TimeThreadLineFunctionMessage
14:15:14.3044158365ftw1Loading (pid: 12472)
14:15:14.304A6C147ProcessHardwareRecorder::CommandThreadstarting recorder thread
14:15:14.306415848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X87570000>6|2|1247871722
14:15:14.306415848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X89F70000>6|2|1247871940
14:15:14.3624158173DXManager::DetectFound in 0
14:15:14.3634158209Initialize::GetLocation@ 0X59E0|23008
14:15:14.3634158209Initialize::GetLocation@ 0X6AE20|437792
14:15:14.3634158209Initialize::GetLocation@ 0X211E0|135648
14:15:14.3634158209Initialize::GetLocation@ 0X2840|10304
14:15:14.3634158111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000
14:15:14.3634158209Initialize::GetLocation@ 0XFD728860|-42825632
14:15:14.3634158111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000
14:15:14.3634158209Initialize::GetLocation@ 0XFD72DC30|-42804176
14:15:14.3634158111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000
14:15:14.3634158209Initialize::GetLocation@ 0XFD72C5F0|-42809872
14:15:14.3634158111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X87570000 <> 0X89F70000
14:15:14.3634158209Initialize::GetLocation@ 0XFD60A7F0|-43997200
14:15:14.374415848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X4A340000>6|2|1247871904
14:15:14.4354158129DXManager::DetectOK
14:15:14.4724158186DXManager::DetectDone
14:15:14.4724158215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
14:15:14.4724158209Initialize::GetLocation@ 0X41090|266384
14:15:14.4724158209Initialize::GetLocation@ 0X33320|209696
14:15:14.4724158209Initialize::GetLocation@ 0X3CBC0|248768
14:15:14.4724158209Initialize::GetLocation@ 0XB76A0|751264
14:15:14.4724158209Initialize::GetLocation@ 0XB71F0|750064
14:15:14.4724158209Initialize::GetLocation@ 0XA1F0|41456
14:15:14.4724158209Initialize::GetLocation@ 0XB7290|750224
14:15:14.4724158209Initialize::GetLocation@ 0X1ABB0|109488
14:15:14.4724158209Initialize::GetLocation@ 0X1D600|120320
14:15:14.4724158209Initialize::GetLocation@ 0X25C30|154672
14:15:14.4724158209Initialize::GetLocation@ 0X113920|1128736
14:15:14.4724158209Initialize::GetLocation@ 0X1133E0|1127392
14:15:14.4724158209Initialize::GetLocation@ 0X1AAA0|109216
14:15:14.4724158209Initialize::GetLocation@ 0X1A9B0|108976
14:15:14.4724158209Initialize::GetLocation@ 0XCB80|52096
14:15:14.4724158209Initialize::GetLocation@ 0X48030|294960
14:15:14.4724158209Initialize::GetLocation@ 0X9D60|40288
14:15:14.4724158209Initialize::GetLocation@ 0XCE890|845968
14:15:14.4724158209Initialize::GetLocation@ 0XCEF60|847712
14:15:14.4724158209Initialize::GetLocation@ 0X9D60|40288
14:15:14.4724158209Initialize::GetLocation@ 0XCFA50|850512
14:15:14.4724158209Initialize::GetLocation@ 0XD00B0|852144
14:15:14.486415848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X2AD10000>6|2|1247870977
14:15:14.496415883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
14:15:14.4964158209Initialize::GetLocation@ 0X4040|16448
14:15:14.4964158209Initialize::GetLocation@ 0X6410|25616
14:15:14.4964158209Initialize::GetLocation@ 0X65C0|26048
14:15:14.497415848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X2ACC0000>6|2|1247870977
14:15:14.504415893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
14:15:14.5044158110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
14:15:14.5054158209Initialize::GetLocation@ 0XA5D0|42448
14:15:14.5054158209Initialize::GetLocation@ 0XD4D0|54480
14:15:14.5054158209Initialize::GetLocation@ 0XD290|53904
14:15:14.5584158225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_173_4_12472 opened succesfuly
14:15:14.558415872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
14:15:14.5584158255InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_173_4_12472 close 2147483647 bytes
14:15:14.5584158301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.173.0.16\OWExplorer.dll]
14:15:14.6194158389ftw1OWExplorer injected
14:15:14.61965471Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
14:15:15.66C851`anonymous-namespace'::CreateProviderInitialize provider: NET
14:15:15.66C8117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
14:15:15.66C854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
14:15:15.66C851`anonymous-namespace'::CreateProviderInitialize provider: GPU
14:15:15.79968669ProcessInjector::InjectProcessprocess |atkexComSvc.exe| missing h
14:15:15.79968669ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
14:15:15.79968669ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
14:15:15.79968669ProcessInjector::InjectProcessprocess |RtWLan.exe| missing h
14:15:15.203968669ProcessInjector::InjectProcessprocess |Aac3572MbHal_x86.exe| missing h
14:17:45.744968386ProcessInjector::HandleElevatedProcessFail injection to process [4188] [t: 0 w_t_id: 0]- atkexComSvc.exe (elevated True) 0x0
