TimeThreadLineFunctionMessage
10:32:46.2022B8365ftw1Loading (pid: 1452)
10:32:46.2122B848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X27F30000>6|2|1247871722
10:32:46.2222B848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X2AD90000>6|2|1247871940
10:32:46.252D3C147ProcessHardwareRecorder::CommandThreadstarting recorder thread
10:32:46.17822B8172DXManager::DetectFound in 0
10:32:46.17922B8209Initialize::GetLocation@ 0X59E0|23008
10:32:46.17922B8209Initialize::GetLocation@ 0X6AE20|437792
10:32:46.17922B8209Initialize::GetLocation@ 0X211E0|135648
10:32:46.17922B8209Initialize::GetLocation@ 0X2840|10304
10:32:46.17922B8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X27F30000 <> 0X2AD90000
10:32:46.17922B8209Initialize::GetLocation@ 0XFD2C8860|-47413152
10:32:46.17922B8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X27F30000 <> 0X2AD90000
10:32:46.17922B8209Initialize::GetLocation@ 0XFD2CDC30|-47391696
10:32:46.17922B8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X27F30000 <> 0X2AD90000
10:32:46.17922B8209Initialize::GetLocation@ 0XFD2CC5F0|-47397392
10:32:46.17922B8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X27F30000 <> 0X2AD90000
10:32:46.17922B8209Initialize::GetLocation@ 0XFD1AA7F0|-48584720
10:32:46.31022B848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XFA830000>6|2|1247871904
10:32:46.41622B8129DXManager::DetectOK
10:32:46.46522B8186DXManager::DetectDone
10:32:46.46522B8215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
10:32:46.46622B8209Initialize::GetLocation@ 0X41090|266384
10:32:46.46622B8209Initialize::GetLocation@ 0X33320|209696
10:32:46.46622B8209Initialize::GetLocation@ 0X3CBC0|248768
10:32:46.46622B8209Initialize::GetLocation@ 0XB76A0|751264
10:32:46.46622B8209Initialize::GetLocation@ 0XB71F0|750064
10:32:46.46622B8209Initialize::GetLocation@ 0XA1F0|41456
10:32:46.46622B8209Initialize::GetLocation@ 0XB7290|750224
10:32:46.46622B8209Initialize::GetLocation@ 0X1ABB0|109488
10:32:46.46622B8209Initialize::GetLocation@ 0X1D600|120320
10:32:46.46622B8209Initialize::GetLocation@ 0X25C30|154672
10:32:46.46622B8209Initialize::GetLocation@ 0X113920|1128736
10:32:46.46622B8209Initialize::GetLocation@ 0X1133E0|1127392
10:32:46.46622B8209Initialize::GetLocation@ 0X1AAA0|109216
10:32:46.46622B8209Initialize::GetLocation@ 0X1A9B0|108976
10:32:46.46622B8209Initialize::GetLocation@ 0XCB80|52096
10:32:46.46622B8209Initialize::GetLocation@ 0X48030|294960
10:32:46.46622B8209Initialize::GetLocation@ 0X9D60|40288
10:32:46.46622B8209Initialize::GetLocation@ 0XCE890|845968
10:32:46.46622B8209Initialize::GetLocation@ 0XCEF60|847712
10:32:46.46622B8209Initialize::GetLocation@ 0X9D60|40288
10:32:46.46622B8209Initialize::GetLocation@ 0XCFA50|850512
10:32:46.46622B8209Initialize::GetLocation@ 0XD00B0|852144
10:32:46.48722B848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XB92C0000>6|2|1247870977
10:32:46.50222B883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
10:32:46.50222B8209Initialize::GetLocation@ 0X4040|16448
10:32:46.50222B8209Initialize::GetLocation@ 0X6410|25616
10:32:46.50222B8209Initialize::GetLocation@ 0X65C0|26048
10:32:46.50722B848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XB9270000>6|2|1247870977
10:32:46.51622B893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
10:32:46.51622B8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
10:32:46.51622B8209Initialize::GetLocation@ 0XA5D0|42448
10:32:46.51622B8209Initialize::GetLocation@ 0XD4D0|54480
