TimeThreadLineFunctionMessage
18:30:50.5625B10365ftw1Loading (pid: 16464)
18:30:50.562240147ProcessHardwareRecorder::CommandThreadstarting recorder thread
18:30:50.5635B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X9D340000>6|2|1247871722
18:30:50.5645B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X9F9B0000>6|2|1247871904
18:30:50.6575B10172DXManager::DetectFound in 0
18:30:50.6575B10209Initialize::GetLocation@ 0X4F80|20352
18:30:50.6575B10209Initialize::GetLocation@ 0X69700|431872
18:30:50.6575B10209Initialize::GetLocation@ 0X206F0|132848
18:30:50.6575B10209Initialize::GetLocation@ 0X1DE0|7648
18:30:50.6575B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000
18:30:50.6575B10209Initialize::GetLocation@ 0XFDAB8860|-39090080
18:30:50.6575B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000
18:30:50.6575B10209Initialize::GetLocation@ 0XFDABDC30|-39068624
18:30:50.6575B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000
18:30:50.6575B10209Initialize::GetLocation@ 0XFDABC5F0|-39074320
18:30:50.6575B10111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X9D340000 <> 0X9F9B0000
18:30:50.6575B10209Initialize::GetLocation@ 0XFD99A7F0|-40261648
18:30:50.6685B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X73FB0000>6|2|1247871904
18:30:50.7495B10129DXManager::DetectOK
18:30:50.7935B10186DXManager::DetectDone
18:30:50.7935B10215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
18:30:50.7935B10209Initialize::GetLocation@ 0X41090|266384
18:30:50.7935B10209Initialize::GetLocation@ 0X33320|209696
18:30:50.7935B10209Initialize::GetLocation@ 0X3CBC0|248768
18:30:50.7935B10209Initialize::GetLocation@ 0XB76A0|751264
18:30:50.7935B10209Initialize::GetLocation@ 0XB71F0|750064
18:30:50.7935B10209Initialize::GetLocation@ 0XA1F0|41456
18:30:50.7935B10209Initialize::GetLocation@ 0XB7290|750224
18:30:50.7935B10209Initialize::GetLocation@ 0X1ABB0|109488
18:30:50.7935B10209Initialize::GetLocation@ 0X1D600|120320
18:30:50.7935B10209Initialize::GetLocation@ 0X25C30|154672
18:30:50.7935B10209Initialize::GetLocation@ 0X113920|1128736
18:30:50.7935B10209Initialize::GetLocation@ 0X1133E0|1127392
18:30:50.7935B10209Initialize::GetLocation@ 0X1AAA0|109216
18:30:50.7935B10209Initialize::GetLocation@ 0X1A9B0|108976
18:30:50.7935B10209Initialize::GetLocation@ 0XCB80|52096
18:30:50.7935B10209Initialize::GetLocation@ 0X48030|294960
18:30:50.7935B10209Initialize::GetLocation@ 0X9D60|40288
18:30:50.7935B10209Initialize::GetLocation@ 0XCE890|845968
18:30:50.7935B10209Initialize::GetLocation@ 0XCEF60|847712
18:30:50.7935B10209Initialize::GetLocation@ 0X9D60|40288
18:30:50.7935B10209Initialize::GetLocation@ 0XCFA50|850512
18:30:50.7935B10209Initialize::GetLocation@ 0XD00B0|852144
18:30:50.8045B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X6BDA0000>6|2|1247870977
18:30:50.9135B1083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
18:30:50.9145B10209Initialize::GetLocation@ 0X4040|16448
18:30:50.9145B10209Initialize::GetLocation@ 0X6410|25616
18:30:50.9145B10209Initialize::GetLocation@ 0X65C0|26048
18:30:50.9155B1048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X6BC00000>6|2|1247870977
18:30:50.9655B1093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
18:30:50.9655B10110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
18:30:50.9655B10209Initialize::GetLocation@ 0XA5D0|42448
18:30:50.9655B10209Initialize::GetLocation@ 0XD4D0|54480
18:30:50.9655B10209Initialize::GetLocation@ 0XD290|53904
18:30:51.235B10225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_14_16464 opened succesfuly
18:30:51.235B1072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
18:30:51.235B10256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_14_16464 close 2147483647 bytes
18:30:51.235B10301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.168.0.12\OWExplorer.dll]
18:30:51.245B10389ftw1OWExplorer injected
18:30:51.2429CC70Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
18:30:51.223550051`anonymous-namespace'::CreateProviderInitialize provider: NET
18:30:51.2235500117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
18:30:51.223550054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
18:30:51.223550051`anonymous-namespace'::CreateProviderInitialize provider: GPU
18:30:51.2363AFC646ProcessInjector::InjectProcessprocess |vmware-authd.exe| missing h
18:30:51.2363AFC646ProcessInjector::InjectProcessprocess |vmware-hostd.exe| missing h
18:30:51.2363AFC646ProcessInjector::InjectProcessprocess |sqlservr.exe| missing h
18:30:51.2363AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
18:30:51.5093AFC646ProcessInjector::InjectProcessprocess |parsecd.exe| missing h
18:30:51.7203AFC646ProcessInjector::InjectProcessprocess |com.docker.service| missing h
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [2356] [t: 0 w_t_id: 0]- docker.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |2356|: docker.exe
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [3968] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |3968|: com.docker.backend.exe
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [4500] [t: 0 w_t_id: 0]- vmware-authd.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |4500|: vmware-authd.exe
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [4532] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |4532|: nvcontainer.exe
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [6460] [t: 0 w_t_id: 0]- vmware-hostd.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |6460|: vmware-hostd.exe
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [7284] [t: 0 w_t_id: 0]- sqlservr.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |7284|: sqlservr.exe
18:33:22.1853AFC385ProcessInjector::HandleElevatedProcessFail injection to process [11228] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x0
18:33:22.1853AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |11228|: DropboxUpdate.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [11496] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |11496|: com.docker.service
