TimeThreadLineFunctionMessage
16:58:47.2532A34361ftw1Loading (pid: 9408)
16:58:47.253225C146ProcessHardwareRecorder::CommandThreadstarting recorder thread
16:58:47.2552A3448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X2AE0000>6|2|1247871522
16:58:47.2552A3448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X5450000>6|2|1247871522
16:58:47.3592A34172DXManager::DetectFound in 0
16:58:47.3602A34209Initialize::GetLocation@ 0X4F80|20352
16:58:47.3602A34209Initialize::GetLocation@ 0X69640|431680
16:58:47.3602A34209Initialize::GetLocation@ 0X206F0|132848
16:58:47.3602A34209Initialize::GetLocation@ 0X1DE0|7648
16:58:47.3602A34111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
16:58:47.3602A34209Initialize::GetLocation@ 0XFD7B8860|-42235808
16:58:47.3602A34111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
16:58:47.3602A34209Initialize::GetLocation@ 0XFD7BDC30|-42214352
16:58:47.3602A34111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
16:58:47.3602A34209Initialize::GetLocation@ 0XFD7BC5F0|-42220048
16:58:47.3602A34111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
16:58:47.3602A34209Initialize::GetLocation@ 0XFD69A7F0|-43407376
16:58:47.3862A3448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XCECE0000>6|2|1247871522
16:58:47.4972A34129DXManager::DetectOK
16:58:47.5272A34186DXManager::DetectDone
16:58:47.5272A34215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
16:58:47.5282A34209Initialize::GetLocation@ 0X41060|266336
16:58:47.5282A34209Initialize::GetLocation@ 0X33320|209696
16:58:47.5282A34209Initialize::GetLocation@ 0X3CB90|248720
16:58:47.5282A34209Initialize::GetLocation@ 0XB75B0|751024
16:58:47.5282A34209Initialize::GetLocation@ 0XB7100|749824
16:58:47.5282A34209Initialize::GetLocation@ 0XA1F0|41456
16:58:47.5282A34209Initialize::GetLocation@ 0XB71A0|749984
16:58:47.5282A34209Initialize::GetLocation@ 0X1ABB0|109488
16:58:47.5282A34209Initialize::GetLocation@ 0X1D600|120320
16:58:47.5282A34209Initialize::GetLocation@ 0X25C30|154672
16:58:47.5282A34209Initialize::GetLocation@ 0X113820|1128480
16:58:47.5282A34209Initialize::GetLocation@ 0X1132E0|1127136
16:58:47.5282A34209Initialize::GetLocation@ 0X1AAA0|109216
16:58:47.5282A34209Initialize::GetLocation@ 0X1A9B0|108976
16:58:47.5282A34209Initialize::GetLocation@ 0XCB80|52096
16:58:47.5282A34209Initialize::GetLocation@ 0X47F90|294800
16:58:47.5282A34209Initialize::GetLocation@ 0X9D60|40288
16:58:47.5282A34209Initialize::GetLocation@ 0XCE7A0|845728
16:58:47.5282A34209Initialize::GetLocation@ 0XCEE70|847472
16:58:47.5282A34209Initialize::GetLocation@ 0X9D60|40288
16:58:47.5282A34209Initialize::GetLocation@ 0XCF960|850272
16:58:47.5282A34209Initialize::GetLocation@ 0XCFFC0|851904
16:58:47.5622A3448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XFE4D0000>6|2|1247870977
16:58:47.5782A3483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
16:58:47.5782A34209Initialize::GetLocation@ 0X4040|16448
16:58:47.5782A34209Initialize::GetLocation@ 0X6410|25616
16:58:47.5782A34209Initialize::GetLocation@ 0X65C0|26048
16:58:47.5822A3448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XF64C0000>6|2|1247870977
16:58:47.5902A3493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
16:58:47.5902A34110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
16:58:47.5902A34209Initialize::GetLocation@ 0XA5D0|42448
16:58:47.5902A34209Initialize::GetLocation@ 0XD4D0|54480
16:58:47.5902A34209Initialize::GetLocation@ 0XD290|53904
16:58:47.6562A34225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_9408 opened succesfuly
16:58:47.6562A3472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
16:58:47.6562A34256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_9408 close 2147483647 bytes
16:58:47.6562A34297InjectOWExplorerExplorer file name [D:\Programe\Overwolf\0.156.1.1\OWExplorer.dll]
16:58:47.6602A34385ftw1OWExplorer injected
16:58:48.319232851`anonymous-namespace'::CreateProviderInitialize provider: NET
16:58:48.3192328117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
16:58:48.319232854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
16:58:48.319232851`anonymous-namespace'::CreateProviderInitialize provider: GPU
17:01:18.945550394ProcessInjector::HandleElevatedProcessFail injection to process [1388] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
17:01:18.945550333ProcessInjector::HandlePendingProccesssFail to inject pending process |1388|: NVDisplay.Container.exe
17:01:18.945550394ProcessInjector::HandleElevatedProcessFail injection to process [3884] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
17:01:18.945550333ProcessInjector::HandlePendingProccesssFail to inject pending process |3884|: nvcontainer.exe
17:01:18.945550394ProcessInjector::HandleElevatedProcessFail injection to process [3980] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
17:01:18.945550333ProcessInjector::HandlePendingProccesssFail to inject pending process |3980|: MsMpEng.exe
17:01:18.945550394ProcessInjector::HandleElevatedProcessFail injection to process [14552] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
17:01:18.945550333ProcessInjector::HandlePendingProccesssFail to inject pending process |14552|: WhatsApp.exe
17:01:18.945550394ProcessInjector::HandleElevatedProcessFail injection to process [15100] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
17:01:18.945550333ProcessInjector::HandlePendingProccesssFail to inject pending process |15100|: WhatsApp.exe
17:28:44.793550394ProcessInjector::HandleElevatedProcessFail injection to process [17560] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
17:28:44.793550333ProcessInjector::HandlePendingProccesssFail to inject pending process |17560|: WhatsApp.exe