TimeThreadLineFunctionMessage
20:03:34.4603F2C361ftw1Loading (pid: 9976)
20:03:34.4611B28146ProcessHardwareRecorder::CommandThreadstarting recorder thread
20:03:34.4613F2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X8F1E0000>6|2|1247871522
20:03:34.4613F2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X91C20000>6|2|1247871522
20:03:34.5883F2C172DXManager::DetectFound in 0
20:03:34.5893F2C209Initialize::GetLocation@ 0X4F80|20352
20:03:34.5893F2C209Initialize::GetLocation@ 0X69640|431680
20:03:34.5893F2C209Initialize::GetLocation@ 0X206F0|132848
20:03:34.5893F2C209Initialize::GetLocation@ 0X1DE0|7648
20:03:34.5893F2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8F1E0000 <> 0X91C20000
20:03:34.5893F2C209Initialize::GetLocation@ 0XFD6E8860|-43087776
20:03:34.5893F2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8F1E0000 <> 0X91C20000
20:03:34.5893F2C209Initialize::GetLocation@ 0XFD6EDC30|-43066320
20:03:34.5893F2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8F1E0000 <> 0X91C20000
20:03:34.5893F2C209Initialize::GetLocation@ 0XFD6EC5F0|-43072016
20:03:34.5893F2C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X8F1E0000 <> 0X91C20000
20:03:34.5893F2C209Initialize::GetLocation@ 0XFD5CA7F0|-44259344
20:03:34.6013F2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X88A50000>6|2|1247871638
20:03:34.6993F2C129DXManager::DetectOK
20:03:34.7323F2C186DXManager::DetectDone
20:03:34.7323F2C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
20:03:34.7333F2C209Initialize::GetLocation@ 0X41B90|269200
20:03:34.7333F2C209Initialize::GetLocation@ 0X33E20|212512
20:03:34.7333F2C209Initialize::GetLocation@ 0X3D6C0|251584
20:03:34.7333F2C209Initialize::GetLocation@ 0XB8E10|757264
20:03:34.7333F2C209Initialize::GetLocation@ 0XB8960|756064
20:03:34.7333F2C209Initialize::GetLocation@ 0XACF0|44272
20:03:34.7333F2C209Initialize::GetLocation@ 0XB8A00|756224
20:03:34.7333F2C209Initialize::GetLocation@ 0X1B6B0|112304
20:03:34.7333F2C209Initialize::GetLocation@ 0X1E100|123136
20:03:34.7333F2C209Initialize::GetLocation@ 0X26730|157488
20:03:34.7333F2C209Initialize::GetLocation@ 0X1146B0|1132208
20:03:34.7333F2C209Initialize::GetLocation@ 0X114170|1130864
20:03:34.7333F2C209Initialize::GetLocation@ 0X1B5A0|112032
20:03:34.7333F2C209Initialize::GetLocation@ 0X1B4B0|111792
20:03:34.7333F2C209Initialize::GetLocation@ 0XD680|54912
20:03:34.7333F2C209Initialize::GetLocation@ 0X493C0|299968
20:03:34.7333F2C209Initialize::GetLocation@ 0XA860|43104
20:03:34.7333F2C209Initialize::GetLocation@ 0XD0000|851968
20:03:34.7333F2C209Initialize::GetLocation@ 0XD06D0|853712
20:03:34.7333F2C209Initialize::GetLocation@ 0XA860|43104
20:03:34.7333F2C209Initialize::GetLocation@ 0XD11C0|856512
20:03:34.7333F2C209Initialize::GetLocation@ 0XD1820|858144
20:03:34.7433F2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X7C1B0000>6|2|1247870977
20:03:34.7503F2C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
20:03:34.7513F2C209Initialize::GetLocation@ 0X4040|16448
20:03:34.7513F2C209Initialize::GetLocation@ 0X6410|25616
20:03:34.7513F2C209Initialize::GetLocation@ 0X65C0|26048
20:03:34.7513F2C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X6E9D0000>6|2|1247870977
20:03:34.7563F2C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
20:03:34.7563F2C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
20:03:34.7563F2C209Initialize::GetLocation@ 0XA5D0|42448
20:03:34.7563F2C209Initialize::GetLocation@ 0XD4D0|54480
20:03:34.7563F2C209Initialize::GetLocation@ 0XD290|53904
20:03:34.8263F2C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_9976 opened succesfuly
20:03:34.8263F2C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
20:03:34.8263F2C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_9976 close 2147483647 bytes
20:03:34.8263F2C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.31\OWExplorer.dll]
20:03:34.8553F2C385ftw1OWExplorer injected
20:03:34.9913FAC51`anonymous-namespace'::CreateProviderInitialize provider: NET
20:03:34.9913FAC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
20:03:34.9913FAC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
20:03:34.9913FAC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
20:03:35.563E4C629ProcessInjector::InjectProcessprocess |CTAudSvc.exe| missing h
20:03:35.563E4C629ProcessInjector::InjectProcessprocess |HeciServer.exe| missing h
20:03:35.2563E4C629ProcessInjector::InjectProcessprocess |Corsair.Service.CpuIdRemote64.exe| missing h
20:03:35.2563E4C629ProcessInjector::InjectProcessprocess |Corsair.Service.DisplayAdapter.exe| missing h
20:03:35.3793E4C629ProcessInjector::InjectProcessprocess |nvfvsdksvc_x64.exe| missing h
20:03:35.3793E4C629ProcessInjector::InjectProcessprocess |PresentMon_x64.exe| missing h
20:03:35.4413E4C629ProcessInjector::InjectProcessprocess |GCloud.exe| missing h
20:03:35.4413E4C468ProcessInjector::DoElevetedInjectionFailed to inject process [3108] 0x57
20:03:35.4413E4C424ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [3108] [t: 9404 w_t_id: 9404]- OverwolfLauncher.exe (elevated True) 0x57
