TimeThreadLineFunctionMessage
08:52:43.95738E4365ftw1Loading (pid: 8976)
08:52:43.957524147ProcessHardwareRecorder::CommandThreadstarting recorder thread
08:52:43.96038E448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XDA190000>6|2|1203372419
08:52:43.96038E448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XDCC00000>6|2|1203373081
08:52:43.99238E4173DXManager::DetectFound in 0
08:52:43.99238E4209Initialize::GetLocation@ 0X4660|18016
08:52:43.99238E4209Initialize::GetLocation@ 0X661F0|418288
08:52:43.99238E4209Initialize::GetLocation@ 0X19DB0|105904
08:52:43.99238E4209Initialize::GetLocation@ 0X1350|4944
08:52:43.99238E4111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XDA190000 <> 0XDCC00000
08:52:43.99238E4209Initialize::GetLocation@ 0XFD6B2E80|-43307392
08:52:43.99238E4111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XDA190000 <> 0XDCC00000
08:52:43.99238E4209Initialize::GetLocation@ 0XFD6B7F80|-43286656
08:52:43.99238E4111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XDA190000 <> 0XDCC00000
08:52:43.99238E4209Initialize::GetLocation@ 0XFD6AE620|-43325920
08:52:43.99238E4111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XDA190000 <> 0XDCC00000
08:52:43.99238E4209Initialize::GetLocation@ 0XFD59AD10|-44454640
08:52:43.99838E448Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XBD1C0000>6|2|1203373142
08:52:44.4838E4129DXManager::DetectOK
08:52:44.5938E4186DXManager::DetectDone
08:52:44.5938E4215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
08:52:44.6038E4209Initialize::GetLocation@ 0X3AC00|240640
08:52:44.6038E4209Initialize::GetLocation@ 0X2C5B0|181680
08:52:44.6038E4209Initialize::GetLocation@ 0X36D00|224512
08:52:44.6038E4209Initialize::GetLocation@ 0XAE210|713232
08:52:44.6038E4209Initialize::GetLocation@ 0XADD60|712032
08:52:44.6038E4209Initialize::GetLocation@ 0X5880|22656
08:52:44.6038E4209Initialize::GetLocation@ 0XADE00|712192
08:52:44.6038E4209Initialize::GetLocation@ 0X20FF0|135152
08:52:44.6038E4209Initialize::GetLocation@ 0X1CA60|117344
08:52:44.6038E4209Initialize::GetLocation@ 0X1C8E0|116960
08:52:44.6038E4209Initialize::GetLocation@ 0X1086D0|1083088
08:52:44.6038E4209Initialize::GetLocation@ 0X108180|1081728
08:52:44.6038E4209Initialize::GetLocation@ 0X248B0|149680
08:52:44.6038E4209Initialize::GetLocation@ 0X247A0|149408
08:52:44.6038E4209Initialize::GetLocation@ 0X2C440|181312
08:52:44.6038E4209Initialize::GetLocation@ 0X3F3F0|259056
08:52:44.6038E4209Initialize::GetLocation@ 0XF3E0|62432
08:52:44.6038E4209Initialize::GetLocation@ 0XF4E0|62688
08:52:44.6038E4209Initialize::GetLocation@ 0XF5D0|62928
08:52:44.6038E4209Initialize::GetLocation@ 0XF3E0|62432
08:52:44.6038E4209Initialize::GetLocation@ 0XF280|62080
08:52:44.6038E4209Initialize::GetLocation@ 0XF430|62512
08:52:44.6938E448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XCA660000>6|2|1203372033
08:52:44.8538E483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
08:52:44.8638E4209Initialize::GetLocation@ 0X3CC0|15552
08:52:44.8638E4209Initialize::GetLocation@ 0X5FD0|24528
08:52:44.8638E4209Initialize::GetLocation@ 0X6180|24960
08:52:44.8738E448Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XCA610000>6|2|1203372033
08:52:44.10138E493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
08:52:44.10138E4110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
08:52:44.10138E4209Initialize::GetLocation@ 0X10000|65536
08:52:44.10138E4209Initialize::GetLocation@ 0X12C80|76928
08:52:44.10138E4209Initialize::GetLocation@ 0X12A60|76384
08:52:44.15338E4225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_173_4_8976 opened succesfuly
08:52:44.15338E472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
08:52:44.15338E4255InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_173_4_8976 close 2147483647 bytes
08:52:44.15338E4301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.173.0.14\OWExplorer.dll]
08:52:44.15538E4389ftw1OWExplorer injected
08:52:44.15549CC71Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
08:52:44.564551051`anonymous-namespace'::CreateProviderInitialize provider: NET
08:52:44.5645510117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
08:52:44.564551054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
08:52:44.564551051`anonymous-namespace'::CreateProviderInitialize provider: GPU
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fsatps.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fshoster32.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fshoster32.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |openvpnserv.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fsulprothoster.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fsorsp64.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |MicrosoftSearchInBing.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fshoster64.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fshoster64.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |client64.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |mysqld.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |com.docker.service| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fsatpl.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fsatpn.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |mysqld.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |fsdevcon.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
08:52:44.6243FA0669ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
08:52:44.8933FA0669ProcessInjector::InjectProcessprocess |FsPisces.exe| missing h
08:52:44.8933FA0669ProcessInjector::InjectProcessprocess |Microsoft.Management.Services.IntuneWindowsAgent.exe| missing h
08:52:44.8933FA0669ProcessInjector::InjectProcessprocess |MBAMAgent.exe| missing h
08:52:44.8933FA0669ProcessInjector::InjectProcessprocess |policyHost.exe| missing h
