TimeThreadLineFunctionMessage
16:45:00.5725020365ftw1Loading (pid: 16332)
16:45:00.573502048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X8DB10000>6|2|1247871722
16:45:00.573502048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X90310000>6|2|1247871940
16:45:00.5754C50147ProcessHardwareRecorder::CommandThreadstarting recorder thread
16:45:00.7065020173DXManager::DetectFound in 0
16:45:00.7075020209Initialize::GetLocation@ 0X59E0|23008
16:45:00.7075020209Initialize::GetLocation@ 0X6AE20|437792
16:45:00.7075020209Initialize::GetLocation@ 0X211E0|135648
16:45:00.7075020209Initialize::GetLocation@ 0X2840|10304
16:45:00.7075020111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8DB10000 <> 0X90310000
16:45:00.7075020209Initialize::GetLocation@ 0XFD928860|-40728480
16:45:00.7075020111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8DB10000 <> 0X90310000
16:45:00.7075020209Initialize::GetLocation@ 0XFD92DC30|-40707024
16:45:00.7075020111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8DB10000 <> 0X90310000
16:45:00.7075020209Initialize::GetLocation@ 0XFD92C5F0|-40712720
16:45:00.7075020111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8DB10000 <> 0X90310000
16:45:00.7075020209Initialize::GetLocation@ 0XFD80A7F0|-41900048
16:45:00.722502048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X82770000>6|2|1247871904
16:45:01.3765020129DXManager::DetectOK
16:45:01.4325020186DXManager::DetectDone
16:45:01.4325020215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
16:45:01.4325020209Initialize::GetLocation@ 0X41090|266384
16:45:01.4325020209Initialize::GetLocation@ 0X33320|209696
16:45:01.4325020209Initialize::GetLocation@ 0X3CBC0|248768
16:45:01.4325020209Initialize::GetLocation@ 0XB76A0|751264
16:45:01.4325020209Initialize::GetLocation@ 0XB71F0|750064
16:45:01.4325020209Initialize::GetLocation@ 0XA1F0|41456
16:45:01.4325020209Initialize::GetLocation@ 0XB7290|750224
16:45:01.4325020209Initialize::GetLocation@ 0X1ABB0|109488
16:45:01.4325020209Initialize::GetLocation@ 0X1D600|120320
16:45:01.4325020209Initialize::GetLocation@ 0X25C30|154672
16:45:01.4325020209Initialize::GetLocation@ 0X113920|1128736
16:45:01.4325020209Initialize::GetLocation@ 0X1133E0|1127392
16:45:01.4325020209Initialize::GetLocation@ 0X1AAA0|109216
16:45:01.4325020209Initialize::GetLocation@ 0X1A9B0|108976
16:45:01.4325020209Initialize::GetLocation@ 0XCB80|52096
16:45:01.4325020209Initialize::GetLocation@ 0X48030|294960
16:45:01.4325020209Initialize::GetLocation@ 0X9D60|40288
16:45:01.4325020209Initialize::GetLocation@ 0XCE890|845968
16:45:01.4325020209Initialize::GetLocation@ 0XCEF60|847712
16:45:01.4325020209Initialize::GetLocation@ 0X9D60|40288
16:45:01.4325020209Initialize::GetLocation@ 0XCFA50|850512
16:45:01.4325020209Initialize::GetLocation@ 0XD00B0|852144
16:45:01.454502048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X6B7B0000>6|2|1247870977
16:45:01.468502083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
16:45:01.4685020209Initialize::GetLocation@ 0X4040|16448
16:45:01.4685020209Initialize::GetLocation@ 0X6410|25616
16:45:01.4685020209Initialize::GetLocation@ 0X65C0|26048
16:45:01.470502048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X6B8A0000>6|2|1247870977
16:45:01.480502093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
16:45:01.4805020110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
16:45:01.4805020209Initialize::GetLocation@ 0XA5D0|42448
16:45:01.4805020209Initialize::GetLocation@ 0XD4D0|54480
16:45:01.4805020209Initialize::GetLocation@ 0XD290|53904
16:45:01.5475020225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_173_4_16332 opened succesfuly
16:45:01.547502072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
16:45:01.5475020255InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_173_4_16332 close 2147483647 bytes
16:45:01.5475020301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.173.0.16\OWExplorer.dll]
16:45:01.5865020389ftw1OWExplorer injected
16:45:01.586517871Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
16:45:01.799B2851`anonymous-namespace'::CreateProviderInitialize provider: NET
16:45:01.799B28117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
16:45:01.799B2854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
16:45:01.799B2851`anonymous-namespace'::CreateProviderInitialize provider: GPU
16:45:01.8112E30669ProcessInjector::InjectProcessprocess |remoting_host.exe| missing h
16:45:01.8112E30669ProcessInjector::InjectProcessprocess |VpnSvc.exe| missing h
16:45:01.9322E30669ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
16:45:01.9322E30669ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
16:45:02.92E30669ProcessInjector::InjectProcessprocess |LMS.exe| missing h
16:47:31.8192E30386ProcessInjector::HandleElevatedProcessFail injection to process [2248] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
16:47:31.8192E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |2248|: NVDisplay.Container.exe
16:47:31.8192E30386ProcessInjector::HandleElevatedProcessFail injection to process [2812] [t: 0 w_t_id: 0]- VpnSvc.exe (elevated True) 0x0
16:47:31.8192E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |2812|: VpnSvc.exe
16:47:31.8192E30386ProcessInjector::HandleElevatedProcessFail injection to process [4032] [t: 0 w_t_id: 0]- remoting_host.exe (elevated True) 0x0