14:17:45.744968318ProcessInjector::HandlePendingProccesssFail to inject pending process |4188|: atkexComSvc.exe
14:17:45.744968386ProcessInjector::HandleElevatedProcessFail injection to process [4992] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
14:17:45.744968318ProcessInjector::HandlePendingProccesssFail to inject pending process |4992|: GoogleCrashHandler.exe
14:17:45.744968386ProcessInjector::HandleElevatedProcessFail injection to process [5016] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
14:17:45.744968318ProcessInjector::HandlePendingProccesssFail to inject pending process |5016|: GoogleCrashHandler64.exe
14:17:45.744968386ProcessInjector::HandleElevatedProcessFail injection to process [9660] [t: 0 w_t_id: 0]- Aac3572MbHal_x86.exe (elevated True) 0x0
14:17:45.744968318ProcessInjector::HandlePendingProccesssFail to inject pending process |9660|: Aac3572MbHal_x86.exe
14:19:42.671968386ProcessInjector::HandleElevatedProcessFail injection to process [17388] [t: 0 w_t_id: 0]- curseforge.exe (elevated True) 0x0
14:19:42.671968318ProcessInjector::HandlePendingProccesssFail to inject pending process |17388|: curseforge.exe
14:20:09.929968669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
14:20:41.197968669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
14:20:41.197968669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |AsusUpdate.exe| missing h
14:20:43.214968669ProcessInjector::InjectProcessprocess |Get-AppxVersion.exe| missing h
14:20:52.263968669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
14:20:55.278968669ProcessInjector::InjectProcessprocess |MicrosoftEdge_X64_91.0.864.64_91.0.864.59.exe| missing h
14:21:05.322968669ProcessInjector::InjectProcessprocess |setup.exe| missing h
14:21:05.322968669ProcessInjector::InjectProcessprocess |setup.exe| missing h
14:21:06.327968669ProcessInjector::InjectProcessprocess |MicrosoftEdge_X64_91.0.864.64_91.0.864.59.exe| missing h
14:21:07.333968669ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
14:21:41.587968386ProcessInjector::HandleElevatedProcessFail injection to process [9752] [t: 0 w_t_id: 0]- Bitwarden.exe (elevated True) 0x578
14:21:41.587968318ProcessInjector::HandlePendingProccesssFail to inject pending process |9752|: Bitwarden.exe
14:21:41.587968386ProcessInjector::HandleElevatedProcessFail injection to process [17488] [t: 0 w_t_id: 0]- Bitwarden.exe (elevated True) 0x578
14:21:41.587968318ProcessInjector::HandlePendingProccesssFail to inject pending process |17488|: Bitwarden.exe
14:23:13.330968386ProcessInjector::HandleElevatedProcessFail injection to process [10044] [t: 0 w_t_id: 0]- AsusUpdate.exe (elevated True) 0x578
14:23:13.330968318ProcessInjector::HandlePendingProccesssFail to inject pending process |10044|: AsusUpdate.exe
14:23:13.330968386ProcessInjector::HandleElevatedProcessFail injection to process [10860] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x578
14:23:13.330968318ProcessInjector::HandlePendingProccesssFail to inject pending process |10860|: GoogleUpdate.exe
14:23:13.330968386ProcessInjector::HandleElevatedProcessFail injection to process [14508] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x578
14:23:13.330968318ProcessInjector::HandlePendingProccesssFail to inject pending process |14508|: MicrosoftEdgeUpdate.exe
15:46:14.814968669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:50:21.16968386ProcessInjector::HandleElevatedProcessFail injection to process [12236] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x578
15:50:21.16968318ProcessInjector::HandlePendingProccesssFail to inject pending process |12236|: GameBarFTServer.exe
16:07:14.1968386ProcessInjector::HandleElevatedProcessFail injection to process [14276] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x578
16:07:14.1968318ProcessInjector::HandlePendingProccesssFail to inject pending process |14276|: GameBarFTServer.exe
16:20:08.594968386ProcessInjector::HandleElevatedProcessFail injection to process [20344] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x0
16:20:08.594968318ProcessInjector::HandlePendingProccesssFail to inject pending process |20344|: GameBarFTServer.exe
17:10:49.782968386ProcessInjector::HandleElevatedProcessFail injection to process [16512] [t: 0 w_t_id: 0]- GameBarFTServer.exe (elevated True) 0x0
17:10:49.783968318ProcessInjector::HandlePendingProccesssFail to inject pending process |16512|: GameBarFTServer.exe
18:20:10.750968669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:20:11.750968669ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
19:18:37.12165476Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
19:18:37.181415866ProcessesMonitor::Stopstopping PM...
19:18:37.1816C8119ProcessesMonitor::ProcessEnumerateThreadexit process listener
19:18:37.1994158527ProcessInjector::Unhookunhook running process