TimeThreadLineFunctionMessage
17:15:48.3572F08361ftw1Loading (pid: 2528)
17:15:48.3582F0848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X9D660000>6|2|1164117043
17:15:48.3582F0848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X9F460000>6|2|1164117043
17:15:48.37542C8146ProcessHardwareRecorder::CommandThreadstarting recorder thread
17:15:48.4662F08172DXManager::DetectFound in 0
17:15:48.4662F08209Initialize::GetLocation@ 0X4910|18704
17:15:48.4662F08209Initialize::GetLocation@ 0X632A0|406176
17:15:48.4662F08209Initialize::GetLocation@ 0X1EF30|126768
17:15:48.4662F08209Initialize::GetLocation@ 0X1D70|7536
17:15:48.4662F08111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9D660000 <> 0X9F460000
17:15:48.4662F08209Initialize::GetLocation@ 0XFE32AB00|-30233856
17:15:48.4662F08111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9D660000 <> 0X9F460000
17:15:48.4662F08209Initialize::GetLocation@ 0XFE331400|-30206976
17:15:48.4662F08111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9D660000 <> 0X9F460000
17:15:48.4662F08209Initialize::GetLocation@ 0XFE326DE0|-30249504
17:15:48.4662F08111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9D660000 <> 0X9F460000
17:15:48.4662F08209Initialize::GetLocation@ 0XFE20E9B0|-31397456
17:15:48.4802F0848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X946D0000>6|2|1164117043
17:15:48.5662F08129DXManager::DetectOK
17:15:48.6102F08186DXManager::DetectDone
17:15:48.6102F08215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
17:15:48.6112F08209Initialize::GetLocation@ 0X3A0A0|237728
17:15:48.6112F08209Initialize::GetLocation@ 0X2DE30|187952
17:15:48.6112F08209Initialize::GetLocation@ 0X35CA0|220320
17:15:48.6112F08209Initialize::GetLocation@ 0XAA4C0|697536
17:15:48.6112F08209Initialize::GetLocation@ 0XAA010|696336
17:15:48.6112F08209Initialize::GetLocation@ 0X62B0|25264
17:15:48.6112F08209Initialize::GetLocation@ 0XAA0B0|696496
17:15:48.6112F08209Initialize::GetLocation@ 0X25E00|155136
17:15:48.6112F08209Initialize::GetLocation@ 0X1E290|123536
17:15:48.6112F08209Initialize::GetLocation@ 0X1E110|123152
17:15:48.6112F08209Initialize::GetLocation@ 0XEBA90|965264
17:15:48.6112F08209Initialize::GetLocation@ 0XEB540|963904
17:15:48.6112F08209Initialize::GetLocation@ 0X25F30|155440
17:15:48.6112F08209Initialize::GetLocation@ 0X25CF0|154864
17:15:48.6112F08209Initialize::GetLocation@ 0X2DCE0|187616
17:15:48.6112F08209Initialize::GetLocation@ 0X3D010|249872
17:15:48.6112F08209Initialize::GetLocation@ 0X10CD0|68816
17:15:48.6112F08209Initialize::GetLocation@ 0X10DD0|69072
17:15:48.6112F08209Initialize::GetLocation@ 0X10EC0|69312
17:15:48.6112F08209Initialize::GetLocation@ 0X10CD0|68816
17:15:48.6112F08209Initialize::GetLocation@ 0X10B70|68464
17:15:48.6112F08209Initialize::GetLocation@ 0X10D20|68896
17:15:48.6232F0848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X8D640000>6|2|1164115969
17:15:48.6332F0883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
17:15:48.6332F08209Initialize::GetLocation@ 0X3D10|15632
17:15:48.6332F08209Initialize::GetLocation@ 0X6130|24880
17:15:48.6332F08209Initialize::GetLocation@ 0X62E0|25312
17:15:48.6342F0848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X928D0000>6|2|1164115969
17:15:48.6412F0893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
17:15:48.6412F08110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
17:15:48.6412F08209Initialize::GetLocation@ 0X100B0|65712
17:15:48.6412F08209Initialize::GetLocation@ 0X12DE0|77280
17:15:48.6412F08209Initialize::GetLocation@ 0X12BB0|76720
17:15:48.6932F08225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_2528 opened succesfuly
17:15:48.6932F0872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
17:15:48.6932F08256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_2528 close 2147483647 bytes
17:15:48.6932F08297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.153.0.13\OWExplorer.dll]
17:15:48.6942F08385ftw1OWExplorer injected
17:15:48.9092C6851`anonymous-namespace'::CreateProviderInitialize provider: NET
17:15:48.9092C68117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
17:15:48.9092C6854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
17:15:48.9092C6851`anonymous-namespace'::CreateProviderInitialize provider: GPU
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [2452] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |2452|: NVDisplay.Container.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [2784] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |2784|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [3388] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |3388|: node.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [4432] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |4432|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [5024] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |5024|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [5252] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |5252|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [6360] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |6360|: nvcontainer.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [6912] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |6912|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [6924] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |6924|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [9152] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |9152|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [10856] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |10856|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [12448] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |12448|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [14636] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |14636|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [16516] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |16516|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [16540] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |16540|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [16596] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |16596|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [16900] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |16900|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [16916] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |16916|: Code.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [17504] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |17504|: CCXProcess.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [17576] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |17576|: NVDisplay.Container.exe
17:18:19.7062E8C394ProcessInjector::HandleElevatedProcessFail injection to process [19036] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
17:18:19.7062E8C333ProcessInjector::HandlePendingProccesssFail to inject pending process |19036|: Code.exe
18:14:21.6062F0866ProcessesMonitor::Stopstopping PM...
18:14:21.6062C68119ProcessesMonitor::ProcessEnumerateThreadexit process listener
18:14:27.6102F0866ProcessesMonitor::Stopstopping PM...