TimeThreadLineFunctionMessage
15:29:41.2014FFC365ftw1Loading (pid: 892)
15:29:41.2034FFC48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X38370000>6|2|1203373348
15:29:41.2034FFC48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X3A140000>6|2|1203373348
15:29:41.2064F54147ProcessHardwareRecorder::CommandThreadstarting recorder thread
15:29:41.3984FFC172DXManager::DetectFound in 0
15:29:41.3994FFC209Initialize::GetLocation@ 0X4660|18016
15:29:41.3994FFC209Initialize::GetLocation@ 0X662B0|418480
15:29:41.3994FFC209Initialize::GetLocation@ 0X19DB0|105904
15:29:41.3994FFC209Initialize::GetLocation@ 0X1350|4944
15:29:41.3994FFC111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000
15:29:41.3994FFC209Initialize::GetLocation@ 0XFE353020|-30068704
15:29:41.3994FFC111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000
15:29:41.3994FFC209Initialize::GetLocation@ 0XFE358060|-30048160
15:29:41.3994FFC111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000
15:29:41.3994FFC209Initialize::GetLocation@ 0XFE34E620|-30087648
15:29:41.3994FFC111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X38370000 <> 0X3A140000
15:29:41.3994FFC209Initialize::GetLocation@ 0XFE23AA80|-31217024
15:29:41.4344FFC48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X31480000>6|2|1203373142
15:29:41.6344FFC129DXManager::DetectOK
15:29:41.7334FFC186DXManager::DetectDone
15:29:41.7334FFC215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
15:29:41.7354FFC209Initialize::GetLocation@ 0X3AC00|240640
15:29:41.7354FFC209Initialize::GetLocation@ 0X2C5B0|181680
15:29:41.7354FFC209Initialize::GetLocation@ 0X36D00|224512
15:29:41.7354FFC209Initialize::GetLocation@ 0XAE210|713232
15:29:41.7354FFC209Initialize::GetLocation@ 0XADD60|712032
15:29:41.7354FFC209Initialize::GetLocation@ 0X5880|22656
15:29:41.7354FFC209Initialize::GetLocation@ 0XADE00|712192
15:29:41.7354FFC209Initialize::GetLocation@ 0X20FF0|135152
15:29:41.7354FFC209Initialize::GetLocation@ 0X1CA60|117344
15:29:41.7354FFC209Initialize::GetLocation@ 0X1C8E0|116960
15:29:41.7354FFC209Initialize::GetLocation@ 0X1086D0|1083088
15:29:41.7354FFC209Initialize::GetLocation@ 0X108180|1081728
15:29:41.7354FFC209Initialize::GetLocation@ 0X248B0|149680
15:29:41.7354FFC209Initialize::GetLocation@ 0X247A0|149408
15:29:41.7354FFC209Initialize::GetLocation@ 0X2C440|181312
15:29:41.7354FFC209Initialize::GetLocation@ 0X3F3F0|259056
15:29:41.7354FFC209Initialize::GetLocation@ 0XF3E0|62432
15:29:41.7354FFC209Initialize::GetLocation@ 0XF4E0|62688
15:29:41.7354FFC209Initialize::GetLocation@ 0XF5D0|62928
15:29:41.7354FFC209Initialize::GetLocation@ 0XF3E0|62432
15:29:41.7354FFC209Initialize::GetLocation@ 0XF280|62080
15:29:41.7354FFC209Initialize::GetLocation@ 0XF430|62512
15:29:41.8154FFC48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X2FA60000>6|2|1203372033
15:29:41.9584FFC83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
15:29:41.9594FFC209Initialize::GetLocation@ 0X3CC0|15552
15:29:41.9594FFC209Initialize::GetLocation@ 0X5FD0|24528
15:29:41.9594FFC209Initialize::GetLocation@ 0X6180|24960
15:29:41.9604FFC48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XDBB90000>6|2|1203372033
15:29:42.1034FFC93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
15:29:42.1044FFC110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
15:29:42.1044FFC209Initialize::GetLocation@ 0X10000|65536
15:29:42.1044FFC209Initialize::GetLocation@ 0X12C80|76928
15:29:42.1044FFC209Initialize::GetLocation@ 0X12A60|76384
15:29:42.1574FFC225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_892 opened succesfuly
15:29:42.1574FFC72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
15:29:42.1584FFC256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_892 close 2147483647 bytes
15:29:42.1584FFC301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.165.0.25\OWExplorer.dll]
15:29:42.2494FFC389ftw1OWExplorer injected
15:29:42.250464870Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
15:29:42.8453B8C51`anonymous-namespace'::CreateProviderInitialize provider: NET
15:29:42.8453B8C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
15:29:42.8453B8C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
15:29:42.8453B8C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
15:29:42.89752D4726ProcessInjector::InjectProcessprocess |vpnagent.exe| missing h
15:29:42.89752D4726ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
15:29:42.89752D4726ProcessInjector::InjectProcessprocess |vmware-authd.exe| missing h
15:29:42.89752D4726ProcessInjector::InjectProcessprocess |WifiSvc.exe| missing h
15:29:42.89752D4726ProcessInjector::InjectProcessprocess |sqlceip.exe| missing h
15:29:42.89752D4726ProcessInjector::InjectProcessprocess |sqlservr.exe| missing h
15:29:42.89852D4726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
15:29:42.89852D4726ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
15:29:42.89852D4726ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
