E00|155136
18:33:40.9092BC209Initialize::GetLocation@ 0X1E290|123536
18:33:40.9092BC209Initialize::GetLocation@ 0X1E110|123152
18:33:40.9092BC209Initialize::GetLocation@ 0XEBA90|965264
18:33:40.9092BC209Initialize::GetLocation@ 0XEB540|963904
18:33:40.9092BC209Initialize::GetLocation@ 0X25F30|155440
18:33:40.9092BC209Initialize::GetLocation@ 0X25CF0|154864
18:33:40.9092BC209Initialize::GetLocation@ 0X2DCE0|187616
18:33:40.9092BC209Initialize::GetLocation@ 0X3D010|249872
18:33:40.9092BC209Initialize::GetLocation@ 0X10CD0|68816
18:33:40.9092BC209Initialize::GetLocation@ 0X10DD0|69072
18:33:40.9092BC209Initialize::GetLocation@ 0X10EC0|69312
18:33:40.9092BC209Initialize::GetLocation@ 0X10CD0|68816
18:33:40.9092BC209Initialize::GetLocation@ 0X10B70|68464
18:33:40.9092BC209Initialize::GetLocation@ 0X10D20|68896
18:33:40.9252BC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XC1C80000>6|2|1164115969
18:33:40.9342BC83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
18:33:40.9342BC209Initialize::GetLocation@ 0X3D10|15632
18:33:40.9342BC209Initialize::GetLocation@ 0X6130|24880
18:33:40.9342BC209Initialize::GetLocation@ 0X62E0|25312
18:33:40.9352BC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XBC0A0000>6|2|1164115969
18:33:40.9412BC93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
18:33:40.9412BC110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
18:33:40.9422BC209Initialize::GetLocation@ 0X100B0|65712
18:33:40.9422BC209Initialize::GetLocation@ 0X12DE0|77280
18:33:40.9422BC209Initialize::GetLocation@ 0X12BB0|76720
18:33:40.9932BC225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_3412 opened succesfuly
18:33:40.9932BC72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
18:33:40.9932BC256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_3412 close 2147483647 bytes
18:33:40.9932BC297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.153.0.13\OWExplorer.dll]
18:33:41.12BC385ftw1OWExplorer injected
18:33:41.2172DD051`anonymous-namespace'::CreateProviderInitialize provider: NET
18:33:41.2172DD0117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
18:33:41.2172DD054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
18:33:41.2172DD051`anonymous-namespace'::CreateProviderInitialize provider: GPU
18:36:11.9971708394ProcessInjector::HandleElevatedProcessFail injection to process [2456] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
18:36:11.9971708333ProcessInjector::HandlePendingProccesssFail to inject pending process |2456|: NVDisplay.Container.exe
18:36:11.9971708394ProcessInjector::HandleElevatedProcessFail injection to process [4452] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
18:36:11.9971708333ProcessInjector::HandlePendingProccesssFail to inject pending process |4452|: nvcontainer.exe
18:36:11.9971708394ProcessInjector::HandleElevatedProcessFail injection to process [10936] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
18:36:11.9971708333ProcessInjector::HandlePendingProccesssFail to inject pending process |10936|: NVIDIA Share.exe
18:36:11.9971708394ProcessInjector::HandleElevatedProcessFail injection to process [11528] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
18:36:11.9971708333ProcessInjector::HandlePendingProccesssFail to inject pending process |11528|: NVIDIA Share.exe
18:36:11.9971708394ProcessInjector::HandleElevatedProcessFail injection to process [11892] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x1f
18:36:11.9971708333ProcessInjector::HandlePendingProccesssFail to inject pending process |11892|: CCXProcess.exe
18:36:11.9971708394ProcessInjector::HandleElevatedProcessFail injection to process [11964] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
18:36:11.9971708333ProcessInjector::HandlePendingProccesssFail to inject pending process |11964|: node.exe
20:14:01.1392BC66ProcessesMonitor::Stopstopping PM...
20:14:01.1392DD0119ProcessesMonitor::ProcessEnumerateThreadexit process listener