TimeThreadLineFunctionMessage
10:27:57.2517860365ftw1Loading (pid: 22100)
10:27:57.253786048Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X947A0000>6|2|1203373348
10:27:57.254786048Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X96240000>6|2|1203373348
10:27:57.4234010147ProcessHardwareRecorder::CommandThreadstarting recorder thread
10:27:58.9207860172DXManager::DetectFound in 0
10:27:58.9217860209Initialize::GetLocation@ 0X4660|18016
10:27:58.9217860209Initialize::GetLocation@ 0X662B0|418480
10:27:58.9217860209Initialize::GetLocation@ 0X19DB0|105904
10:27:58.9217860209Initialize::GetLocation@ 0X1350|4944
10:27:58.9217860111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X947A0000 <> 0X96240000
10:27:58.9217860209Initialize::GetLocation@ 0XFE683020|-26726368
10:27:58.9217860111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X947A0000 <> 0X96240000
10:27:58.9217860209Initialize::GetLocation@ 0XFE688060|-26705824
10:27:58.9217860111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X947A0000 <> 0X96240000
10:27:58.9217860209Initialize::GetLocation@ 0XFE67E620|-26745312
10:27:58.9217860111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X947A0000 <> 0X96240000
10:27:58.9217860209Initialize::GetLocation@ 0XFE56AA80|-27874688
10:27:59.717786048Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X5F6E0000>6|2|1203373142
10:28:00.3007860129DXManager::DetectOK
10:28:00.5067860186DXManager::DetectDone
10:28:00.5067860215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
10:28:00.5267860209Initialize::GetLocation@ 0X3AC00|240640
10:28:00.5267860209Initialize::GetLocation@ 0X2C5B0|181680
10:28:00.5267860209Initialize::GetLocation@ 0X36D00|224512
10:28:00.5267860209Initialize::GetLocation@ 0XAE210|713232
10:28:00.5267860209Initialize::GetLocation@ 0XADD60|712032
10:28:00.5267860209Initialize::GetLocation@ 0X5880|22656
10:28:00.5267860209Initialize::GetLocation@ 0XADE00|712192
10:28:00.5267860209Initialize::GetLocation@ 0X20FF0|135152
10:28:00.5267860209Initialize::GetLocation@ 0X1CA60|117344
10:28:00.5267860209Initialize::GetLocation@ 0X1C8E0|116960
10:28:00.5267860209Initialize::GetLocation@ 0X1086D0|1083088
10:28:00.5267860209Initialize::GetLocation@ 0X108180|1081728
10:28:00.5267860209Initialize::GetLocation@ 0X248B0|149680
10:28:00.5267860209Initialize::GetLocation@ 0X247A0|149408
10:28:00.5277860209Initialize::GetLocation@ 0X2C440|181312
10:28:00.5277860209Initialize::GetLocation@ 0X3F3F0|259056
10:28:00.5277860209Initialize::GetLocation@ 0XF3E0|62432
10:28:00.5277860209Initialize::GetLocation@ 0XF4E0|62688
10:28:00.5277860209Initialize::GetLocation@ 0XF5D0|62928
10:28:00.5277860209Initialize::GetLocation@ 0XF3E0|62432
10:28:00.5277860209Initialize::GetLocation@ 0XF280|62080
10:28:00.5277860209Initialize::GetLocation@ 0XF430|62512
10:28:00.573786048Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X42860000>6|2|1203372033
10:28:00.585786083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
10:28:00.5857860209Initialize::GetLocation@ 0X3CC0|15552
10:28:00.5857860209Initialize::GetLocation@ 0X5FD0|24528
10:28:00.5857860209Initialize::GetLocation@ 0X6180|24960
10:28:00.589786048Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X3F990000>6|2|1203372033
10:28:00.598786093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
10:28:00.5987860110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
10:28:00.5997860209Initialize::GetLocation@ 0X10000|65536
10:28:00.5997860209Initialize::GetLocation@ 0X12C80|76928
10:28:00.5997860209Initialize::GetLocation@ 0X12A60|76384
10:28:00.6517860225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_22100 opened succesfuly
10:28:00.651786072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
10:28:00.6517860256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_22100 close 2147483647 bytes
10:28:00.6517860301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.165.0.28\OWExplorer.dll]
10:28:00.6707860389ftw1OWExplorer injected
10:28:00.701103070Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
10:28:02.412424051`anonymous-namespace'::CreateProviderInitialize provider: NET
10:28:02.4134240117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
10:28:02.413424054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
10:28:02.413424051`anonymous-namespace'::CreateProviderInitialize provider: GPU
10:28:02.5257234726ProcessInjector::InjectProcessprocess |vpnagent.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |com.docker.service| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |nassvc.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |httpd.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |mysqld.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |httpd.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |tv_w32.exe| missing h
10:28:02.5257234726ProcessInjector::InjectProcessprocess |tv_x64.exe| missing h
10:29:03.3157234726ProcessInjector::InjectProcessprocess |CCUpdate.exe| missing h
10:29:03.3157234726ProcessInjector::InjectProcessprocess |VSIXAutoUpdate.exe| missing h
10:29:13.3377234726ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
10:29:29.3477234726ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
10:29:58.4267234726ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
10:30:02.4237234726ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [3172] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |3172|: vpnagent.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [4052] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |4052|: gameinputsvc.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [4060] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |4060|: com.docker.service
