TimeThreadLineFunctionMessage
18:49:34.9914E9C361ftw1Loading (pid: 3920)
18:49:34.9915338146ProcessHardwareRecorder::CommandThreadstarting recorder thread
18:49:34.9934E9C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XDB570000>6|2|1247870977
18:49:34.9934E9C48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XE1700000>6|2|1247870977
18:49:35.404E9C172DXManager::DetectFound in 0
18:49:35.404E9C209Initialize::GetLocation@ 0X4F80|20352
18:49:35.404E9C209Initialize::GetLocation@ 0X69160|430432
18:49:35.404E9C209Initialize::GetLocation@ 0X20410|132112
18:49:35.404E9C209Initialize::GetLocation@ 0X1DE0|7648
18:49:35.404E9C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDB570000 <> 0XE1700000
18:49:35.404E9C209Initialize::GetLocation@ 0XF9F98850|-101087152
18:49:35.404E9C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDB570000 <> 0XE1700000
18:49:35.404E9C209Initialize::GetLocation@ 0XF9F9DE80|-101065088
18:49:35.404E9C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDB570000 <> 0XE1700000
18:49:35.404E9C209Initialize::GetLocation@ 0XF9F9C5E0|-101071392
18:49:35.404E9C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XDB570000 <> 0XE1700000
18:49:35.404E9C209Initialize::GetLocation@ 0XF9E7A7F0|-102258704
18:49:35.464E9C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0XD76D0000>6|2|1247870977
18:49:35.744E9C129DXManager::DetectOK
18:49:35.894E9C186DXManager::DetectDone
18:49:35.904E9C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
18:49:35.904E9C209Initialize::GetLocation@ 0X3FC10|261136
18:49:35.904E9C209Initialize::GetLocation@ 0X33840|211008
18:49:35.904E9C209Initialize::GetLocation@ 0X3BFA0|245664
18:49:35.904E9C209Initialize::GetLocation@ 0XB70E0|749792
18:49:35.904E9C209Initialize::GetLocation@ 0XB6C30|748592
18:49:35.904E9C209Initialize::GetLocation@ 0XAF40|44864
18:49:35.904E9C209Initialize::GetLocation@ 0XB6CD0|748752
18:49:35.904E9C209Initialize::GetLocation@ 0X20C40|134208
18:49:35.904E9C209Initialize::GetLocation@ 0X16A10|92688
18:49:35.904E9C209Initialize::GetLocation@ 0X2D530|185648
18:49:35.904E9C209Initialize::GetLocation@ 0X113350|1127248
18:49:35.904E9C209Initialize::GetLocation@ 0X112E10|1125904
18:49:35.904E9C209Initialize::GetLocation@ 0X20B30|133936
18:49:35.904E9C209Initialize::GetLocation@ 0X20A40|133696
18:49:35.904E9C209Initialize::GetLocation@ 0XD8D0|55504
18:49:35.904E9C209Initialize::GetLocation@ 0X466B0|288432
18:49:35.904E9C209Initialize::GetLocation@ 0XAAB0|43696
18:49:35.904E9C209Initialize::GetLocation@ 0XCE2D0|844496
18:49:35.904E9C209Initialize::GetLocation@ 0XCE9A0|846240
18:49:35.904E9C209Initialize::GetLocation@ 0XAAB0|43696
18:49:35.904E9C209Initialize::GetLocation@ 0XCF490|849040
18:49:35.904E9C209Initialize::GetLocation@ 0XCFAF0|850672
18:49:35.1044E9C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X6F030000>6|2|1247870977
18:49:35.1554E9C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
18:49:35.1554E9C209Initialize::GetLocation@ 0X4040|16448
18:49:35.1554E9C209Initialize::GetLocation@ 0X6410|25616
18:49:35.1554E9C209Initialize::GetLocation@ 0X65C0|26048
18:49:35.1604E9C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X62C70000>6|2|1247870977
18:49:35.1714E9C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
18:49:35.1714E9C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
18:49:35.1714E9C209Initialize::GetLocation@ 0XA5D0|42448
18:49:35.1714E9C209Initialize::GetLocation@ 0XD4D0|54480
18:49:35.1714E9C209Initialize::GetLocation@ 0XD290|53904
18:49:35.2304E9C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_78_14_3920 opened succesfuly
18:49:35.2304E9C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
18:49:35.2314E9C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_78_14_3920 close 2147483647 bytes
18:49:35.2314E9C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.149.2.30\OWExplorer.dll]
18:49:35.3064E9C385ftw1OWExplorer injected
18:49:35.84740D051`anonymous-namespace'::CreateProviderInitialize provider: NET
18:49:35.84840D0117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
18:49:35.84840D054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
18:49:35.84840D051`anonymous-namespace'::CreateProviderInitialize provider: GPU
18:52:06.3302C7C352ProcessInjector::HandleElevatedProcessFail injection to process [2616] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |2616|: NVDisplay.Container.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [4668] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |4668|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [5004] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |5004|: nvcontainer.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [5340] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |5340|: MsMpEng.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [5384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |5384|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [11780] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |11780|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [13372] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |13372|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [14616] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |14616|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [14688] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |14688|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [14696] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |14696|: node.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [16156] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |16156|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [18780] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |18780|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [20912] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |20912|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [21404] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |21404|: firefox.exe
