TimeThreadLineFunctionMessage
14:21:58.712F84361ftw1Loading (pid: 11116)
14:21:58.7122DC146ProcessHardwareRecorder::CommandThreadstarting recorder thread
14:21:58.732F8448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X2AE0000>6|2|1247871522
14:21:58.732F8448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X5450000>6|2|1247871522
14:21:58.1962F84172DXManager::DetectFound in 0
14:21:58.1962F84209Initialize::GetLocation@ 0X4F80|20352
14:21:58.1962F84209Initialize::GetLocation@ 0X69640|431680
14:21:58.1962F84209Initialize::GetLocation@ 0X206F0|132848
14:21:58.1962F84209Initialize::GetLocation@ 0X1DE0|7648
14:21:58.1962F84111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
14:21:58.1962F84209Initialize::GetLocation@ 0XFD7B8860|-42235808
14:21:58.1962F84111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
14:21:58.1962F84209Initialize::GetLocation@ 0XFD7BDC30|-42214352
14:21:58.1962F84111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
14:21:58.1962F84209Initialize::GetLocation@ 0XFD7BC5F0|-42220048
14:21:58.1972F84111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2AE0000 <> 0X5450000
14:21:58.1972F84209Initialize::GetLocation@ 0XFD69A7F0|-43407376
14:21:58.2122F8448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XCECE0000>6|2|1247871522
14:21:58.3402F84129DXManager::DetectOK
14:21:58.3682F84186DXManager::DetectDone
14:21:58.3682F84215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
14:21:58.3682F84209Initialize::GetLocation@ 0X41060|266336
14:21:58.3682F84209Initialize::GetLocation@ 0X33320|209696
14:21:58.3682F84209Initialize::GetLocation@ 0X3CB90|248720
14:21:58.3682F84209Initialize::GetLocation@ 0XB75B0|751024
14:21:58.3682F84209Initialize::GetLocation@ 0XB7100|749824
14:21:58.3682F84209Initialize::GetLocation@ 0XA1F0|41456
14:21:58.3682F84209Initialize::GetLocation@ 0XB71A0|749984
14:21:58.3682F84209Initialize::GetLocation@ 0X1ABB0|109488
14:21:58.3682F84209Initialize::GetLocation@ 0X1D600|120320
14:21:58.3682F84209Initialize::GetLocation@ 0X25C30|154672
14:21:58.3682F84209Initialize::GetLocation@ 0X113820|1128480
14:21:58.3682F84209Initialize::GetLocation@ 0X1132E0|1127136
14:21:58.3682F84209Initialize::GetLocation@ 0X1AAA0|109216
14:21:58.3682F84209Initialize::GetLocation@ 0X1A9B0|108976
14:21:58.3682F84209Initialize::GetLocation@ 0XCB80|52096
14:21:58.3682F84209Initialize::GetLocation@ 0X47F90|294800
14:21:58.3682F84209Initialize::GetLocation@ 0X9D60|40288
14:21:58.3682F84209Initialize::GetLocation@ 0XCE7A0|845728
14:21:58.3682F84209Initialize::GetLocation@ 0XCEE70|847472
14:21:58.3682F84209Initialize::GetLocation@ 0X9D60|40288
14:21:58.3682F84209Initialize::GetLocation@ 0XCF960|850272
14:21:58.3682F84209Initialize::GetLocation@ 0XCFFC0|851904
14:21:58.3862F8448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XEB3D0000>6|2|1247870977
14:21:58.4382F8483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
14:21:58.4392F84209Initialize::GetLocation@ 0X4040|16448
14:21:58.4392F84209Initialize::GetLocation@ 0X6410|25616
14:21:58.4392F84209Initialize::GetLocation@ 0X65C0|26048
14:21:58.4412F8448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XCE9E0000>6|2|1247870977
14:21:58.4672F8493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
14:21:58.4682F84110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
14:21:58.4682F84209Initialize::GetLocation@ 0XA5D0|42448
14:21:58.4682F84209Initialize::GetLocation@ 0XD4D0|54480
14:21:58.4682F84209Initialize::GetLocation@ 0XD290|53904
14:21:58.5302F84225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_11116 opened succesfuly
14:21:58.5302F8472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
14:21:58.5302F84256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_11116 close 2147483647 bytes
14:21:58.5302F84297InjectOWExplorerExplorer file name [D:\Programe\Overwolf\0.156.1.1\OWExplorer.dll]
14:21:58.5792F84385ftw1OWExplorer injected
14:21:58.9692E9451`anonymous-namespace'::CreateProviderInitialize provider: NET
14:21:58.9692E94117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
14:21:58.9692E9454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
14:21:58.9692E9451`anonymous-namespace'::CreateProviderInitialize provider: GPU
14:24:29.5332EA4394ProcessInjector::HandleElevatedProcessFail injection to process [1388] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
14:24:29.5342EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |1388|: NVDisplay.Container.exe
14:24:29.5342EA4394ProcessInjector::HandleElevatedProcessFail injection to process [3884] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
14:24:29.5342EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |3884|: nvcontainer.exe
14:24:29.5342EA4394ProcessInjector::HandleElevatedProcessFail injection to process [3980] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
14:24:29.5342EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |3980|: MsMpEng.exe
14:24:29.5342EA4394ProcessInjector::HandleElevatedProcessFail injection to process [10512] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
14:24:29.5342EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |10512|: Teams.exe
14:24:29.5342EA4394ProcessInjector::HandleElevatedProcessFail injection to process [10716] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
14:24:29.5342EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |10716|: Teams.exe
14:24:29.5342EA4394ProcessInjector::HandleElevatedProcessFail injection to process [10900] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
14:24:29.5342EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |10900|: Teams.exe
14:53:27.5162EA4394ProcessInjector::HandleElevatedProcessFail injection to process [14552] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
14:53:27.5172EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |14552|: WhatsApp.exe
14:53:27.5172EA4394ProcessInjector::HandleElevatedProcessFail injection to process [15100] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
14:53:27.5172EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |15100|: WhatsApp.exe
14:53:39.6482EA4394ProcessInjector::HandleElevatedProcessFail injection to process [13588] [t: 0 w_t_id: 0]- WhatsApp.exe (elevated True) 0x0
14:53:39.6482EA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |13588|: WhatsApp.exe
16:58:36.3052F8466ProcessesMonitor::Stopstopping PM...
16:58:36.3062E94119ProcessesMonitor::ProcessEnumerateThreadexit process listener
16:58:42.3522F8466ProcessesMonitor::Stopstopping PM...