TimeThreadLineFunctionMessage
16:54:46.6983EB0361ftw1Loading (pid: 13552)
16:54:46.6983B30146ProcessHardwareRecorder::CommandThreadstarting recorder thread
16:54:46.6993EB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X2A060000>6|2|1247871522
16:54:46.6993EB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X2C9C0000>6|2|1247871522
16:54:46.7923EB0172DXManager::DetectFound in 0
16:54:46.7933EB0209Initialize::GetLocation@ 0X4F80|20352
16:54:46.7933EB0209Initialize::GetLocation@ 0X69640|431680
16:54:46.7933EB0209Initialize::GetLocation@ 0X206F0|132848
16:54:46.7933EB0209Initialize::GetLocation@ 0X1DE0|7648
16:54:46.7933EB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2A060000 <> 0X2C9C0000
16:54:46.7933EB0209Initialize::GetLocation@ 0XFD7C8860|-42170272
16:54:46.7933EB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2A060000 <> 0X2C9C0000
16:54:46.7933EB0209Initialize::GetLocation@ 0XFD7CDC30|-42148816
16:54:46.7933EB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2A060000 <> 0X2C9C0000
16:54:46.7933EB0209Initialize::GetLocation@ 0XFD7CC5F0|-42154512
16:54:46.7933EB0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X2A060000 <> 0X2C9C0000
16:54:46.7933EB0209Initialize::GetLocation@ 0XFD6AA7F0|-43341840
16:54:46.8023EB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X229C0000>6|2|1247871638
16:54:46.8953EB0129DXManager::DetectOK
16:54:46.9243EB0186DXManager::DetectDone
16:54:46.9243EB0215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
16:54:46.9243EB0209Initialize::GetLocation@ 0X41B90|269200
16:54:46.9243EB0209Initialize::GetLocation@ 0X33E20|212512
16:54:46.9243EB0209Initialize::GetLocation@ 0X3D6C0|251584
16:54:46.9243EB0209Initialize::GetLocation@ 0XB8E10|757264
16:54:46.9243EB0209Initialize::GetLocation@ 0XB8960|756064
16:54:46.9243EB0209Initialize::GetLocation@ 0XACF0|44272
16:54:46.9243EB0209Initialize::GetLocation@ 0XB8A00|756224
16:54:46.9243EB0209Initialize::GetLocation@ 0X1B6B0|112304
16:54:46.9243EB0209Initialize::GetLocation@ 0X1E100|123136
16:54:46.9243EB0209Initialize::GetLocation@ 0X26730|157488
16:54:46.9243EB0209Initialize::GetLocation@ 0X1146B0|1132208
16:54:46.9243EB0209Initialize::GetLocation@ 0X114170|1130864
16:54:46.9243EB0209Initialize::GetLocation@ 0X1B5A0|112032
16:54:46.9243EB0209Initialize::GetLocation@ 0X1B4B0|111792
16:54:46.9243EB0209Initialize::GetLocation@ 0XD680|54912
16:54:46.9243EB0209Initialize::GetLocation@ 0X493C0|299968
16:54:46.9243EB0209Initialize::GetLocation@ 0XA860|43104
16:54:46.9243EB0209Initialize::GetLocation@ 0XD0000|851968
16:54:46.9243EB0209Initialize::GetLocation@ 0XD06D0|853712
16:54:46.9243EB0209Initialize::GetLocation@ 0XA860|43104
16:54:46.9243EB0209Initialize::GetLocation@ 0XD11C0|856512
16:54:46.9243EB0209Initialize::GetLocation@ 0XD1820|858144
16:54:46.9343EB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XF3540000>6|2|1247870977
16:54:46.9443EB083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
16:54:46.9443EB0209Initialize::GetLocation@ 0X4040|16448
16:54:46.9443EB0209Initialize::GetLocation@ 0X6410|25616
16:54:46.9443EB0209Initialize::GetLocation@ 0X65C0|26048
16:54:46.9463EB048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XF0190000>6|2|1247870977
16:54:46.9523EB093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
16:54:46.9523EB0110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
16:54:46.9523EB0209Initialize::GetLocation@ 0XA5D0|42448
16:54:46.9523EB0209Initialize::GetLocation@ 0XD4D0|54480
16:54:46.9523EB0209Initialize::GetLocation@ 0XD290|53904
16:54:47.163EB0225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_4_13552 opened succesfuly
16:54:47.163EB072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
16:54:47.163EB0256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_4_13552 close 2147483647 bytes
16:54:47.163EB0297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.21\OWExplorer.dll]
16:54:47.503EB0385ftw1OWExplorer injected
16:54:47.16532BC51`anonymous-namespace'::CreateProviderInitialize provider: NET
16:54:47.16532BC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
16:54:47.16532BC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
16:54:47.16532BC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
16:54:47.2923E7C629ProcessInjector::InjectProcessprocess |CTAudSvc.exe| missing h
16:54:47.2923E7C629ProcessInjector::InjectProcessprocess |HeciServer.exe| missing h
16:54:47.4153E7C629ProcessInjector::InjectProcessprocess |Corsair.Service.CpuIdRemote64.exe| missing h
16:54:47.4153E7C629ProcessInjector::InjectProcessprocess |Corsair.Service.DisplayAdapter.exe| missing h
16:54:47.5383E7C629ProcessInjector::InjectProcessprocess |nvfvsdksvc_x64.exe| missing h