16:47:31.8192E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |4032|: remoting_host.exe
16:47:31.8192E30386ProcessInjector::HandleElevatedProcessFail injection to process [4184] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
16:47:31.8192E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |4184|: nvcontainer.exe
16:47:32.8272E30386ProcessInjector::HandleElevatedProcessFail injection to process [8696] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0
16:47:32.8272E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |8696|: LMS.exe
16:47:32.8272E30386ProcessInjector::HandleElevatedProcessFail injection to process [9116] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
16:47:32.8272E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |9116|: GoogleCrashHandler.exe
16:47:32.8272E30386ProcessInjector::HandleElevatedProcessFail injection to process [9144] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
16:47:32.8272E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |9144|: GoogleCrashHandler64.exe
16:49:52.422E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:08:06.9492E30669ProcessInjector::InjectProcessprocess |AvBugReport.exe| missing h
20:44:37.3332E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
20:49:51.9182E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:29:55.3212E30669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
21:30:15.4902E30669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
22:10:06.5712E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
00:44:37.8332E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
00:49:51.6522E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
03:10:06.5942E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
03:10:50.9442E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
04:44:37.2752E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
04:49:51.9532E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
06:10:06.4782E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
07:10:05.6332E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
07:29:55.6112E30669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
07:30:40.9852E30669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
08:10:05.6912E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
08:44:37.992E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
08:49:51.6472E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:16:31.1352E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:44:37.8132E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:49:51.3572E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:49:52.3592E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:01:12.5522E30386ProcessInjector::HandleElevatedProcessFail injection to process [7588] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
13:01:12.5522E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |7588|: firefox.exe
13:01:12.5522E30386ProcessInjector::HandleElevatedProcessFail injection to process [18148] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
13:01:12.5522E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |18148|: firefox.exe
13:01:13.5662E30386ProcessInjector::HandleElevatedProcessFail injection to process [20308] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
13:01:13.5662E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |20308|: firefox.exe
13:01:20.6312E30386ProcessInjector::HandleElevatedProcessFail injection to process [17992] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
13:01:20.6312E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |17992|: firefox.exe
13:10:05.7152E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:33:56.4352E30669ProcessInjector::InjectProcessprocess |OverwolfLauncher.exe| missing h
14:14:12.792E30669ProcessInjector::InjectProcessprocess |VpnUpdate.exe| missing h
14:25:54.6192E30386ProcessInjector::HandleElevatedProcessFail injection to process [13372] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:25:54.6192E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |13372|: firefox.exe
14:25:54.6192E30386ProcessInjector::HandleElevatedProcessFail injection to process [16504] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:25:54.6192E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |16504|: firefox.exe
14:25:55.6252E30386ProcessInjector::HandleElevatedProcessFail injection to process [17244] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:25:55.6252E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |17244|: firefox.exe
14:26:00.6612E30386ProcessInjector::HandleElevatedProcessFail injection to process [14208] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:00.6612E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |14208|: firefox.exe
14:26:01.6662E30386ProcessInjector::HandleElevatedProcessFail injection to process [2284] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:01.6662E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |2284|: firefox.exe
14:26:03.6892E30386ProcessInjector::HandleElevatedProcessFail injection to process [16492] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:03.6892E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |16492|: firefox.exe
14:26:05.7012E30386ProcessInjector::HandleElevatedProcessFail injection to process [2396] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:05.7012E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |2396|: firefox.exe
