TimeThreadLineFunctionMessage
15:31:38.5522B30147ProcessHardwareRecorder::CommandThreadstarting recorder thread
15:31:38.5521094365ftw1Loading (pid: 1668)
15:31:38.553109448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X8E860000>6|2|1247871722
15:31:38.553109448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X91290000>6|2|1247871940
15:31:38.7051094172DXManager::DetectFound in 0
15:31:38.7061094209Initialize::GetLocation@ 0X59E0|23008
15:31:38.7061094209Initialize::GetLocation@ 0X6AE20|437792
15:31:38.7061094209Initialize::GetLocation@ 0X211E0|135648
15:31:38.7061094209Initialize::GetLocation@ 0X2840|10304
15:31:38.7061094111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8E860000 <> 0X91290000
15:31:38.7061094209Initialize::GetLocation@ 0XFD6F8860|-43022240
15:31:38.7061094111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8E860000 <> 0X91290000
15:31:38.7061094209Initialize::GetLocation@ 0XFD6FDC30|-43000784
15:31:38.7061094111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8E860000 <> 0X91290000
15:31:38.7061094209Initialize::GetLocation@ 0XFD6FC5F0|-43006480
15:31:38.7061094111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8E860000 <> 0X91290000
15:31:38.7061094209Initialize::GetLocation@ 0XFD5DA7F0|-44193808
15:31:38.741109448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X89100000>6|2|1247871904
15:31:39.171094129DXManager::DetectOK
15:31:39.1231094186DXManager::DetectDone
15:31:39.1231094215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
15:31:39.1241094209Initialize::GetLocation@ 0X41090|266384
15:31:39.1241094209Initialize::GetLocation@ 0X33320|209696
15:31:39.1241094209Initialize::GetLocation@ 0X3CBC0|248768
15:31:39.1241094209Initialize::GetLocation@ 0XB76A0|751264
15:31:39.1241094209Initialize::GetLocation@ 0XB71F0|750064
15:31:39.1241094209Initialize::GetLocation@ 0XA1F0|41456
15:31:39.1241094209Initialize::GetLocation@ 0XB7290|750224
15:31:39.1241094209Initialize::GetLocation@ 0X1ABB0|109488
15:31:39.1241094209Initialize::GetLocation@ 0X1D600|120320
15:31:39.1241094209Initialize::GetLocation@ 0X25C30|154672
15:31:39.1241094209Initialize::GetLocation@ 0X113920|1128736
15:31:39.1241094209Initialize::GetLocation@ 0X1133E0|1127392
15:31:39.1241094209Initialize::GetLocation@ 0X1AAA0|109216
15:31:39.1241094209Initialize::GetLocation@ 0X1A9B0|108976
15:31:39.1241094209Initialize::GetLocation@ 0XCB80|52096
15:31:39.1241094209Initialize::GetLocation@ 0X48030|294960
15:31:39.1241094209Initialize::GetLocation@ 0X9D60|40288
15:31:39.1241094209Initialize::GetLocation@ 0XCE890|845968
15:31:39.1241094209Initialize::GetLocation@ 0XCEF60|847712
15:31:39.1241094209Initialize::GetLocation@ 0X9D60|40288
15:31:39.1241094209Initialize::GetLocation@ 0XCFA50|850512
15:31:39.1241094209Initialize::GetLocation@ 0XD00B0|852144
15:31:39.150109448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X67C30000>6|2|1247870977
15:31:39.176109483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
15:31:39.1761094209Initialize::GetLocation@ 0X4040|16448
15:31:39.1761094209Initialize::GetLocation@ 0X6410|25616
15:31:39.1761094209Initialize::GetLocation@ 0X65C0|26048
15:31:39.179109448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X53F80000>6|2|1247870977
15:31:39.204109493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
15:31:39.2041094110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
15:31:39.2041094209Initialize::GetLocation@ 0XA5D0|42448
15:31:39.2041094209Initialize::GetLocation@ 0XD4D0|54480
15:31:39.2041094209Initialize::GetLocation@ 0XD290|53904
15:31:39.2561094225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_85_4_1668 opened succesfuly
15:31:39.256109472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
15:31:39.2561094256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_85_4_1668 close 2147483647 bytes
15:31:39.2561094301InjectOWExplorerExplorer file name [E:\Windows.old\Program Files (x86)\Overwolf\0.170.0.13\OWExplorer.dll]
15:31:39.3671094389ftw1OWExplorer injected
15:31:39.41249F071Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
15:31:39.67249EC51`anonymous-namespace'::CreateProviderInitialize provider: NET
15:31:39.67249EC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
15:31:39.67249EC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
15:31:39.67249EC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
15:31:39.73349F4669ProcessInjector::InjectProcessprocess |atkexComSvc.exe| missing h
15:31:39.73349F4669ProcessInjector::InjectProcessprocess |mDNSResponder.exe| missing h
15:31:39.73349F4669ProcessInjector::InjectProcessprocess |nssm.exe| missing h
15:31:39.73349F4669ProcessInjector::InjectProcessprocess |expressvpnd.exe| missing h
15:31:39.73349F4669ProcessInjector::InjectProcessprocess |Corsair.Service.CpuIdRemote64.exe| missing h
15:31:39.94949F4669ProcessInjector::InjectProcessprocess |Corsair.Service.DisplayAdapter.exe| missing h
15:31:39.97149F4669ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
15:31:39.97149F4669ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
15:32:16.39549F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [2412] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |2412|: NVIDIA Share.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [2528] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |2528|: NVDisplay.Container.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [4844] [t: 0 w_t_id: 0]- atkexComSvc.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |4844|: atkexComSvc.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [4852] [t: 0 w_t_id: 0]- mDNSResponder.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |4852|: mDNSResponder.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [4888] [t: 0 w_t_id: 0]- nssm.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |4888|: nssm.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [4920] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |4920|: nvcontainer.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [5272] [t: 0 w_t_id: 0]- expressvpnd.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |5272|: expressvpnd.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [6348] [t: 0 w_t_id: 0]- Corsair.Service.CpuIdRemote64.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |6348|: Corsair.Service.CpuIdRemote64.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [8912] [t: 0 w_t_id: 0]- Corsair.Service.DisplayAdapter.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |8912|: Corsair.Service.DisplayAdapter.