16:54:47.5383E7C629ProcessInjector::InjectProcessprocess |PresentMon_x64.exe| missing h
16:54:47.6003E7C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:56:22.563E7C629ProcessInjector::InjectProcessprocess |GCloud.exe| missing h
16:56:22.563E7C629ProcessInjector::InjectProcessprocess |LMS.exe| missing h
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [2128] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |2128|: NVDisplay.Container.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [3992] [t: 0 w_t_id: 0]- PresentMon_x64.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3992|: PresentMon_x64.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [4824] [t: 0 w_t_id: 0]- CTAudSvc.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4824|: CTAudSvc.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [5248] [t: 0 w_t_id: 0]- HeciServer.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |5248|: HeciServer.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [6216] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6216|: nvcontainer.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [6452] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6452|: MsMpEng.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [10412] [t: 0 w_t_id: 0]- Corsair.Service.CpuIdRemote64.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |10412|: Corsair.Service.CpuIdRemote64.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [10612] [t: 0 w_t_id: 0]- Corsair.Service.DisplayAdapter.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |10612|: Corsair.Service.DisplayAdapter.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [12328] [t: 0 w_t_id: 0]- nvfvsdksvc_x64.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12328|: nvfvsdksvc_x64.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [12664] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12664|: NVIDIA Share.exe
16:57:17.7003E7C441ProcessInjector::HandleElevatedProcessFail injection to process [12760] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
16:57:17.7003E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12760|: NVIDIA Share.exe
16:58:52.7553E7C441ProcessInjector::HandleElevatedProcessFail injection to process [13576] [t: 0 w_t_id: 0]- GCloud.exe (elevated True) 0x0
16:58:52.7553E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13576|: GCloud.exe
16:59:41.3303E7C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:00:18.7713E7C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
17:02:49.6203E7C441ProcessInjector::HandleElevatedProcessFail injection to process [17440] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
17:02:49.6203E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |17440|: MicrosoftEdgeUpdate.exe
17:04:22.6323E7C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:04:23.6473E7C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:04:23.6473E7C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:11:31.7413E7C441ProcessInjector::HandleElevatedProcessFail injection to process [3840] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:11:31.7413E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |3840|: Streamlabs OBS.exe
17:11:31.7413E7C441ProcessInjector::HandleElevatedProcessFail injection to process [13380] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:11:31.7413E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |13380|: Streamlabs OBS.exe
17:11:31.7413E7C441ProcessInjector::HandleElevatedProcessFail injection to process [14944] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:11:31.7413E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |14944|: Streamlabs OBS.exe
17:11:31.7413E7C441ProcessInjector::HandleElevatedProcessFail injection to process [17884] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:11:31.7413E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |17884|: Streamlabs OBS.exe
17:11:31.7413E7C441ProcessInjector::HandleElevatedProcessFail injection to process [17948] [t: 0 w_t_id: 0]- crash-handler-process.exe (elevated True) 0x0
17:11:31.7413E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |17948|: crash-handler-process.exe
17:11:33.7713E7C441ProcessInjector::HandleElevatedProcessFail injection to process [14104] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:11:33.7713E7C380ProcessInjector::HandlePendingProccesssFail to inject pending process |14104|: Streamlabs OBS.exe
17:26:03.9143E7C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:26:03.9143E7C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:26:03.9143E7C629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:26:56.6643EB066ProcessesMonitor::Stopstopping PM...
17:26:56.66432BC119ProcessesMonitor::ProcessEnumerateThreadexit process listener