TimeThreadLineFunctionMessage
09:56:10.6893D74361ftw1Loading (pid: 11816)
09:56:10.6913D7448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X58C10000>6|2|1203372419
09:56:10.6923D7448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X5A640000>6|2|1203372847
09:56:10.7484B8146ProcessHardwareRecorder::CommandThreadstarting recorder thread
09:56:11.5423D74172DXManager::DetectFound in 0
09:56:11.5423D74209Initialize::GetLocation@ 0X4670|18032
09:56:11.5423D74209Initialize::GetLocation@ 0X66400|418816
09:56:11.5423D74209Initialize::GetLocation@ 0X19DE0|105952
09:56:11.5423D74209Initialize::GetLocation@ 0X1350|4944
09:56:11.5423D74111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58C10000 <> 0X5A640000
09:56:11.5423D74209Initialize::GetLocation@ 0XFE6F2E80|-26268032
09:56:11.5423D74111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58C10000 <> 0X5A640000
09:56:11.5423D74209Initialize::GetLocation@ 0XFE6F7F80|-26247296
09:56:11.5423D74111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58C10000 <> 0X5A640000
09:56:11.5423D74209Initialize::GetLocation@ 0XFE6EE620|-26286560
09:56:11.5423D74111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X58C10000 <> 0X5A640000
09:56:11.5423D74209Initialize::GetLocation@ 0XFE5DAD10|-27415280
09:56:11.7263D7448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X359D0000>6|2|1203372419
09:56:11.7923D74129DXManager::DetectOK
09:56:11.8013D74186DXManager::DetectDone
09:56:11.8013D74215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
09:56:11.8023D74209Initialize::GetLocation@ 0X3AC00|240640
09:56:11.8023D74209Initialize::GetLocation@ 0X2C5B0|181680
09:56:11.8023D74209Initialize::GetLocation@ 0X36D00|224512
09:56:11.8023D74209Initialize::GetLocation@ 0XAE020|712736
09:56:11.8023D74209Initialize::GetLocation@ 0XADB70|711536
09:56:11.8023D74209Initialize::GetLocation@ 0X5880|22656
09:56:11.8023D74209Initialize::GetLocation@ 0XADC10|711696
09:56:11.8023D74209Initialize::GetLocation@ 0X20FF0|135152
09:56:11.8023D74209Initialize::GetLocation@ 0X1CA60|117344
09:56:11.8023D74209Initialize::GetLocation@ 0X1C8E0|116960
09:56:11.8023D74209Initialize::GetLocation@ 0X1084E0|1082592
09:56:11.8023D74209Initialize::GetLocation@ 0X107F90|1081232
09:56:11.8023D74209Initialize::GetLocation@ 0X248B0|149680
09:56:11.8023D74209Initialize::GetLocation@ 0X247A0|149408
09:56:11.8023D74209Initialize::GetLocation@ 0X2C440|181312
09:56:11.8023D74209Initialize::GetLocation@ 0X3F210|258576
09:56:11.8023D74209Initialize::GetLocation@ 0XF3E0|62432
09:56:11.8023D74209Initialize::GetLocation@ 0XF4E0|62688
09:56:11.8023D74209Initialize::GetLocation@ 0XF5D0|62928
09:56:11.8023D74209Initialize::GetLocation@ 0XF3E0|62432
09:56:11.8023D74209Initialize::GetLocation@ 0XF280|62080
09:56:11.8023D74209Initialize::GetLocation@ 0XF430|62512
09:56:11.8313D7448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X462A0000>6|2|1203372033
09:56:11.9103D7483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
09:56:11.9103D74209Initialize::GetLocation@ 0X3CC0|15552
09:56:11.9103D74209Initialize::GetLocation@ 0X5FD0|24528
09:56:11.9103D74209Initialize::GetLocation@ 0X6180|24960
09:56:11.9143D7448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X3C7F0000>6|2|1203372033
09:56:11.9213D7493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
09:56:11.9213D74110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
09:56:11.9213D74209Initialize::GetLocation@ 0X10000|65536
09:56:11.9213D74209Initialize::GetLocation@ 0X12C80|76928
09:56:11.9213D74209Initialize::GetLocation@ 0X12A60|76384
09:56:11.9733D74225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_11816 opened succesfuly
09:56:11.9733D7472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
09:56:11.9733D74256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_11816 close 2147483647 bytes
09:56:11.9733D74297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.155.0.10\OWExplorer.dll]
09:56:12.493D74385ftw1OWExplorer injected
09:56:12.571237C51`anonymous-namespace'::CreateProviderInitialize provider: NET
09:56:12.571237C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
09:56:12.571237C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
09:56:12.571237C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
09:58:42.811426C394ProcessInjector::HandleElevatedProcessFail injection to process [11612] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
09:58:42.811426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |11612|: MsMpEng.exe
09:58:43.810426C394ProcessInjector::HandleElevatedProcessFail injection to process [18748] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x5
09:58:43.810426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |18748|: lghub.exe
09:58:43.810426C394ProcessInjector::HandleElevatedProcessFail injection to process [20464] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x5
09:58:43.810426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |20464|: lghub.exe
09:58:51.808426C394ProcessInjector::HandleElevatedProcessFail injection to process [13984] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:51.808426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |13984|: Code.exe
09:58:52.807426C394ProcessInjector::HandleElevatedProcessFail injection to process [8152] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:52.807426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |8152|: Code.exe
09:58:52.807426C394ProcessInjector::HandleElevatedProcessFail injection to process [10208] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:52.807426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |10208|: Code.exe
09:58:55.807426C394ProcessInjector::HandleElevatedProcessFail injection to process [2660] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:55.807426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |2660|: Code.exe
09:58:55.807426C394ProcessInjector::HandleElevatedProcessFail injection to process [14968] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:55.807426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |14968|: Code.exe
09:58:56.807426C394ProcessInjector::HandleElevatedProcessFail injection to process [9804] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x5
09:58:56.807426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |9804|: bash.exe
09:58:56.807426C394ProcessInjector::HandleElevatedProcessFail injection to process [19624] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x5
09:58:56.807426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |19624|: bash.exe
09:58:59.809426C394ProcessInjector::HandleElevatedProcessFail injection to process [388] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:59.809426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |388|: Code.exe
09:58:59.809426C394ProcessInjector::HandleElevatedProcessFail injection to process [19324] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:58:59.809426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |19324|: Code.exe
09:59:01.808426C394ProcessInjector::HandleElevatedProcessFail injection to process [8668] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:59:01.808426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |8668|: Code.exe
09:59:01.808426C394ProcessInjector::HandleElevatedProcessFail injection to process [18872] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:59:01.808426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |18872|: Code.exe
09:59:01.808426C394ProcessInjector::HandleElevatedProcessFail injection to process [19696] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
09:59:01.808426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |19696|: Code.exe
09:59:26.803426C394ProcessInjector::HandleElevatedProcessFail injection to process [14668] [t: 0 w_t_id: 0]- DTShellHlp.exe (elevated True) 0x5
09:59:26.803426C333ProcessInjector::HandlePendingProccesssFail to inject pending process |14668|: DTShellHlp.exe
10:02:48.3353D7466ProcessesMonitor::Stopstopping PM...
10:02:48.335237C119ProcessesMonitor::ProcessEnumerateThreadexit process listener
10:02:54.3403D7466ProcessesMonitor::Stopstopping PM...