15:29:42.89852D4726ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [512] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |512|: QtWebEngineProcess.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [2012] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |2012|: NVDisplay.Container.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [3060] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |3060|: vpnagent.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [3728] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |3728|: Microsoft.ServiceHub.Controller.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [4168] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |4168|: gameinputsvc.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [4392] [t: 0 w_t_id: 0]- vmware-authd.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |4392|: vmware-authd.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [4572] [t: 0 w_t_id: 0]- WifiSvc.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |4572|: WifiSvc.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [4580] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |4580|: MsMpEng.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [4912] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |4912|: obs-browser-page.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [6088] [t: 0 w_t_id: 0]- sqlceip.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |6088|: sqlceip.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [6096] [t: 0 w_t_id: 0]- sqlservr.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |6096|: sqlservr.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [7556] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |7556|: DropboxUpdate.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [8004] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |8004|: QtWebEngineProcess.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [8468] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |8468|: Teams.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [9136] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |9136|: GoogleCrashHandler.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [9664] [t: 0 w_t_id: 0]- voicemodplugin.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |9664|: voicemodplugin.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [9744] [t: 0 w_t_id: 0]- sdaudioswitch.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |9744|: sdaudioswitch.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [9748] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |9748|: GoogleCrashHandler64.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [10616] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |10616|: node.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [10628] [t: 0 w_t_id: 0]- ServiceHub.RoslynCodeAnalysisService.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |10628|: ServiceHub.RoslynCodeAnalysisService.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [12692] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |12692|: Teams.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [13264] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |13264|: obs-browser-page.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [14200] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |14200|: Teams.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [14768] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |14768|: Teams.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [18760] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |18760|: obs-browser-page.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [18776] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |18776|: obs-browser-page.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [19584] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |19584|: QtWebEngineProcess.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [19780] [t: 0 w_t_id: 0]- ServiceHub.TestWindowStoreHost.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |19780|: ServiceHub.TestWindowStoreHost.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [20936] [t: 0 w_t_id: 0]- ServiceHub.RoslynCodeAnalysisService.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |20936|: ServiceHub.RoslynCodeAnalysisService.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [21564] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |21564|: Microsoft.ServiceHub.Controller.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [23520] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |23520|: Teams.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [23912] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |23912|: obs-browser-page.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [24228] [t: 0 w_t_id: 0]- twitchstudiostreamdeck.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |24228|: twitchstudiostreamdeck.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [24372] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |24372|: gameinputsvc.exe
15:32:13.32352D4481ProcessInjector::HandleElevatedProcessFail injection to process [27592] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
15:32:13.32352D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |27592|: obs-browser-page.exe
15:32:44.33652D4481ProcessInjector::HandleElevatedProcessFail injection to process [26608] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
15:32:44.33652D4413ProcessInjector::HandlePendingProccesssFail to inject pending process |26608|: Teams.exe
15:32:55.992464875Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
15:32:57.1934FFC66ProcessesMonitor::Stopstopping PM...
15:32:57.1933B8C119ProcessesMonitor::ProcessEnumerateThreadexit process listener
15:32:57.1934FFC619ProcessInjector::Unhookunhook running process
15:33:03.2004FFC66ProcessesMonitor::Stopstopping PM...