TimeThreadLineFunctionMessage
16:55:50.111E50361ftw1Loading (pid: 18664)
16:55:50.113E5048Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X8B500000>6|2|1203372419
16:55:50.113E5048Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X8CFD0000>6|2|1203373081
16:55:50.1335A20146ProcessHardwareRecorder::CommandThreadstarting recorder thread
16:55:50.229E50172DXManager::DetectFound in 0
16:55:50.230E50209Initialize::GetLocation@ 0X4660|18016
16:55:50.230E50209Initialize::GetLocation@ 0X661F0|418288
16:55:50.230E50209Initialize::GetLocation@ 0X19DB0|105904
16:55:50.230E50209Initialize::GetLocation@ 0X1350|4944
16:55:50.230E50111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8B500000 <> 0X8CFD0000
16:55:50.230E50209Initialize::GetLocation@ 0XFE652E80|-26923392
16:55:50.230E50111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8B500000 <> 0X8CFD0000
16:55:50.230E50209Initialize::GetLocation@ 0XFE657F80|-26902656
16:55:50.230E50111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8B500000 <> 0X8CFD0000
16:55:50.230E50209Initialize::GetLocation@ 0XFE64E620|-26941920
16:55:50.230E50111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8B500000 <> 0X8CFD0000
16:55:50.230E50209Initialize::GetLocation@ 0XFE53AD10|-28070640
16:55:50.261E5048Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X621E0000>6|2|1203372419
16:55:50.387E50129DXManager::DetectOK
16:55:50.492E50186DXManager::DetectDone
16:55:50.492E50215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
16:55:50.492E50209Initialize::GetLocation@ 0X3AC00|240640
16:55:50.492E50209Initialize::GetLocation@ 0X2C5B0|181680
16:55:50.492E50209Initialize::GetLocation@ 0X36D00|224512
16:55:50.492E50209Initialize::GetLocation@ 0XAE020|712736
16:55:50.492E50209Initialize::GetLocation@ 0XADB70|711536
16:55:50.492E50209Initialize::GetLocation@ 0X5880|22656
16:55:50.492E50209Initialize::GetLocation@ 0XADC10|711696
16:55:50.492E50209Initialize::GetLocation@ 0X20FF0|135152
16:55:50.492E50209Initialize::GetLocation@ 0X1CA60|117344
16:55:50.492E50209Initialize::GetLocation@ 0X1C8E0|116960
16:55:50.492E50209Initialize::GetLocation@ 0X1084E0|1082592
16:55:50.492E50209Initialize::GetLocation@ 0X107F90|1081232
16:55:50.492E50209Initialize::GetLocation@ 0X248B0|149680
16:55:50.492E50209Initialize::GetLocation@ 0X247A0|149408
16:55:50.492E50209Initialize::GetLocation@ 0X2C440|181312
16:55:50.492E50209Initialize::GetLocation@ 0X3F210|258576
16:55:50.492E50209Initialize::GetLocation@ 0XF3E0|62432
16:55:50.492E50209Initialize::GetLocation@ 0XF4E0|62688
16:55:50.492E50209Initialize::GetLocation@ 0XF5D0|62928
16:55:50.492E50209Initialize::GetLocation@ 0XF3E0|62432
16:55:50.492E50209Initialize::GetLocation@ 0XF280|62080
16:55:50.492E50209Initialize::GetLocation@ 0XF430|62512
16:55:50.551E5048Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X459A0000>6|2|1203372033
16:55:50.567E5083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
16:55:50.567E50209Initialize::GetLocation@ 0X3CC0|15552
16:55:50.567E50209Initialize::GetLocation@ 0X5FD0|24528
16:55:50.567E50209Initialize::GetLocation@ 0X6180|24960
16:55:50.571E5048Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X31540000>6|2|1203372033
16:55:50.581E5093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
16:55:50.581E50110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
16:55:50.581E50209Initialize::GetLocation@ 0X10000|65536
16:55:50.581E50209Initialize::GetLocation@ 0X12C80|76928
16:55:50.581E50209Initialize::GetLocation@ 0X12A60|76384
16:55:50.633E50225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_18664 opened succesfuly
16:55:50.633E5072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
16:55:50.633E50256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_18664 close 2147483647 bytes
16:55:50.634E50297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll]
16:55:50.647E50385ftw1OWExplorer injected
16:55:51.13652851`anonymous-namespace'::CreateProviderInitialize provider: NET
16:55:51.136528117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
16:55:51.13652854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
16:55:51.13652851`anonymous-namespace'::CreateProviderInitialize provider: GPU
16:58:21.96543AC394ProcessInjector::HandleElevatedProcessFail injection to process [12568] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:58:21.96543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |12568|: Teams.exe
16:58:21.96543AC394ProcessInjector::HandleElevatedProcessFail injection to process [16524] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:58:21.96543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |16524|: Teams.exe
16:58:21.96543AC394ProcessInjector::HandleElevatedProcessFail injection to process [16920] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
16:58:21.96543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |16920|: MsMpEng.exe