10:32:46.51622B8209Initialize::GetLocation@ 0XD290|53904
10:32:46.58922B8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_85_4_1452 opened succesfuly
10:32:46.58922B872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
10:32:46.58922B8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_85_4_1452 close 2147483647 bytes
10:32:46.58922B8301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.170.48.15\OWExplorer.dll]
10:32:46.68122B8389ftw1OWExplorer injected
10:32:46.688359471Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
10:32:47.034F451`anonymous-namespace'::CreateProviderInitialize provider: NET
10:32:47.134F4117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
10:32:47.134F454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
10:32:47.134F451`anonymous-namespace'::CreateProviderInitialize provider: GPU
10:32:47.92C0C669ProcessInjector::InjectProcessprocess |ekrn.exe| missing h
10:32:47.92C0C669ProcessInjector::InjectProcessprocess |culauncher.exe| missing h
10:32:47.92C0C669ProcessInjector::InjectProcessprocess |ERAAgent.exe| missing h
10:32:47.92C0C669ProcessInjector::InjectProcessprocess |remoting_host.exe| missing h
10:32:47.92C0C669ProcessInjector::InjectProcessprocess |RzSDKServer.exe| missing h
10:32:59.7962C0C669ProcessInjector::InjectProcessprocess |culauncher.exe| missing h
10:33:37.2252C0C669ProcessInjector::InjectProcessprocess |culauncher.exe| missing h
10:34:11.5032C0C669ProcessInjector::InjectProcessprocess |culauncher.exe| missing h
10:34:48.9132C0C669ProcessInjector::InjectProcessprocess |culauncher.exe| missing h
10:35:17.1012C0C386ProcessInjector::HandleElevatedProcessFail injection to process [1704] [t: 0 w_t_id: 0]- ekrn.exe (elevated True) 0x0
10:35:17.1012C0C318ProcessInjector::HandlePendingProccesssFail to inject pending process |1704|: ekrn.exe
10:35:17.1012C0C386ProcessInjector::HandleElevatedProcessFail injection to process [2372] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
10:35:17.1012C0C318ProcessInjector::HandlePendingProccesssFail to inject pending process |2372|: NVDisplay.Container.exe
10:35:17.1012C0C386ProcessInjector::HandleElevatedProcessFail injection to process [3076] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
10:35:17.1012C0C318ProcessInjector::HandlePendingProccesssFail to inject pending process |3076|: nvcontainer.exe
10:35:17.1012C0C386ProcessInjector::HandleElevatedProcessFail injection to process [3976] [t: 0 w_t_id: 0]- ERAAgent.exe (elevated True) 0x0
10:35:17.1012C0C318ProcessInjector::HandlePendingProccesssFail to inject pending process |3976|: ERAAgent.exe
10:35:17.1012C0C386ProcessInjector::HandleElevatedProcessFail injection to process [3992] [t: 0 w_t_id: 0]- remoting_host.exe (elevated True) 0x0
10:35:17.1012C0C318ProcessInjector::HandlePendingProccesssFail to inject pending process |3992|: remoting_host.exe
10:35:17.1012C0C386ProcessInjector::HandleElevatedProcessFail injection to process [4180] [t: 0 w_t_id: 0]- RzSDKServer.exe (elevated True) 0x0
10:35:17.1012C0C318ProcessInjector::HandlePendingProccesssFail to inject pending process |4180|: RzSDKServer.exe
10:35:23.1502C0C669ProcessInjector::InjectProcessprocess |culauncher.exe| missing h
10:35:23.944359476Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
10:35:23.96322B866ProcessesMonitor::Stopstopping PM...
10:35:23.96334F4119ProcessesMonitor::ProcessEnumerateThreadexit process listener
10:35:23.96422B8527ProcessInjector::Unhookunhook running process