TimeThreadLineFunctionMessage
18:09:52.6823A0C361ftw1Loading (pid: 23748)
18:09:52.6821E68146ProcessHardwareRecorder::CommandThreadstarting recorder thread
18:09:52.6853A0C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XF7620000>6|2|1247870977
18:09:52.6863A0C48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XFD100000>6|2|1247870977
18:09:52.7433A0C172DXManager::DetectFound in 0
18:09:52.7433A0C209Initialize::GetLocation@ 0X4F80|20352
18:09:52.7433A0C209Initialize::GetLocation@ 0X69160|430432
18:09:52.7433A0C209Initialize::GetLocation@ 0X20410|132112
18:09:52.7433A0C209Initialize::GetLocation@ 0X1DE0|7648
18:09:52.7433A0C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000
18:09:52.7433A0C209Initialize::GetLocation@ 0XFA648850|-94074800
18:09:52.7433A0C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000
18:09:52.7433A0C209Initialize::GetLocation@ 0XFA64DE80|-94052736
18:09:52.7433A0C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000
18:09:52.7433A0C209Initialize::GetLocation@ 0XFA64C5E0|-94059040
18:09:52.7443A0C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF7620000 <> 0XFD100000
18:09:52.7443A0C209Initialize::GetLocation@ 0XFA52A7F0|-95246352
18:09:52.7513A0C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0XF44D0000>6|2|1247870977
18:09:52.7793A0C129DXManager::DetectOK
18:09:52.7963A0C186DXManager::DetectDone
18:09:52.7963A0C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
18:09:52.7973A0C209Initialize::GetLocation@ 0X3FC10|261136
18:09:52.7973A0C209Initialize::GetLocation@ 0X33840|211008
18:09:52.7973A0C209Initialize::GetLocation@ 0X3BFA0|245664
18:09:52.7973A0C209Initialize::GetLocation@ 0XB70E0|749792
18:09:52.7973A0C209Initialize::GetLocation@ 0XB6C30|748592
18:09:52.7973A0C209Initialize::GetLocation@ 0XAF40|44864
18:09:52.7973A0C209Initialize::GetLocation@ 0XB6CD0|748752
18:09:52.7973A0C209Initialize::GetLocation@ 0X20C40|134208
18:09:52.7973A0C209Initialize::GetLocation@ 0X16A10|92688
18:09:52.7973A0C209Initialize::GetLocation@ 0X2D530|185648
18:09:52.7973A0C209Initialize::GetLocation@ 0X113350|1127248
18:09:52.7973A0C209Initialize::GetLocation@ 0X112E10|1125904
18:09:52.7973A0C209Initialize::GetLocation@ 0X20B30|133936
18:09:52.7973A0C209Initialize::GetLocation@ 0X20A40|133696
18:09:52.7973A0C209Initialize::GetLocation@ 0XD8D0|55504
18:09:52.7973A0C209Initialize::GetLocation@ 0X466B0|288432
18:09:52.7973A0C209Initialize::GetLocation@ 0XAAB0|43696
18:09:52.7973A0C209Initialize::GetLocation@ 0XCE2D0|844496
18:09:52.7973A0C209Initialize::GetLocation@ 0XCE9A0|846240
18:09:52.7973A0C209Initialize::GetLocation@ 0XAAB0|43696
18:09:52.7973A0C209Initialize::GetLocation@ 0XCF490|849040
18:09:52.7973A0C209Initialize::GetLocation@ 0XCFAF0|850672
18:09:52.8393A0C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XABF40000>6|2|1247870977
18:09:52.9203A0C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
18:09:52.9213A0C209Initialize::GetLocation@ 0X4040|16448
18:09:52.9213A0C209Initialize::GetLocation@ 0X6410|25616
18:09:52.9213A0C209Initialize::GetLocation@ 0X65C0|26048
18:09:52.9443A0C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XA4010000>6|2|1247870977
18:09:52.9683A0C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
18:09:52.9703A0C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
18:09:52.9703A0C209Initialize::GetLocation@ 0XA5D0|42448
18:09:52.9703A0C209Initialize::GetLocation@ 0XD4D0|54480
18:09:52.9703A0C209Initialize::GetLocation@ 0XD290|53904
18:09:53.323A0C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_78_14_23748 opened succesfuly
18:09:53.323A0C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
18:09:53.323A0C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_78_14_23748 close 2147483647 bytes
18:09:53.323A0C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.149.2.30\OWExplorer.dll]
18:09:53.1143A0C385ftw1OWExplorer injected
18:09:53.86844AC51`anonymous-namespace'::CreateProviderInitialize provider: NET
18:09:53.86844AC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
18:09:53.86844AC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
18:09:53.86844AC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
18:12:24.2952FC8352ProcessInjector::HandleElevatedProcessFail injection to process [2684] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
18:12:24.2952FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |2684|: NVDisplay.Container.exe
18:12:24.2952FC8352ProcessInjector::HandleElevatedProcessFail injection to process [4964] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
18:12:24.2952FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |4964|: nvcontainer.