16:58:21.96543AC394ProcessInjector::HandleElevatedProcessFail injection to process [36356] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x5
16:58:21.96543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |36356|: docker-mutagen.exe
16:58:21.96543AC394ProcessInjector::HandleElevatedProcessFail injection to process [36664] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x5
16:58:21.96543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |36664|: com.docker.backend.exe
16:58:25.96443AC394ProcessInjector::HandleElevatedProcessFail injection to process [16000] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x5
16:58:25.96443AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |16000|: vpnkit-bridge.exe
16:58:34.97243AC394ProcessInjector::HandleElevatedProcessFail injection to process [22544] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
16:58:34.97243AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |22544|: Teams.exe
16:58:38.96443AC394ProcessInjector::HandleElevatedProcessFail injection to process [9836] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x5
16:58:38.96443AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |9836|: vpnkit.exe
16:58:50.97343AC394ProcessInjector::HandleElevatedProcessFail injection to process [29084] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x5
16:58:50.97343AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |29084|: com.docker.proxy.exe
17:02:58.3943AC394ProcessInjector::HandleElevatedProcessFail injection to process [30184] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:02:58.3943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |30184|: Teams.exe
17:09:02.9743AC394ProcessInjector::HandleElevatedProcessFail injection to process [26276] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:09:02.9743AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |26276|: Teams.exe
17:15:03.10743AC394ProcessInjector::HandleElevatedProcessFail injection to process [1652] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:15:03.10743AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |1652|: Teams.exe
17:33:13.20943AC394ProcessInjector::HandleElevatedProcessFail injection to process [9696] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:33:13.20943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |9696|: Teams.exe
17:41:29.27643AC394ProcessInjector::HandleElevatedProcessFail injection to process [7588] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:41:29.27643AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |7588|: Teams.exe
17:51:41.50943AC394ProcessInjector::HandleElevatedProcessFail injection to process [30160] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:51:41.50943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |30160|: Teams.exe
17:59:45.55343AC394ProcessInjector::HandleElevatedProcessFail injection to process [13320] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
17:59:45.55343AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |13320|: Teams.exe
18:07:47.63243AC394ProcessInjector::HandleElevatedProcessFail injection to process [13268] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:07:47.63243AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |13268|: Teams.exe
18:19:58.67643AC394ProcessInjector::HandleElevatedProcessFail injection to process [16592] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:19:58.67643AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |16592|: Teams.exe
18:30:01.83743AC394ProcessInjector::HandleElevatedProcessFail injection to process [10028] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:30:01.83743AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |10028|: Teams.exe
18:38:04.90043AC394ProcessInjector::HandleElevatedProcessFail injection to process [30212] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:38:04.90143AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |30212|: Teams.exe
18:46:08.96543AC394ProcessInjector::HandleElevatedProcessFail injection to process [2928] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:46:08.96543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |2928|: Teams.exe
18:54:14.743AC394ProcessInjector::HandleElevatedProcessFail injection to process [8816] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
18:54:14.743AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |8816|: Teams.exe
19:02:16.7943AC394ProcessInjector::HandleElevatedProcessFail injection to process [4736] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
19:02:16.7943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |4736|: Teams.exe
19:16:24.30143AC394ProcessInjector::HandleElevatedProcessFail injection to process [11852] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
19:16:24.30143AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |11852|: Teams.exe
19:20:27.81943AC394ProcessInjector::HandleElevatedProcessFail injection to process [20332] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:27.81943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |20332|: Code.exe