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [4164] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |4164|: nassvc.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [4196] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |4196|: httpd.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [4376] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |4376|: MsMpEng.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [4856] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |4856|: mysqld.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [5352] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |5352|: httpd.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [6264] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |6264|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [6712] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |6712|: Teams.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [7828] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |7828|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [10268] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |10268|: GoogleCrashHandler.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [10284] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |10284|: GoogleCrashHandler64.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [10584] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |10584|: Teams.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [12400] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |12400|: gameinputsvc.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [14464] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |14464|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [16360] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |16360|: rg.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [16756] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |16756|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [18268] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |18268|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [18340] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |18340|: tv_x64.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [19476] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |19476|: MicrosoftEdgeUpdate.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [19664] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |19664|: GoogleUpdate.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [19704] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |19704|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [20752] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |20752|: Teams.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [22932] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |22932|: DropboxUpdate.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [23712] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |23712|: Teams.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [23832] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |23832|: tv_w32.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [25476] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |25476|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [25980] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |25980|: rg.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [27072] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |27072|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [28556] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |28556|: Teams.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [28724] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |28724|: rg.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [29792] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |29792|: Code.exe
10:30:33.5017234481ProcessInjector::HandleElevatedProcessFail injection to process [31676] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:30:33.5017234413ProcessInjector::HandlePendingProccesssFail to inject pending process |31676|: rg.exe
10:30:41.5007234481ProcessInjector::HandleElevatedProcessFail injection to process [2768] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:30:41.5007234413ProcessInjector::HandlePendingProccesssFail to inject pending process |2768|: Code.exe
10:31:40.5067234481ProcessInjector::HandleElevatedProcessFail injection to process [10504] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x5
10:31:40.5067234413ProcessInjector::HandlePendingProccesssFail to inject pending process |10504|: com.docker.backend.exe
10:31:41.5067234481ProcessInjector::HandleElevatedProcessFail injection to process [24888] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x5
10:31:41.5067234413ProcessInjector::HandlePendingProccesssFail to inject pending process |24888|: docker-mutagen.exe
10:32:07.5757234481ProcessInjector::HandleElevatedProcessFail injection to process [16968] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x5
10:32:07.5757234413ProcessInjector::HandlePendingProccesssFail to inject pending process |16968|: vpnkit-bridge.exe
10:32:16.5777234481ProcessInjector::HandleElevatedProcessFail injection to process [30116] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x1f
10:32:16.5777234413ProcessInjector::HandlePendingProccesssFail to inject pending process |30116|: vpnkit.exe
10:32:19.5747234481ProcessInjector::HandleElevatedProcessFail injection to process [20668] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x1f
10:32:19.5747234413ProcessInjector::HandlePendingProccesssFail to inject pending process |20668|: com.docker.proxy.exe
10:32:25.5807234726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:33:03.6067234481ProcessInjector::HandleElevatedProcessFail injection to process [7620] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
10:33:03.6067234413ProcessInjector::HandlePendingProccesssFail to inject pending process |7620|: node.exe
10:33:03.6067234481ProcessInjector::HandleElevatedProcessFail injection to process [17344] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
10:33:03.6067234413ProcessInjector::HandlePendingProccesssFail to inject pending process |17344|: node.exe
10:38:38.1477234481ProcessInjector::HandleElevatedProcessFail injection to process [29428] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
10:38:38.1487234413ProcessInjector::HandlePendingProccesssFail to inject pending process |29428|: Teams.exe