14:26:05.7012E30386ProcessInjector::HandleElevatedProcessFail injection to process [16484] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:05.7012E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |16484|: firefox.exe
14:26:39.9302E30386ProcessInjector::HandleElevatedProcessFail injection to process [13208] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:39.9302E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |13208|: firefox.exe
14:26:40.9372E30386ProcessInjector::HandleElevatedProcessFail injection to process [20148] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:26:40.9372E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |20148|: firefox.exe
14:28:37.9002E30386ProcessInjector::HandleElevatedProcessFail injection to process [13248] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:28:37.9002E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |13248|: firefox.exe
14:29:37.3742E30386ProcessInjector::HandleElevatedProcessFail injection to process [19260] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
14:29:37.3742E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |19260|: firefox.exe
14:58:43.9922E30669ProcessInjector::InjectProcessprocess |DXSETUP.exe| missing h
15:07:20.4902E30386ProcessInjector::HandleElevatedProcessFail injection to process [10652] [t: 0 w_t_id: 0]- War.exe (elevated True) 0x0
15:07:20.4902E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |10652|: War.exe
15:07:21.4962E30386ProcessInjector::HandleElevatedProcessFail injection to process [12100] [t: 0 w_t_id: 0]- CrashReportClient.exe (elevated True) 0x0
15:07:21.4962E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |12100|: CrashReportClient.exe
15:07:40.6522E30386ProcessInjector::HandleElevatedProcessFail injection to process [13788] [t: 0 w_t_id: 0]- UnrealCEFSubProcess.exe (elevated True) 0x0
15:07:40.6522E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |13788|: UnrealCEFSubProcess.exe
15:09:14.4092E30386ProcessInjector::HandleElevatedProcessFail injection to process [15480] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x578
15:09:14.4092E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |15480|: owobs-ffmpeg-mux.exe
15:19:27.2932E30386ProcessInjector::HandleElevatedProcessFail injection to process [4872] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:19:27.2932E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |4872|: owobs-ffmpeg-mux.exe
15:38:38.1392E30669ProcessInjector::InjectProcessprocess |aion.bin| missing h
15:39:34.5092E30669ProcessInjector::InjectProcessprocess |aion.bin| missing h
15:44:17.492E30386ProcessInjector::HandleElevatedProcessFail injection to process [13656] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:44:17.502E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |13656|: owobs-ffmpeg-mux.exe
15:55:38.5042E30669ProcessInjector::InjectProcessprocess |aion.bin| missing h
15:56:26.8992E30669ProcessInjector::InjectProcessprocess |eu4.exe| missing h
15:58:11.5232E30386ProcessInjector::HandleElevatedProcessFail injection to process [16192] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
15:58:11.5232E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |16192|: software_reporter_tool.exe
15:58:12.5252E30386ProcessInjector::HandleElevatedProcessFail injection to process [8420] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
15:58:12.5252E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |8420|: software_reporter_tool.exe
15:58:12.5252E30386ProcessInjector::HandleElevatedProcessFail injection to process [17612] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
15:58:12.5252E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |17612|: software_reporter_tool.exe
15:58:57.7512E30386ProcessInjector::HandleElevatedProcessFail injection to process [11660] [t: 0 w_t_id: 0]- eu4.exe (elevated True) 0x578
15:58:57.7512E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |11660|: eu4.exe
16:14:33.532E30669ProcessInjector::InjectProcessprocess |eu4.exe| missing h
16:44:37.3172E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:49:51.4472E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:49:52.4562E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:08:07.392E30669ProcessInjector::InjectProcessprocess |AvBugReport.exe| missing h
17:09:12.6052E30669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:11:30.7552E30669ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
17:13:14.9272E30669ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
17:15:45.6952E30386ProcessInjector::HandleElevatedProcessFail injection to process [4404] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
17:15:45.6952E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |4404|: EasyAntiCheat.exe
17:29:54.7612E30669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
17:30:39.722E30669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
18:10:06.482E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
18:10:22.1192E30669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
18:29:18.1852E30669ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
18:31:48.9552E30386ProcessInjector::HandleElevatedProcessFail injection to process [1380] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
18:31:48.9552E30318ProcessInjector::HandlePendingProccesssFail to inject pending process |1380|: EasyAntiCheat.exe