19:20:27.81943AC394ProcessInjector::HandleElevatedProcessFail injection to process [28928] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:27.81943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |28928|: Code.exe
19:20:30.82043AC394ProcessInjector::HandleElevatedProcessFail injection to process [22688] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:30.82043AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |22688|: Code.exe
19:20:30.82043AC394ProcessInjector::HandleElevatedProcessFail injection to process [23960] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:30.82043AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |23960|: Code.exe
19:20:30.82043AC394ProcessInjector::HandleElevatedProcessFail injection to process [36432] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:30.82043AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |36432|: Code.exe
19:20:32.82043AC394ProcessInjector::HandleElevatedProcessFail injection to process [26016] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:32.82043AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |26016|: Code.exe
19:20:34.83743AC394ProcessInjector::HandleElevatedProcessFail injection to process [35908] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:34.83743AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |35908|: Code.exe
19:20:34.83743AC394ProcessInjector::HandleElevatedProcessFail injection to process [36384] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:34.83743AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |36384|: Code.exe
19:20:35.86443AC394ProcessInjector::HandleElevatedProcessFail injection to process [18560] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
19:20:35.86443AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |18560|: Code.exe
19:20:36.88143AC394ProcessInjector::HandleElevatedProcessFail injection to process [9448] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
19:20:36.88143AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |9448|: rg.exe
19:20:36.88143AC394ProcessInjector::HandleElevatedProcessFail injection to process [10392] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
19:20:36.88143AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |10392|: rg.exe
19:22:25.97143AC394ProcessInjector::HandleElevatedProcessFail injection to process [17116] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
19:22:25.97143AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |17116|: Teams.exe
19:22:34.98443AC394ProcessInjector::HandleElevatedProcessFail injection to process [26400] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
19:22:34.98443AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |26400|: node.exe
19:22:35.98443AC394ProcessInjector::HandleElevatedProcessFail injection to process [25100] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
19:22:35.98443AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |25100|: node.exe
19:26:28.38543AC394ProcessInjector::HandleElevatedProcessFail injection to process [27076] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
19:26:28.38543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |27076|: Teams.exe
19:32:31.82343AC394ProcessInjector::HandleElevatedProcessFail injection to process [10668] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
19:32:31.82343AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |10668|: Teams.exe
19:46:35.91343AC394ProcessInjector::HandleElevatedProcessFail injection to process [9068] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
19:46:35.91343AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |9068|: Teams.exe
19:56:44.94143AC394ProcessInjector::HandleElevatedProcessFail injection to process [32852] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
19:56:44.94243AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |32852|: Teams.exe
20:08:50.99043AC394ProcessInjector::HandleElevatedProcessFail injection to process [6896] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
20:08:50.99043AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |6896|: Teams.exe
20:16:55.25943AC394ProcessInjector::HandleElevatedProcessFail injection to process [21336] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
20:16:55.25943AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |21336|: Teams.exe
20:19:46.32543AC394ProcessInjector::HandleElevatedProcessFail injection to process [31200] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:19:46.32543AC333ProcessInjector::HandlePendingProccesssFail to inject pending process |31200|: Code.exe
20:20:10.703E5066ProcessesMonitor::Stopstopping PM...
20:20:10.704528119ProcessesMonitor::ProcessEnumerateThreadexit process listener
20:20:10.707E50479ProcessInjector::Unhookunhook running process
20:20:16.719E5066ProcessesMonitor::Stopstopping PM...