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [2556] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |2556|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [3352] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |3352|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [6952] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |6952|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [8264] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |8264|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [8460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |8460|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [8672] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |8672|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [8764] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |8764|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [9068] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |9068|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [9872] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |9872|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [10132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |10132|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [10388] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |10388|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [11680] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |11680|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [11780] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |11780|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [12132] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |12132|: MsMpEng.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [13880] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |13880|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [13964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |13964|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [14144] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |14144|: node.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [14444] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |14444|: firefox.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [20580] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |20580|: Code.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [23476] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |23476|: node.exe
18:12:25.3082FC8352ProcessInjector::HandleElevatedProcessFail injection to process [25056] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:12:25.3082FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |25056|: Code.exe
18:16:31.4612FC8352ProcessInjector::HandleElevatedProcessFail injection to process [12460] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:16:31.4612FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |12460|: firefox.exe
18:18:33.6282FC8352ProcessInjector::HandleElevatedProcessFail injection to process [23564] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
18:18:33.6282FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |23564|: firefox.exe
18:23:22.1972FC8352ProcessInjector::HandleElevatedProcessFail injection to process [1236] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:23:22.1972FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |1236|: Code.exe
18:24:56.212FC8352ProcessInjector::HandleElevatedProcessFail injection to process [532] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
18:24:56.212FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |532|: node.exe
18:33:27.5202FC8352ProcessInjector::HandleElevatedProcessFail injection to process [17968] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
18:33:27.5202FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |17968|: node.exe
18:36:33.9092FC8352ProcessInjector::HandleElevatedProcessFail injection to process [11572] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
18:36:33.9092FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |11572|: firefox.exe
18:36:34.9252FC8352ProcessInjector::HandleElevatedProcessFail injection to process [24800] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
18:36:34.9252FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |24800|: firefox.exe
18:49:15.6752FC8352ProcessInjector::HandleElevatedProcessFail injection to process [20864] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
18:49:15.6752FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |20864|: firefox.exe
19:04:32.8612FC8352ProcessInjector::HandleElevatedProcessFail injection to process [17964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
19:04:32.8612FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |17964|: firefox.exe
19:20:06.4152FC8352ProcessInjector::HandleElevatedProcessFail injection to process [10336] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
19:20:06.4152FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |10336|: firefox.exe
19:38:56.6692FC8352ProcessInjector::HandleElevatedProcessFail injection to process [10180] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
19:38:56.6692FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |10180|: firefox.exe
22:31:42.1742FC8352ProcessInjector::HandleElevatedProcessFail injection to process [10788] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
22:31:42.1742FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |10788|: Code.exe
22:39:19.512FC8352ProcessInjector::HandleElevatedProcessFail injection to process [7964] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x5
22:39:19.522FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |7964|: firefox.exe
00:05:55.1072FC8352ProcessInjector::HandleElevatedProcessFail injection to process [8712] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x5
00:05:55.1072FC8291ProcessInjector::HandlePendingProccesssFail to inject pending process |8712|: openvpn.exe
00:49:53.9883A0C66ProcessesMonitor::Stopstopping PM...
00:49:53.98844AC119ProcessesMonitor::ProcessEnumerateThreadexit process listener
00:49:59.9953A0C66ProcessesMonitor::Stopstopping PM...