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [12532] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |12532|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [13360] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |13360|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [13920] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |13920|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [14156] [t: 0 w_t_id: 0]- SnagPriv.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |14156|: SnagPriv.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [16108] [t: 0 w_t_id: 0]- com.docker.wsl-distro-proxy.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |16108|: com.docker.wsl-distro-proxy.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [17552] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |17552|: vpnkit.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [17868] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |17868|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [18832] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |18832|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [19744] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |19744|: vpnkit-bridge.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [20076] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |20076|: CCXProcess.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [20092] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |20092|: node.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [21284] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |21284|: com.docker.proxy.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [22132] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |22132|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [22764] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |22764|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [23692] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |23692|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [23704] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |23704|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [24064] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |24064|: Code.exe
18:33:22.1863AFC385ProcessInjector::HandleElevatedProcessFail injection to process [24484] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
18:33:22.1863AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |24484|: Code.exe
18:35:47.2023AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:55:01.7023AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
19:55:01.7293AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
20:55:01.8973AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
21:55:02.5463AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
22:14:03.2863AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
22:35:46.9343AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
22:35:47.9333AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
22:36:57.6873AFC646ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
22:37:06.7943AFC646ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
22:47:16.9513AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
22:47:16.9513AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
22:55:01.7473AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
07:31:33.2123AFC646ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
07:31:33.4843AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
07:31:33.4843AFC646ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
07:32:12.4883AFC646ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
07:32:17.5163AFC646ProcessInjector::InjectProcessprocess |MicrosoftEdge_X64_90.0.818.46_90.0.818.42.exe| missing h
07:32:30.6403AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
07:36:57.2923AFC646ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
07:55:01.9993AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
08:55:01.8963AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
09:55:02.4513AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
09:56:27.533AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:14:02.8593AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:55:01.9043AFC646ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
10:58:29.2823AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:58:30.2923AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
11:29:27.7393AFC385ProcessInjector::HandleElevatedProcessFail injection to process [5232] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
11:29:27.7393AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |5232|: Code.exe
11:29:28.7403AFC385ProcessInjector::HandleElevatedProcessFail injection to process [21028] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
11:29:28.7403AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |21028|: Code.exe
11:29:28.7403AFC385ProcessInjector::HandleElevatedProcessFail injection to process [22552] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
11:29:28.7403AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |22552|: Code.exe
11:29:29.7563AFC385ProcessInjector::HandleElevatedProcessFail injection to process [19724] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
11:29:29.7563AFC317ProcessInjector::HandlePendingProccesssFail to inject pending process |19724|: Code.exe
11:40:58.6953AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
11:41:03.7413AFC646ProcessInjector::InjectProcessprocess |owver64.exe| missing h
11:41:10.8023AFC646ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
11:41:10.8023AFC646ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
11:41:12.8123AFC646ProcessInjector::InjectProcessprocess |00020000000E6AF873CF50BC| missing h
11:41:12.8123AFC646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
11:41:18.97029CC75Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
11:41:19.3605B1066ProcessesMonitor::Stopstopping PM...
11:41:19.3605500119ProcessesMonitor::ProcessEnumerateThreadexit process listener
11:41:19.3625B10529ProcessInjector::Unhookunhook running process
11:41:25.3765B1066ProcessesMonitor::Stopstopping PM...