TimeThreadLineFunctionMessage
23:10:09.3174FB0361ftw1Loading (pid: 5088)
23:10:09.31752E8146ProcessHardwareRecorder::CommandThreadstarting recorder thread
23:10:09.3194FB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XF4BB0000>6|2|1203372419
23:10:09.3194FB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XF6540000>6|2|1203373081
23:10:09.3884FB0172DXManager::DetectFound in 0
23:10:09.3884FB0209Initialize::GetLocation@ 0X4660|18016
23:10:09.3884FB0209Initialize::GetLocation@ 0X661F0|418288
23:10:09.3884FB0209Initialize::GetLocation@ 0X19DB0|105904
23:10:09.3884FB0209Initialize::GetLocation@ 0X1350|4944
23:10:09.3884FB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF4BB0000 <> 0XF6540000
23:10:09.3884FB0209Initialize::GetLocation@ 0XFE792E80|-25612672
23:10:09.3884FB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF4BB0000 <> 0XF6540000
23:10:09.3884FB0209Initialize::GetLocation@ 0XFE797F80|-25591936
23:10:09.3884FB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF4BB0000 <> 0XF6540000
23:10:09.3884FB0209Initialize::GetLocation@ 0XFE78E620|-25631200
23:10:09.3884FB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF4BB0000 <> 0XF6540000
23:10:09.3884FB0209Initialize::GetLocation@ 0XFE67AD10|-26759920
23:10:09.4064FB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XEFDF0000>6|2|1203372419
23:10:09.5364FB0129DXManager::DetectOK
23:10:09.6024FB0186DXManager::DetectDone
23:10:09.6034FB0215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
23:10:09.6034FB0209Initialize::GetLocation@ 0X3AC00|240640
23:10:09.6034FB0209Initialize::GetLocation@ 0X2C5B0|181680
23:10:09.6034FB0209Initialize::GetLocation@ 0X36D00|224512
23:10:09.6034FB0209Initialize::GetLocation@ 0XAE020|712736
23:10:09.6034FB0209Initialize::GetLocation@ 0XADB70|711536
23:10:09.6034FB0209Initialize::GetLocation@ 0X5880|22656
23:10:09.6034FB0209Initialize::GetLocation@ 0XADC10|711696
23:10:09.6034FB0209Initialize::GetLocation@ 0X20FF0|135152
23:10:09.6034FB0209Initialize::GetLocation@ 0X1CA60|117344
23:10:09.6034FB0209Initialize::GetLocation@ 0X1C8E0|116960
23:10:09.6034FB0209Initialize::GetLocation@ 0X1084E0|1082592
23:10:09.6034FB0209Initialize::GetLocation@ 0X107F90|1081232
23:10:09.6034FB0209Initialize::GetLocation@ 0X248B0|149680
23:10:09.6034FB0209Initialize::GetLocation@ 0X247A0|149408
23:10:09.6034FB0209Initialize::GetLocation@ 0X2C440|181312
23:10:09.6034FB0209Initialize::GetLocation@ 0X3F210|258576
23:10:09.6034FB0209Initialize::GetLocation@ 0XF3E0|62432
23:10:09.6034FB0209Initialize::GetLocation@ 0XF4E0|62688
23:10:09.6034FB0209Initialize::GetLocation@ 0XF5D0|62928
23:10:09.6034FB0209Initialize::GetLocation@ 0XF3E0|62432
23:10:09.6034FB0209Initialize::GetLocation@ 0XF280|62080
23:10:09.6034FB0209Initialize::GetLocation@ 0XF430|62512
23:10:09.6434FB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XB59E0000>6|2|1203372033
23:10:09.6764FB083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
23:10:09.6764FB0209Initialize::GetLocation@ 0X3CC0|15552
23:10:09.6764FB0209Initialize::GetLocation@ 0X5FD0|24528
23:10:09.6764FB0209Initialize::GetLocation@ 0X6180|24960
23:10:09.6784FB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XCAFB0000>6|2|1203372033
23:10:09.6924FB093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
23:10:09.6934FB0110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
23:10:09.6934FB0209Initialize::GetLocation@ 0X10000|65536
23:10:09.6944FB0209Initialize::GetLocation@ 0X12C80|76928
23:10:09.6944FB0209Initialize::GetLocation@ 0X12A60|76384
23:10:09.7594FB0225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_5088 opened succesfuly
23:10:09.7594FB072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
23:10:09.7594FB0256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_5088 close 2147483647 bytes
23:10:09.7594FB0297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.155.0.10\OWExplorer.dll]
23:10:09.8314FB0385ftw1OWExplorer injected
23:10:10.289553C51`anonymous-namespace'::CreateProviderInitialize provider: NET
23:10:10.290553C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
23:10:10.290553C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
23:10:10.290553C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [1840] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |1840|: NVDisplay.Container.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [3976] [t: 0 w_t_id: 0]- dbsrv17.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |3976|: dbsrv17.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [4216] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |4216|: nvcontainer.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [4476] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |4476|: MsMpEng.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [6748] [t: 0 w_t_id: 0]- dbsrv17.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |6748|: dbsrv17.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [7980] [t: 0 w_t_id: 0]- java.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |7980|: java.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [14396] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |14396|: NVIDIA Share.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [14536] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |14536|: NVIDIA Share.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [14600] [t: 0 w_t_id: 0]- googledrivesync.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |14600|: googledrivesync.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [15220] [t: 0 w_t_id: 0]- GoogleDriveFS.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |15220|: GoogleDriveFS.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [15716] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |15716|: lghub.exe
23:12:40.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [16296] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x1f
23:12:40.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |16296|: lghub.exe
23:12:41.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [4696] [t: 0 w_t_id: 0]- GOOGLE~1.EXE (elevated True) 0x1f
23:12:41.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |4696|: GOOGLE~1.EXE
23:12:41.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [9204] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x1f
23:12:41.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |9204|: splwow64.exe
23:12:41.9975540394ProcessInjector::HandleElevatedProcessFail injection to process [20140] [t: 0 w_t_id: 0]- GOOGLE~1.EXE (elevated True) 0x1f
23:12:41.9975540333ProcessInjector::HandlePendingProccesssFail to inject pending process |20140|: GOOGLE~1.EXE
23:13:52.994FB066ProcessesMonitor::Stopstopping PM...
23:13:52.99553C119ProcessesMonitor::ProcessEnumerateThreadexit process listener
23:13:58.1034FB066ProcessesMonitor::Stopstopping PM...