TimeThreadLineFunctionMessage
20:37:47.80725C8361ftw1Loading (pid: 15708)
20:37:47.80925C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XAB830000>6|2|1247871522
20:37:47.80925C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XADFF0000>6|2|1247871522
20:37:47.8164504146ProcessHardwareRecorder::CommandThreadstarting recorder thread
20:37:47.93225C8172DXManager::DetectFound in 0
20:37:47.93225C8209Initialize::GetLocation@ 0X4F80|20352
20:37:47.93225C8209Initialize::GetLocation@ 0X69640|431680
20:37:47.93225C8209Initialize::GetLocation@ 0X206F0|132848
20:37:47.93225C8209Initialize::GetLocation@ 0X1DE0|7648
20:37:47.93225C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XAB830000 <> 0XADFF0000
20:37:47.93225C8209Initialize::GetLocation@ 0XFD968860|-40466336
20:37:47.93225C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XAB830000 <> 0XADFF0000
20:37:47.93225C8209Initialize::GetLocation@ 0XFD96DC30|-40444880
20:37:47.93225C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XAB830000 <> 0XADFF0000
20:37:47.93225C8209Initialize::GetLocation@ 0XFD96C5F0|-40450576
20:37:47.93225C8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XAB830000 <> 0XADFF0000
20:37:47.93225C8209Initialize::GetLocation@ 0XFD84A7F0|-41637904
20:37:47.98725C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X8A060000>6|2|1247871522
20:37:48.5325C8129DXManager::DetectOK
20:37:48.6125C8186DXManager::DetectDone
20:37:48.6125C8215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
20:37:48.6225C8209Initialize::GetLocation@ 0X41060|266336
20:37:48.6225C8209Initialize::GetLocation@ 0X33320|209696
20:37:48.6225C8209Initialize::GetLocation@ 0X3CB90|248720
20:37:48.6225C8209Initialize::GetLocation@ 0XB75B0|751024
20:37:48.6225C8209Initialize::GetLocation@ 0XB7100|749824
20:37:48.6225C8209Initialize::GetLocation@ 0XA1F0|41456
20:37:48.6225C8209Initialize::GetLocation@ 0XB71A0|749984
20:37:48.6225C8209Initialize::GetLocation@ 0X1ABB0|109488
20:37:48.6225C8209Initialize::GetLocation@ 0X1D600|120320
20:37:48.6225C8209Initialize::GetLocation@ 0X25C30|154672
20:37:48.6225C8209Initialize::GetLocation@ 0X113820|1128480
20:37:48.6225C8209Initialize::GetLocation@ 0X1132E0|1127136
20:37:48.6225C8209Initialize::GetLocation@ 0X1AAA0|109216
20:37:48.6225C8209Initialize::GetLocation@ 0X1A9B0|108976
20:37:48.6225C8209Initialize::GetLocation@ 0XCB80|52096
20:37:48.6225C8209Initialize::GetLocation@ 0X47F90|294800
20:37:48.6225C8209Initialize::GetLocation@ 0X9D60|40288
20:37:48.6225C8209Initialize::GetLocation@ 0XCE7A0|845728
20:37:48.6225C8209Initialize::GetLocation@ 0XCEE70|847472
20:37:48.6225C8209Initialize::GetLocation@ 0X9D60|40288
20:37:48.6225C8209Initialize::GetLocation@ 0XCF960|850272
20:37:48.6225C8209Initialize::GetLocation@ 0XCFFC0|851904
20:37:48.7625C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X934D0000>6|2|1247870977
20:37:48.8825C883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
20:37:48.8825C8209Initialize::GetLocation@ 0X4040|16448
20:37:48.8825C8209Initialize::GetLocation@ 0X6410|25616
20:37:48.8825C8209Initialize::GetLocation@ 0X65C0|26048
20:37:48.9225C848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X85A50000>6|2|1247870977
20:37:48.11525C893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
20:37:48.11525C8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
20:37:48.11525C8209Initialize::GetLocation@ 0XA5D0|42448
20:37:48.11525C8209Initialize::GetLocation@ 0XD4D0|54480
20:37:48.11525C8209Initialize::GetLocation@ 0XD290|53904
20:37:48.18025C8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_15708 opened succesfuly
20:37:48.18025C872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
20:37:48.18125C8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_15708 close 2147483647 bytes
20:37:48.18125C8297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.157.0.16\OWExplorer.dll]
20:37:48.22725C8385ftw1OWExplorer injected
20:37:48.742300C51`anonymous-namespace'::CreateProviderInitialize provider: NET
20:37:48.742300C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
20:37:48.742300C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
20:37:48.742300C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
20:40:19.6898F4394ProcessInjector::HandleElevatedProcessFail injection to process [3860] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
20:40:19.6898F4333ProcessInjector::HandlePendingProccesssFail to inject pending process |3860|: MsMpEng.exe
20:40:19.6898F4394ProcessInjector::HandleElevatedProcessFail injection to process [18304] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0
20:40:19.6908F4333ProcessInjector::HandlePendingProccesssFail to inject pending process |18304|: lghub.exe
20:40:19.6908F4394ProcessInjector::HandleElevatedProcessFail injection to process [20176] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0
20:40:19.6908F4333ProcessInjector::HandlePendingProccesssFail to inject pending process |20176|: lghub.exe
20:40:45.9418F4394ProcessInjector::HandleElevatedProcessFail injection to process [5332] [t: 0 w_t_id: 0]- DTShellHlp.exe (elevated True) 0x0
20:40:45.9418F4333ProcessInjector::HandlePendingProccesssFail to inject pending process |5332|: DTShellHlp.exe
00:56:02.58725C866ProcessesMonitor::Stopstopping PM...
00:56:02.587300C119ProcessesMonitor::ProcessEnumerateThreadexit process listener