TimeThreadLineFunctionMessage
08:50:07.2963D18365ftw1Loading (pid: 9764)
08:50:07.29645AC147ProcessHardwareRecorder::CommandThreadstarting recorder thread
08:50:07.2973D1848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X8A590000>6|2|1247871722
08:50:07.2973D1848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X8C630000>6|2|1247871722
08:50:07.4373D18172DXManager::DetectFound in 0
08:50:07.4373D18209Initialize::GetLocation@ 0X4F80|20352
08:50:07.4373D18209Initialize::GetLocation@ 0X69700|431872
08:50:07.4373D18209Initialize::GetLocation@ 0X206F0|132848
08:50:07.4373D18209Initialize::GetLocation@ 0X1DE0|7648
08:50:07.4373D18111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8A590000 <> 0X8C630000
08:50:07.4373D18209Initialize::GetLocation@ 0XFE088860|-32995232
08:50:07.4373D18111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8A590000 <> 0X8C630000
08:50:07.4373D18209Initialize::GetLocation@ 0XFE08DC30|-32973776
08:50:07.4373D18111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8A590000 <> 0X8C630000
08:50:07.4373D18209Initialize::GetLocation@ 0XFE08C5F0|-32979472
08:50:07.4373D18111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8A590000 <> 0X8C630000
08:50:07.4373D18209Initialize::GetLocation@ 0XFDF6A7F0|-34166800
08:50:07.4523D1848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X81900000>6|2|1247871638
08:50:07.5553D18129DXManager::DetectOK
08:50:07.6023D18186DXManager::DetectDone
08:50:07.6023D18215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
08:50:07.6023D18209Initialize::GetLocation@ 0X41B90|269200
08:50:07.6023D18209Initialize::GetLocation@ 0X33E20|212512
08:50:07.6023D18209Initialize::GetLocation@ 0X3D6C0|251584
08:50:07.6023D18209Initialize::GetLocation@ 0XB8E10|757264
08:50:07.6023D18209Initialize::GetLocation@ 0XB8960|756064
08:50:07.6023D18209Initialize::GetLocation@ 0XACF0|44272
08:50:07.6023D18209Initialize::GetLocation@ 0XB8A00|756224
08:50:07.6023D18209Initialize::GetLocation@ 0X1B6B0|112304
08:50:07.6023D18209Initialize::GetLocation@ 0X1E100|123136
08:50:07.6023D18209Initialize::GetLocation@ 0X26730|157488
08:50:07.6023D18209Initialize::GetLocation@ 0X1146B0|1132208
08:50:07.6023D18209Initialize::GetLocation@ 0X114170|1130864
08:50:07.6023D18209Initialize::GetLocation@ 0X1B5A0|112032
08:50:07.6023D18209Initialize::GetLocation@ 0X1B4B0|111792
08:50:07.6023D18209Initialize::GetLocation@ 0XD680|54912
08:50:07.6023D18209Initialize::GetLocation@ 0X493C0|299968
08:50:07.6023D18209Initialize::GetLocation@ 0XA860|43104
08:50:07.6023D18209Initialize::GetLocation@ 0XD0000|851968
08:50:07.6023D18209Initialize::GetLocation@ 0XD06D0|853712
08:50:07.6023D18209Initialize::GetLocation@ 0XA860|43104
08:50:07.6023D18209Initialize::GetLocation@ 0XD11C0|856512
08:50:07.6023D18209Initialize::GetLocation@ 0XD1820|858144
08:50:07.6163D1848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X165C0000>6|2|1247870977
08:50:07.6383D1883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
08:50:07.6383D18209Initialize::GetLocation@ 0X4040|16448
08:50:07.6383D18209Initialize::GetLocation@ 0X6410|25616
08:50:07.6383D18209Initialize::GetLocation@ 0X65C0|26048
08:50:07.6463D1848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X16570000>6|2|1247870977
08:50:07.6573D1893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
08:50:07.6573D18110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
08:50:07.6573D18209Initialize::GetLocation@ 0XA5D0|42448
08:50:07.6573D18209Initialize::GetLocation@ 0XD4D0|54480
08:50:07.6573D18209Initialize::GetLocation@ 0XD290|53904
08:50:07.7183D18225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_9764 opened succesfuly
08:50:07.7183D1872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
08:50:07.7183D18256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_9764 close 2147483647 bytes
08:50:07.7183D18301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.165.0.28\OWExplorer.dll]
08:50:07.7533D18389ftw1OWExplorer injected
08:50:07.753492470Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
08:50:08.45411451`anonymous-namespace'::CreateProviderInitialize provider: NET
08:50:08.454114117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
08:50:08.45411454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
08:50:08.45411451`anonymous-namespace'::CreateProviderInitialize provider: GPU
08:50:08.533D0726ProcessInjector::InjectProcessprocess |CTAudSvc.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |EvtEng.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |RzSDKServer.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |GCloud.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |IAStorDataMgrSvc.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |LMS.exe| missing h
08:50:08.543D0726ProcessInjector::InjectProcessprocess |XSpltVidSvc.exe| missing h
08:50:08.1123D0726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
08:50:08.2343D0726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
08:50:28.9333D0726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
08:52:38.8303D0481ProcessInjector::HandleElevatedProcessFail injection to process [2444] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |2444|: NVDisplay.Container.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [3528] [t: 0 w_t_id: 0]- CTAudSvc.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |3528|: CTAudSvc.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [4568] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |4568|: nvcontainer.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [4580] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |4580|: MsMpEng.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [4608] [t: 0 w_t_id: 0]- EvtEng.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |4608|: EvtEng.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [4616] [t: 0 w_t_id: 0]- RzSDKServer.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |4616|: RzSDKServer.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [5336] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |5336|: NVIDIA Share.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [7744] [t: 0 w_t_id: 0]- Zygor.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |7744|: Zygor.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [8568] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |8568|: DropboxUpdate.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [10976] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |10976|: MicrosoftEdgeUpdate.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [16112] [t: 0 w_t_id: 0]- Zygor.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |16112|: Zygor.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [17392] [t: 0 w_t_id: 0]- IAStorDataMgrSvc.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |17392|: IAStorDataMgrSvc.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [17844] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |17844|: LMS.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [18532] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |18532|: NVIDIA Share.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [21036] [t: 0 w_t_id: 0]- XSpltVidSvc.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |21036|: XSpltVidSvc.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [21376] [t: 0 w_t_id: 0]- GCloud.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |21376|: GCloud.exe
