TimeThreadLineFunctionMessage
08:57:51.285290C365ftw1Loading (pid: 9524)
08:57:51.286290C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X278D0000>6|2|1203373348
08:57:51.287290C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X28C00000>6|2|1203373348
08:57:51.2932930147ProcessHardwareRecorder::CommandThreadstarting recorder thread
08:57:51.421290C172DXManager::DetectFound in 0
08:57:51.421290C209Initialize::GetLocation@ 0X4660|18016
08:57:51.421290C209Initialize::GetLocation@ 0X662B0|418480
08:57:51.421290C209Initialize::GetLocation@ 0X19DB0|105904
08:57:51.421290C209Initialize::GetLocation@ 0X1350|4944
08:57:51.421290C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X278D0000 <> 0X28C00000
08:57:51.421290C209Initialize::GetLocation@ 0XFEDF3020|-18927584
08:57:51.421290C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X278D0000 <> 0X28C00000
08:57:51.421290C209Initialize::GetLocation@ 0XFEDF8060|-18907040
08:57:51.421290C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X278D0000 <> 0X28C00000
08:57:51.421290C209Initialize::GetLocation@ 0XFEDEE620|-18946528
08:57:51.421290C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X278D0000 <> 0X28C00000
08:57:51.421290C209Initialize::GetLocation@ 0XFECDAA80|-20075904
08:57:51.455290C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XFD4C0000>6|2|1203373382
08:57:51.548290C129DXManager::DetectOK
08:57:51.583290C186DXManager::DetectDone
08:57:51.583290C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
08:57:51.584290C209Initialize::GetLocation@ 0X3AC00|240640
08:57:51.584290C209Initialize::GetLocation@ 0X2C5B0|181680
08:57:51.584290C209Initialize::GetLocation@ 0X36D00|224512
08:57:51.584290C209Initialize::GetLocation@ 0XAE030|712752
08:57:51.584290C209Initialize::GetLocation@ 0XADB80|711552
08:57:51.584290C209Initialize::GetLocation@ 0X5880|22656
08:57:51.584290C209Initialize::GetLocation@ 0XADC20|711712
08:57:51.584290C209Initialize::GetLocation@ 0X20FF0|135152
08:57:51.584290C209Initialize::GetLocation@ 0X1CA60|117344
08:57:51.584290C209Initialize::GetLocation@ 0X1C8E0|116960
08:57:51.584290C209Initialize::GetLocation@ 0X1084F0|1082608
08:57:51.584290C209Initialize::GetLocation@ 0X107FA0|1081248
08:57:51.584290C209Initialize::GetLocation@ 0X248B0|149680
08:57:51.584290C209Initialize::GetLocation@ 0X247A0|149408
08:57:51.584290C209Initialize::GetLocation@ 0X2C440|181312
08:57:51.584290C209Initialize::GetLocation@ 0X3F210|258576
08:57:51.584290C209Initialize::GetLocation@ 0XF3E0|62432
08:57:51.584290C209Initialize::GetLocation@ 0XF4E0|62688
08:57:51.584290C209Initialize::GetLocation@ 0XF5D0|62928
08:57:51.584290C209Initialize::GetLocation@ 0XF3E0|62432
08:57:51.584290C209Initialize::GetLocation@ 0XF280|62080
08:57:51.584290C209Initialize::GetLocation@ 0XF430|62512
08:57:51.645290C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XDC2F0000>6|2|1203372033
08:57:51.655290C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
08:57:51.655290C209Initialize::GetLocation@ 0X3CC0|15552
08:57:51.655290C209Initialize::GetLocation@ 0X5FD0|24528
08:57:51.655290C209Initialize::GetLocation@ 0X6180|24960
08:57:51.677290C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XDD110000>6|2|1203372033
08:57:51.685290C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
08:57:51.685290C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
08:57:51.685290C209Initialize::GetLocation@ 0X10000|65536
08:57:51.685290C209Initialize::GetLocation@ 0X12C80|76928
08:57:51.685290C209Initialize::GetLocation@ 0X12A60|76384
08:57:51.737290C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_9524 opened succesfuly
08:57:51.737290C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
08:57:51.737290C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_9524 close 2147483647 bytes
08:57:51.737290C301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.165.0.28\OWExplorer.dll]
08:57:51.773290C389ftw1OWExplorer injected
08:57:51.7872A3870Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
08:57:52.4632A3451`anonymous-namespace'::CreateProviderInitialize provider: NET
08:57:52.4632A34117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
08:57:52.4632A3454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
08:57:52.4632A3451`anonymous-namespace'::CreateProviderInitialize provider: GPU
08:57:52.4702A3C726ProcessInjector::InjectProcessprocess |mDNSResponder.exe| missing h
08:57:52.4702A3C726ProcessInjector::InjectProcessprocess |avp.exe| missing h
08:57:52.4702A3C726ProcessInjector::InjectProcessprocess |ijplmsvc.exe| missing h
08:57:52.4702A3C726ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
08:57:52.4702A3C726ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
08:57:52.8602A3C726ProcessInjector::InjectProcessprocess |OverwolfLauncher.exe| missing h
08:58:35.1632A3C726ProcessInjector::InjectProcessprocess |ksde.exe| missing h
08:59:36.1832A3C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
09:00:23.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [2340] [t: 0 w_t_id: 0]- mDNSResponder.exe (elevated True) 0x0
09:00:23.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |2340|: mDNSResponder.exe
09:00:23.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [2648] [t: 0 w_t_id: 0]- avp.exe (elevated True) 0x0
09:00:23.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |2648|: avp.exe
09:00:23.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [3132] [t: 0 w_t_id: 0]- ijplmsvc.exe (elevated True) 0x0
09:00:23.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |3132|: ijplmsvc.exe
09:00:23.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [7892] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
09:00:23.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |7892|: GoogleCrashHandler.exe
09:00:23.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [7944] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
09:00:23.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |7944|: GoogleCrashHandler64.exe
09:00:28.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [9396] [t: 0 w_t_id: 0]- googledrivesync.exe (elevated True) 0x0
09:00:28.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |9396|: googledrivesync.exe
09:00:34.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [6656] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
09:00:34.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |6656|: msedge.exe
09:00:34.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [10036] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
09:00:34.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |10036|: msedge.exe
09:00:34.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [10088] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
09:00:34.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |10088|: msedge.exe
09:00:36.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [3420] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
09:00:36.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |3420|: msedge.exe
09:00:36.1762A3C481ProcessInjector::HandleElevatedProcessFail injection to process [10784] [t: 0 w_t_id: 0]- msedge.exe (elevated True) 0x0
09:00:36.1762A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |10784|: msedge.exe
09:01:05.1872A3C481ProcessInjector::HandleElevatedProcessFail injection to process [2040] [t: 0 w_t_id: 0]- ksde.exe (elevated True) 0x0
09:01:05.1872A3C413ProcessInjector::HandlePendingProccesssFail to inject pending process |2040|: ksde.exe
09:02:45.2322A3C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:14:05.3282A3C726ProcessInjector::InjectProcessprocess |avp.exe| missing h
09:14:31.1192A3875Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
09:14:31.147290C66ProcessesMonitor::Stopstopping PM...
09:14:31.1472A34119ProcessesMonitor::ProcessEnumerateThreadexit process listener
09:14:31.148290C619ProcessInjector::Unhookunhook running process