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [12312] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |12312|: QtWebEngineProcess.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [13164] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |13164|: GoogleCrashHandler.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [13268] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |13268|: GoogleCrashHandler64.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [13572] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |13572|: QtWebEngineProcess.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [13992] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |13992|: NVIDIA Share.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [14376] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |14376|: QtWebEngineProcess.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [14388] [t: 0 w_t_id: 0]- com.barraider.twitchtools.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |14388|: com.barraider.twitchtools.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [14420] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |14420|: QtWebEngineProcess.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [14468] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |14468|: QtWebEngineProcess.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [14980] [t: 0 w_t_id: 0]- voicemodplugin.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |14980|: voicemodplugin.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [15268] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |15268|: QtWebEngineProcess.exe
15:34:10.41149F4386ProcessInjector::HandleElevatedProcessFail injection to process [17644] [t: 0 w_t_id: 0]- curseforge.exe (elevated True) 0x0
15:34:10.41149F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |17644|: curseforge.exe
15:34:16.41249F4386ProcessInjector::HandleElevatedProcessFail injection to process [19836] [t: 0 w_t_id: 0]- curseforge.exe (elevated True) 0x0
15:34:16.41349F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |19836|: curseforge.exe
15:36:28.51349F4669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:25:21.60649F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
16:25:21.60649F4669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [1652] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |1652|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [2216] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |2216|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [7112] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |7112|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [8632] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |8632|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [9220] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |9220|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [9224] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |9224|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [9308] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |9308|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [10612] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |10612|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [12468] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |12468|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [12584] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |12584|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [13008] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |13008|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [15136] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |15136|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [15680] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |15680|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [17532] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |17532|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [20424] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |20424|: opera.exe
17:22:50.57549F4386ProcessInjector::HandleElevatedProcessFail injection to process [20616] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:50.57549F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |20616|: opera.exe
17:22:51.57449F4386ProcessInjector::HandleElevatedProcessFail injection to process [2108] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:51.57449F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |2108|: opera.exe
17:22:56.57749F4386ProcessInjector::HandleElevatedProcessFail injection to process [21436] [t: 0 w_t_id: 0]- opera.exe (elevated True) 0x0
17:22:56.57749F4318ProcessInjector::HandlePendingProccesssFail to inject pending process |21436|: opera.exe
17:25:21.60049F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
17:25:21.60049F4669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
17:45:24.86149F4669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
19:25:21.65349F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
19:25:21.65349F4669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
19:36:28.87049F4669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
19:51:33.16549F4669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:51:36.16649F4669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
20:25:21.68849F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
20:25:21.68849F4669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
22:25:21.57749F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
22:25:21.57749F4669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
23:08:54.26249F4669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
23:36:28.68849F4669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
00:25:21.54749F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
00:25:21.54749F4669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
00:51:32.94949F4669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
00:52:02.95649F4669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
01:45:23.83649F4669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
02:25:21.50749F4669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
02:42:38.41049F076Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
02:42:38.447109466ProcessesMonitor::Stopstopping PM...
02:42:38.44749EC119ProcessesMonitor::ProcessEnumerateThreadexit process listener
02:42:38.4471094527ProcessInjector::Unhookunhook running process