20:03:35.4413E4C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
20:03:35.8713E4C468ProcessInjector::DoElevetedInjectionFailed to inject process [3108] 0x57
20:03:35.8713E4C441ProcessInjector::HandleElevatedProcessFail injection to process [3108] [t: 9404 w_t_id: 9404]- OverwolfLauncher.exe (elevated True) 0x57
20:03:35.8713E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3108|: OverwolfLauncher.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [2112] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |2112|: NVDisplay.Container.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [3796] [t: 0 w_t_id: 0]- HeciServer.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3796|: HeciServer.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [4112] [t: 0 w_t_id: 0]- CTAudSvc.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4112|: CTAudSvc.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [5244] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5244|: nvcontainer.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [5528] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5528|: MsMpEng.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [9896] [t: 0 w_t_id: 0]- Corsair.Service.DisplayAdapter.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |9896|: Corsair.Service.DisplayAdapter.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [9916] [t: 0 w_t_id: 0]- Corsair.Service.CpuIdRemote64.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |9916|: Corsair.Service.CpuIdRemote64.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [11988] [t: 0 w_t_id: 0]- GCloud.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |11988|: GCloud.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [12312] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12312|: NVIDIA Share.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [12392] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12392|: NVIDIA Share.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [12576] [t: 0 w_t_id: 0]- nvfvsdksvc_x64.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12576|: nvfvsdksvc_x64.exe
20:06:05.6493E4C441ProcessInjector::HandleElevatedProcessFail injection to process [12624] [t: 0 w_t_id: 0]- PresentMon_x64.exe (elevated True) 0x1f
20:06:05.6493E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12624|: PresentMon_x64.exe
20:08:24.813E4C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:33:16.5133E4C441ProcessInjector::HandleElevatedProcessFail injection to process [2628] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:33:16.5143E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |2628|: Streamlabs OBS.exe
21:33:16.5143E4C441ProcessInjector::HandleElevatedProcessFail injection to process [3512] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:33:16.5173E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3512|: Streamlabs OBS.exe
21:33:16.5173E4C441ProcessInjector::HandleElevatedProcessFail injection to process [12680] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:33:16.5173E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12680|: Streamlabs OBS.exe
21:33:16.5173E4C441ProcessInjector::HandleElevatedProcessFail injection to process [16284] [t: 0 w_t_id: 0]- crash-handler-process.exe (elevated True) 0x0
21:33:16.5173E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |16284|: crash-handler-process.exe
21:33:16.5173E4C441ProcessInjector::HandleElevatedProcessFail injection to process [17512] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:33:16.5173E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |17512|: Streamlabs OBS.exe
21:33:39.8313E4C441ProcessInjector::HandleElevatedProcessFail injection to process [15136] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:33:39.8313E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |15136|: Streamlabs OBS.exe
21:35:01.2153E4C441ProcessInjector::HandleElevatedProcessFail injection to process [10256] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:35:01.2153E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |10256|: Streamlabs OBS.exe
21:35:05.2583E4C441ProcessInjector::HandleElevatedProcessFail injection to process [6948] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
21:35:05.2583E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6948|: Streamlabs OBS.exe
22:28:09.2943E4C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
22:28:12.3143E4C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
22:29:42.6463E4C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
23:52:37.3293E4C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
23:52:38.7523E4C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
23:55:17.6353E4C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
00:08:25.8253E4C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
00:08:26.8293E4C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
00:16:16.8053F2C66ProcessesMonitor::Stopstopping PM...
00:16:16.8053FAC119ProcessesMonitor::ProcessEnumerateThreadexit process listener