TimeThreadLineFunctionMessage
09:53:36.6473B10361ftw1Loading (pid: 14624)
09:53:36.6473C5C146ProcessHardwareRecorder::CommandThreadstarting recorder thread
09:53:36.6483B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X959A0000>6|2|1247871522
09:53:36.6483B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X983E0000>6|2|1247871522
09:53:36.7563B10172DXManager::DetectFound in 0
09:53:36.7563B10209Initialize::GetLocation@ 0X4F80|20352
09:53:36.7563B10209Initialize::GetLocation@ 0X69640|431680
09:53:36.7563B10209Initialize::GetLocation@ 0X206F0|132848
09:53:36.7563B10209Initialize::GetLocation@ 0X1DE0|7648
09:53:36.7563B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X959A0000 <> 0X983E0000
09:53:36.7563B10209Initialize::GetLocation@ 0XFD6E8860|-43087776
09:53:36.7563B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X959A0000 <> 0X983E0000
09:53:36.7563B10209Initialize::GetLocation@ 0XFD6EDC30|-43066320
09:53:36.7563B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X959A0000 <> 0X983E0000
09:53:36.7563B10209Initialize::GetLocation@ 0XFD6EC5F0|-43072016
09:53:36.7563B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X959A0000 <> 0X983E0000
09:53:36.7563B10209Initialize::GetLocation@ 0XFD5CA7F0|-44259344
09:53:36.7693B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X8F490000>6|2|1247871638
09:53:36.8463B10129DXManager::DetectOK
09:53:36.8803B10186DXManager::DetectDone
09:53:36.8803B10215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
09:53:36.8813B10209Initialize::GetLocation@ 0X41B90|269200
09:53:36.8813B10209Initialize::GetLocation@ 0X33E20|212512
09:53:36.8813B10209Initialize::GetLocation@ 0X3D6C0|251584
09:53:36.8813B10209Initialize::GetLocation@ 0XB8E10|757264
09:53:36.8813B10209Initialize::GetLocation@ 0XB8960|756064
09:53:36.8813B10209Initialize::GetLocation@ 0XACF0|44272
09:53:36.8813B10209Initialize::GetLocation@ 0XB8A00|756224
09:53:36.8813B10209Initialize::GetLocation@ 0X1B6B0|112304
09:53:36.8813B10209Initialize::GetLocation@ 0X1E100|123136
09:53:36.8813B10209Initialize::GetLocation@ 0X26730|157488
09:53:36.8813B10209Initialize::GetLocation@ 0X1146B0|1132208
09:53:36.8813B10209Initialize::GetLocation@ 0X114170|1130864
09:53:36.8813B10209Initialize::GetLocation@ 0X1B5A0|112032
09:53:36.8813B10209Initialize::GetLocation@ 0X1B4B0|111792
09:53:36.8813B10209Initialize::GetLocation@ 0XD680|54912
09:53:36.8813B10209Initialize::GetLocation@ 0X493C0|299968
09:53:36.8813B10209Initialize::GetLocation@ 0XA860|43104
09:53:36.8813B10209Initialize::GetLocation@ 0XD0000|851968
09:53:36.8813B10209Initialize::GetLocation@ 0XD06D0|853712
09:53:36.8813B10209Initialize::GetLocation@ 0XA860|43104
09:53:36.8813B10209Initialize::GetLocation@ 0XD11C0|856512
09:53:36.8813B10209Initialize::GetLocation@ 0XD1820|858144
09:53:36.8903B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X650F0000>6|2|1247870977
09:53:36.8973B1083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
09:53:36.8973B10209Initialize::GetLocation@ 0X4040|16448
09:53:36.8973B10209Initialize::GetLocation@ 0X6410|25616
09:53:36.8973B10209Initialize::GetLocation@ 0X65C0|26048
09:53:36.8973B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X5DD00000>6|2|1247870977
09:53:36.9033B1093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
09:53:36.9033B10110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
09:53:36.9033B10209Initialize::GetLocation@ 0XA5D0|42448
09:53:36.9033B10209Initialize::GetLocation@ 0XD4D0|54480
09:53:36.9033B10209Initialize::GetLocation@ 0XD290|53904
09:53:36.9583B10225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_14624 opened succesfuly
09:53:36.9583B1072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
09:53:36.9583B10256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_14624 close 2147483647 bytes
09:53:36.9593B10297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.31\OWExplorer.dll]
09:53:36.9913B10385ftw1OWExplorer injected
09:53:37.1153F5451`anonymous-namespace'::CreateProviderInitialize provider: NET
09:53:37.1153F54117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
09:53:37.1153F5454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
09:53:37.1153F5451`anonymous-namespace'::CreateProviderInitialize provider: GPU
09:53:37.2513F3C629ProcessInjector::InjectProcessprocess |CTAudSvc.exe| missing h
09:53:37.2513F3C629ProcessInjector::InjectProcessprocess |HeciServer.exe| missing h
09:53:37.3743F3C629ProcessInjector::InjectProcessprocess |Corsair.Service.CpuIdRemote64.exe| missing h
09:53:37.3743F3C629ProcessInjector::InjectProcessprocess |Corsair.Service.DisplayAdapter.exe| missing h
09:53:37.4963F3C629ProcessInjector::InjectProcessprocess |nvfvsdksvc_x64.exe| missing h
09:53:37.4963F3C629ProcessInjector::InjectProcessprocess |PresentMon_x64.exe| missing h
09:53:37.5583F3C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:54:13.3863F3C629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
09:54:13.3863F3C629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
09:54:15.4163F3C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:54:15.4163F3C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:55:14.223F3C629ProcessInjector::InjectProcessprocess |GCloud.exe| missing h
09:55:14.223F3C629ProcessInjector::InjectProcessprocess |LMS.exe| missing h
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [2096] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |2096|: NVDisplay.Container.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [4716] [t: 0 w_t_id: 0]- CTAudSvc.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4716|: CTAudSvc.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [5476] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5476|: nvcontainer.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [5980] [t: 0 w_t_id: 0]- HeciServer.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5980|: HeciServer.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [6436] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6436|: MsMpEng.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [10288] [t: 0 w_t_id: 0]- Corsair.Service.CpuIdRemote64.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |10288|: Corsair.Service.CpuIdRemote64.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [10724] [t: 0 w_t_id: 0]- Corsair.Service.DisplayAdapter.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |10724|: Corsair.Service.DisplayAdapter.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [12400] [t: 0 w_t_id: 0]- PresentMon_x64.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12400|: PresentMon_x64.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [12432] [t: 0 w_t_id: 0]- nvfvsdksvc_x64.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12432|: nvfvsdksvc_x64.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [13168] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13168|: NVIDIA Share.exe
09:56:09.6053F3C441ProcessInjector::HandleElevatedProcessFail injection to process [13276] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
09:56:09.6053F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13276|: NVIDIA Share.exe
09:57:44.5983F3C441ProcessInjector::HandleElevatedProcessFail injection to process [6128] [t: 0 w_t_id: 0]- GCloud.exe (elevated True) 0x0
09:57:44.5983F3C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6128|: GCloud.exe
09:58:35.1413F3C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:03:15.1383F3C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:03:15.1383F3C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:28:08.6383F3C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:29:42.7253F3C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
10:30:15.1223F3C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
11:15:14.9853B1066ProcessesMonitor::Stopstopping PM...
11:15:14.9853F54119ProcessesMonitor::ProcessEnumerateThreadexit process listener