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [1464] [t: 0 w_t_id: 0]- Microsoft.Management.Services.IntuneWindowsAgent.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |1464|: Microsoft.Management.Services.IntuneWindowsAgent.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [3732] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |3732|: vpnkit.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [3864] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |3864|: Teams.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [4480] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |4480|: NVDisplay.Container.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [5268] [t: 0 w_t_id: 0]- fsulprothoster.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |5268|: fsulprothoster.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [5288] [t: 0 w_t_id: 0]- fsorsp64.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |5288|: fsorsp64.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [5772] [t: 0 w_t_id: 0]- MicrosoftSearchInBing.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |5772|: MicrosoftSearchInBing.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6060] [t: 0 w_t_id: 0]- fsatps.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6060|: fsatps.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6100] [t: 0 w_t_id: 0]- fshoster32.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6100|: fshoster32.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6116] [t: 0 w_t_id: 0]- fshoster32.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6116|: fshoster32.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6124] [t: 0 w_t_id: 0]- openvpnserv.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6124|: openvpnserv.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6240] [t: 0 w_t_id: 0]- fshoster64.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6240|: fshoster64.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6260] [t: 0 w_t_id: 0]- fshoster64.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6260|: fshoster64.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6268] [t: 0 w_t_id: 0]- client64.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6268|: client64.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6332] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6332|: com.docker.backend.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [6348] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |6348|: mysqld.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [7492] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |7492|: com.docker.service
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [7904] [t: 0 w_t_id: 0]- fsatpl.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |7904|: fsatpl.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [8120] [t: 0 w_t_id: 0]- fsatpn.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |8120|: fsatpn.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [8412] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |8412|: mysqld.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [8928] [t: 0 w_t_id: 0]- fsdevcon.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |8928|: fsdevcon.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [9244] [t: 0 w_t_id: 0]- python.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |9244|: python.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [11832] [t: 0 w_t_id: 0]- policyHost.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |11832|: policyHost.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [12540] [t: 0 w_t_id: 0]- python.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |12540|: python.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [13532] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |13532|: GoogleCrashHandler.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [13728] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |13728|: GoogleCrashHandler64.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [13824] [t: 0 w_t_id: 0]- FsPisces.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |13824|: FsPisces.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [15172] [t: 0 w_t_id: 0]- MBAMAgent.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |15172|: MBAMAgent.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [17484] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |17484|: Teams.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [18704] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |18704|: Teams.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [19400] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |19400|: Teams.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [22216] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |22216|: Teams.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [22840] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |22840|: com.docker.proxy.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [23160] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |23160|: vpnkit-bridge.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [23480] [t: 0 w_t_id: 0]- docker.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |23480|: docker.exe
08:55:15.4423FA0386ProcessInjector::HandleElevatedProcessFail injection to process [23864] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:55:15.4423FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |23864|: Teams.exe
08:57:40.9493FA0669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:12:47.2353FA0386ProcessInjector::HandleElevatedProcessFail injection to process [17008] [t: 0 w_t_id: 0]- VBCSCompiler.exe (elevated True) 0x0
09:12:47.2353FA0318ProcessInjector::HandlePendingProccesssFail to inject pending process |17008|: VBCSCompiler.exe
09:37:27.4233FA0669ProcessInjector::InjectProcessprocess |scanner64.exe| missing h
09:44:33.4113FA0669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h