08:52:38.8313D0481ProcessInjector::HandleElevatedProcessFail injection to process [25516] [t: 0 w_t_id: 0]- Zygor.exe (elevated True) 0x0
08:52:38.8313D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |25516|: Zygor.exe
08:54:34.6763D0481ProcessInjector::HandleElevatedProcessFail injection to process [11204] [t: 0 w_t_id: 0]- curseforge.exe (elevated True) 0x0
08:54:34.6763D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |11204|: curseforge.exe
08:55:01.8383D0726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
08:55:23.9883D0726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
08:56:46.5853D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
08:58:02.1743D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
08:59:27.7713D0726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
08:59:29.7833D0481ProcessInjector::HandleElevatedProcessFail injection to process [17056] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:29.7833D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |17056|: firefox.exe
08:59:29.7833D0481ProcessInjector::HandleElevatedProcessFail injection to process [25752] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:29.7833D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |25752|: firefox.exe
08:59:30.8003D0481ProcessInjector::HandleElevatedProcessFail injection to process [5016] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:30.8003D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |5016|: firefox.exe
08:59:30.8003D0481ProcessInjector::HandleElevatedProcessFail injection to process [5380] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:30.8003D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |5380|: firefox.exe
08:59:30.8003D0481ProcessInjector::HandleElevatedProcessFail injection to process [22616] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:30.8003D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |22616|: firefox.exe
08:59:31.8053D0481ProcessInjector::HandleElevatedProcessFail injection to process [9364] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:31.8053D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |9364|: firefox.exe
08:59:31.8053D0481ProcessInjector::HandleElevatedProcessFail injection to process [23448] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:31.8053D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |23448|: firefox.exe
08:59:33.8133D0481ProcessInjector::HandleElevatedProcessFail injection to process [13180] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
08:59:33.8133D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |13180|: firefox.exe
09:15:20.3293D0481ProcessInjector::HandleElevatedProcessFail injection to process [13032] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
09:15:20.3293D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |13032|: firefox.exe
09:27:26.4943D0481ProcessInjector::HandleElevatedProcessFail injection to process [17824] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
09:27:26.4943D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |17824|: firefox.exe
09:32:35.6473D0481ProcessInjector::HandleElevatedProcessFail injection to process [8672] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
09:32:35.6473D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |8672|: firefox.exe
09:45:22.2043D0481ProcessInjector::HandleElevatedProcessFail injection to process [24244] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
09:45:22.2043D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |24244|: firefox.exe
09:54:58.1183D0481ProcessInjector::HandleElevatedProcessFail injection to process [5912] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
09:54:58.1183D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |5912|: firefox.exe
09:55:35.3783D0726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
09:55:35.3783D0726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
09:58:02.4273D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:45:31.6543D0726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:56:46.6393D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:58:02.1773D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:58:17.2793D0726ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
11:00:47.3923D0481ProcessInjector::HandleElevatedProcessFail injection to process [3336] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
11:00:47.3923D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |3336|: EasyAntiCheat.exe
11:43:37.6213D0481ProcessInjector::HandleElevatedProcessFail injection to process [23308] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5
11:43:37.6213D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |23308|: owobs-ffmpeg-mux.exe
11:58:02.3313D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
12:03:49.9613D0481ProcessInjector::HandleElevatedProcessFail injection to process [13572] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5
12:03:49.9613D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |13572|: owobs-ffmpeg-mux.exe
12:21:05.7743D0726ProcessInjector::InjectProcessprocess |VSIXAutoUpdate.exe| missing h
12:21:08.8013D0726ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
12:33:37.6783D0481ProcessInjector::HandleElevatedProcessFail injection to process [7044] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x5
12:33:37.6783D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |7044|: owobs-ffmpeg-mux.exe
12:48:37.4593D0726ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
12:51:07.5643D0481ProcessInjector::HandleElevatedProcessFail injection to process [11460] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
12:51:07.5643D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |11460|: EasyAntiCheat.exe
12:52:33.1923D0726ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
12:55:01.3233D0726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:55:02.3333D0726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:55:03.3333D0481ProcessInjector::HandleElevatedProcessFail injection to process [18216] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x1f
12:55:03.3333D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |18216|: EasyAntiCheat.exe
12:55:24.5123D0726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:58:02.6983D0726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
13:01:13.2273D0726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:02:57.9923D0481ProcessInjector::HandleElevatedProcessFail injection to process [21176] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x1f
13:02:57.9933D0413ProcessInjector::HandlePendingProccesssFail to inject pending process |21176|: owobs-ffmpeg-mux.exe