18:52:06.3312C7C352ProcessInjector::HandleElevatedProcessFail injection to process [23980] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:52:06.3312C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |23980|: firefox.exe
18:52:07.3332C7C352ProcessInjector::HandleElevatedProcessFail injection to process [7312] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3332C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |7312|: Code.exe
18:52:07.3332C7C352ProcessInjector::HandleElevatedProcessFail injection to process [8928] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3332C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |8928|: Code.exe
18:52:07.3332C7C352ProcessInjector::HandleElevatedProcessFail injection to process [9780] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |9780|: Code.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [12388] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |12388|: Code.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [12660] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |12660|: Code.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [14056] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |14056|: node.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [14344] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |14344|: Code.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [16164] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |16164|: Code.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [19000] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |19000|: Code.exe
18:52:07.3342C7C352ProcessInjector::HandleElevatedProcessFail injection to process [22172] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:52:07.3342C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |22172|: Code.exe
19:25:55.142C7C352ProcessInjector::HandleElevatedProcessFail injection to process [8812] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
19:25:55.142C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |8812|: firefox.exe
19:26:59.6892C7C352ProcessInjector::HandleElevatedProcessFail injection to process [23560] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
19:26:59.6892C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |23560|: Code.exe
19:33:03.3572C7C352ProcessInjector::HandleElevatedProcessFail injection to process [21464] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x0
19:33:03.3572C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |21464|: openvpn.exe
21:10:41.9982C7C352ProcessInjector::HandleElevatedProcessFail injection to process [12920] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
21:10:41.9982C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |12920|: Code.exe
22:16:28.7772C7C352ProcessInjector::HandleElevatedProcessFail injection to process [2380] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
22:16:28.7772C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |2380|: node.exe
22:37:21.3052C7C352ProcessInjector::HandleElevatedProcessFail injection to process [23368] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
22:37:21.3062C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |23368|: firefox.exe
00:29:12.5332C7C352ProcessInjector::HandleElevatedProcessFail injection to process [21336] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:29:12.5332C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |21336|: firefox.exe
00:34:06.7352C7C352ProcessInjector::HandleElevatedProcessFail injection to process [13268] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:34:06.7352C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |13268|: firefox.exe
00:34:07.7382C7C352ProcessInjector::HandleElevatedProcessFail injection to process [23000] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:34:07.7382C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |23000|: firefox.exe
00:48:26.3412C7C352ProcessInjector::HandleElevatedProcessFail injection to process [18468] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:48:26.3412C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |18468|: firefox.exe
00:53:18.5982C7C352ProcessInjector::HandleElevatedProcessFail injection to process [20860] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:53:18.5982C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |20860|: firefox.exe
00:53:19.6092C7C352ProcessInjector::HandleElevatedProcessFail injection to process [5932] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:53:19.6092C7C291ProcessInjector::HandlePendingProccesssFail to inject pending process |5932|: firefox.exe
01:18:47.5004E9C66ProcessesMonitor::Stopstopping PM...
01:18:47.50040D0119ProcessesMonitor::ProcessEnumerateThreadexit process listener
01:18:47.5024E9C437ProcessInjector::Unhookunhook running process