TimeThreadLineFunctionMessage
01:25:37.6232E64361ftw1Loading (pid: 8324)
01:25:37.624CCC146ProcessHardwareRecorder::CommandThreadstarting recorder thread
01:25:37.6242E6448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XF0300000>6|2|1247871522
01:25:37.6242E6448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XF2D20000>6|2|1247871522
01:25:37.7582E64172DXManager::DetectFound in 0
01:25:37.7592E64209Initialize::GetLocation@ 0X4F80|20352
01:25:37.7592E64209Initialize::GetLocation@ 0X69640|431680
01:25:37.7592E64209Initialize::GetLocation@ 0X206F0|132848
01:25:37.7592E64209Initialize::GetLocation@ 0X1DE0|7648
01:25:37.7592E64111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF0300000 <> 0XF2D20000
01:25:37.7592E64209Initialize::GetLocation@ 0XFD708860|-42956704
01:25:37.7592E64111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF0300000 <> 0XF2D20000
01:25:37.7592E64209Initialize::GetLocation@ 0XFD70DC30|-42935248
01:25:37.7592E64111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF0300000 <> 0XF2D20000
01:25:37.7592E64209Initialize::GetLocation@ 0XFD70C5F0|-42940944
01:25:37.7592E64111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XF0300000 <> 0XF2D20000
01:25:37.7592E64209Initialize::GetLocation@ 0XFD5EA7F0|-44128272
01:25:37.7762E6448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XE99E0000>6|2|1247871638
01:25:37.9902E64129DXManager::DetectOK
01:25:38.432E64186DXManager::DetectDone
01:25:38.432E64215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
01:25:38.432E64209Initialize::GetLocation@ 0X41B90|269200
01:25:38.432E64209Initialize::GetLocation@ 0X33E20|212512
01:25:38.432E64209Initialize::GetLocation@ 0X3D6C0|251584
01:25:38.432E64209Initialize::GetLocation@ 0XB8E10|757264
01:25:38.432E64209Initialize::GetLocation@ 0XB8960|756064
01:25:38.432E64209Initialize::GetLocation@ 0XACF0|44272
01:25:38.432E64209Initialize::GetLocation@ 0XB8A00|756224
01:25:38.432E64209Initialize::GetLocation@ 0X1B6B0|112304
01:25:38.432E64209Initialize::GetLocation@ 0X1E100|123136
01:25:38.432E64209Initialize::GetLocation@ 0X26730|157488
01:25:38.432E64209Initialize::GetLocation@ 0X1146B0|1132208
01:25:38.432E64209Initialize::GetLocation@ 0X114170|1130864
01:25:38.432E64209Initialize::GetLocation@ 0X1B5A0|112032
01:25:38.432E64209Initialize::GetLocation@ 0X1B4B0|111792
01:25:38.432E64209Initialize::GetLocation@ 0XD680|54912
01:25:38.432E64209Initialize::GetLocation@ 0X493C0|299968
01:25:38.432E64209Initialize::GetLocation@ 0XA860|43104
01:25:38.432E64209Initialize::GetLocation@ 0XD0000|851968
01:25:38.432E64209Initialize::GetLocation@ 0XD06D0|853712
01:25:38.432E64209Initialize::GetLocation@ 0XA860|43104
01:25:38.432E64209Initialize::GetLocation@ 0XD11C0|856512
01:25:38.432E64209Initialize::GetLocation@ 0XD1820|858144
01:25:38.572E6448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XC77C0000>6|2|1247870977
01:25:38.732E6483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
01:25:38.732E64209Initialize::GetLocation@ 0X4040|16448
01:25:38.732E64209Initialize::GetLocation@ 0X6410|25616
01:25:38.732E64209Initialize::GetLocation@ 0X65C0|26048
01:25:38.742E6448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XB94D0000>6|2|1247870977
01:25:38.862E6493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
01:25:38.862E64110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
01:25:38.862E64209Initialize::GetLocation@ 0XA5D0|42448
01:25:38.862E64209Initialize::GetLocation@ 0XD4D0|54480
01:25:38.862E64209Initialize::GetLocation@ 0XD290|53904
01:25:38.1552E64225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_8324 opened succesfuly
01:25:38.1552E6472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
01:25:38.1552E64256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_8324 close 2147483647 bytes
01:25:38.1552E64297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.31\OWExplorer.dll]
01:25:38.1572E64385ftw1OWExplorer injected
01:25:38.353A4451`anonymous-namespace'::CreateProviderInitialize provider: NET
01:25:38.353A44117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
01:25:38.353A4454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
01:25:38.353A4451`anonymous-namespace'::CreateProviderInitialize provider: GPU
01:25:38.4361B74629ProcessInjector::InjectProcessprocess |VpnSvc.exe| missing h
01:25:38.5001B74629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
01:25:38.5001B74629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
01:25:38.6861B74629ProcessInjector::InjectProcessprocess |LMS.exe| missing h
01:28:08.4831B74441ProcessInjector::HandleElevatedProcessFail injection to process [2396] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
01:28:08.4841B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |2396|: NVDisplay.Container.exe
01:28:08.4841B74441ProcessInjector::HandleElevatedProcessFail injection to process [5484] [t: 0 w_t_id: 0]- VpnSvc.exe (elevated True) 0x0
01:28:08.4841B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |5484|: VpnSvc.exe
01:28:08.4841B74441ProcessInjector::HandleElevatedProcessFail injection to process [5616] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
01:28:08.4841B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |5616|: nvcontainer.exe
01:28:08.4841B74441ProcessInjector::HandleElevatedProcessFail injection to process [5820] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
01:28:08.4841B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |5820|: MsMpEng.exe
01:28:09.4941B74441ProcessInjector::HandleElevatedProcessFail injection to process [5668] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0
01:28:09.4941B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |5668|: LMS.exe
01:28:09.4941B74441ProcessInjector::HandleElevatedProcessFail injection to process [9888] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
01:28:09.4941B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |9888|: GoogleCrashHandler.exe
01:28:09.4941B74441ProcessInjector::HandleElevatedProcessFail injection to process [9912] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
01:28:09.4941B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |9912|: GoogleCrashHandler64.exe
01:30:33.5631B74629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
01:30:57.7041B74441ProcessInjector::HandleElevatedProcessFail injection to process [7264] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
01:30:57.7041B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |7264|: owobs-ffmpeg-mux.exe
01:35:40.9811B74441ProcessInjector::HandleElevatedProcessFail injection to process [8328] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
01:35:40.9811B74380ProcessInjector::HandlePendingProccesssFail to inject pending process |8328|: owobs-ffmpeg-mux.exe
02:24:59.8102E6466ProcessesMonitor::Stopstopping PM...
02:24:59.810A44119ProcessesMonitor::ProcessEnumerateThreadexit process listener