TimeThreadLineFunctionMessage
08:33:38.6195B8361ftw1Loading (pid: 17000)
08:33:38.619275C146ProcessHardwareRecorder::CommandThreadstarting recorder thread
08:33:38.6205B848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X4D980000>6|2|1164117043
08:33:38.6205B848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X4F650000>6|2|1164117043
08:33:38.6885B8172DXManager::DetectFound in 0
08:33:38.6895B8209Initialize::GetLocation@ 0X4910|18704
08:33:38.6895B8209Initialize::GetLocation@ 0X632A0|406176
08:33:38.6895B8209Initialize::GetLocation@ 0X1EF30|126768
08:33:38.6895B8209Initialize::GetLocation@ 0X1D70|7536
08:33:38.6895B8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X4D980000 <> 0X4F650000
08:33:38.6895B8209Initialize::GetLocation@ 0XFE45AB00|-28988672
08:33:38.6895B8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X4D980000 <> 0X4F650000
08:33:38.6895B8209Initialize::GetLocation@ 0XFE461400|-28961792
08:33:38.6895B8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X4D980000 <> 0X4F650000
08:33:38.6895B8209Initialize::GetLocation@ 0XFE456DE0|-29004320
08:33:38.6895B8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X4D980000 <> 0X4F650000
08:33:38.6895B8209Initialize::GetLocation@ 0XFE33E9B0|-30152272
08:33:38.7025B848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X47EE0000>6|2|1164117043
08:33:38.7915B8129DXManager::DetectOK
08:33:38.8245B8186DXManager::DetectDone
08:33:38.8245B8215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
08:33:38.8245B8209Initialize::GetLocation@ 0X3A0A0|237728
08:33:38.8245B8209Initialize::GetLocation@ 0X2DE30|187952
08:33:38.8245B8209Initialize::GetLocation@ 0X35CA0|220320
08:33:38.8245B8209Initialize::GetLocation@ 0XAA4C0|697536
08:33:38.8245B8209Initialize::GetLocation@ 0XAA010|696336
08:33:38.8245B8209Initialize::GetLocation@ 0X62B0|25264
08:33:38.8245B8209Initialize::GetLocation@ 0XAA0B0|696496
08:33:38.8245B8209Initialize::GetLocation@ 0X25E00|155136
08:33:38.8245B8209Initialize::GetLocation@ 0X1E290|123536
08:33:38.8245B8209Initialize::GetLocation@ 0X1E110|123152
08:33:38.8245B8209Initialize::GetLocation@ 0XEBA90|965264
08:33:38.8245B8209Initialize::GetLocation@ 0XEB540|963904
08:33:38.8245B8209Initialize::GetLocation@ 0X25F30|155440
08:33:38.8245B8209Initialize::GetLocation@ 0X25CF0|154864
08:33:38.8245B8209Initialize::GetLocation@ 0X2DCE0|187616
08:33:38.8245B8209Initialize::GetLocation@ 0X3D010|249872
08:33:38.8245B8209Initialize::GetLocation@ 0X10CD0|68816
08:33:38.8245B8209Initialize::GetLocation@ 0X10DD0|69072
08:33:38.8245B8209Initialize::GetLocation@ 0X10EC0|69312
08:33:38.8245B8209Initialize::GetLocation@ 0X10CD0|68816
08:33:38.8245B8209Initialize::GetLocation@ 0X10B70|68464
08:33:38.8245B8209Initialize::GetLocation@ 0X10D20|68896
08:33:38.8425B848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X136B0000>6|2|1164115969
08:33:38.9625B883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
08:33:38.9625B8209Initialize::GetLocation@ 0X3D10|15632
08:33:38.9625B8209Initialize::GetLocation@ 0X6130|24880
08:33:38.9625B8209Initialize::GetLocation@ 0X62E0|25312
08:33:38.9635B848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XFE630000>6|2|1164115969
08:33:38.9675B893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
08:33:38.9675B8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
08:33:38.9675B8209Initialize::GetLocation@ 0X100B0|65712
08:33:38.9675B8209Initialize::GetLocation@ 0X12DE0|77280
08:33:38.9675B8209Initialize::GetLocation@ 0X12BB0|76720
08:33:39.205B8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_17000 opened succesfuly
08:33:39.205B872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
08:33:39.205B8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_79_8_17000 close 2147483647 bytes
08:33:39.205B8297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.153.0.13\OWExplorer.dll]
08:33:39.535B8385ftw1OWExplorer injected
08:33:39.2684EC51`anonymous-namespace'::CreateProviderInitialize provider: NET
08:33:39.2684EC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
08:33:39.2684EC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
08:33:39.2684EC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
08:36:10.472FA4394ProcessInjector::HandleElevatedProcessFail injection to process [420] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
08:36:10.482FA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |420|: NVIDIA Share.exe
08:36:10.482FA4394ProcessInjector::HandleElevatedProcessFail injection to process [1532] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
08:36:10.482FA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |1532|: NVDisplay.Container.exe
08:36:10.482FA4394ProcessInjector::HandleElevatedProcessFail injection to process [3172] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
08:36:10.482FA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |3172|: nvcontainer.exe
08:36:10.482FA4394ProcessInjector::HandleElevatedProcessFail injection to process [3184] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
08:36:10.482FA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |3184|: NVIDIA Share.exe
08:36:10.482FA4394ProcessInjector::HandleElevatedProcessFail injection to process [3288] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
08:36:10.482FA4333ProcessInjector::HandlePendingProccesssFail to inject pending process |3288|: MsMpEng.exe
22:44:33.2525B866ProcessesMonitor::Stopstopping PM...
22:44:33.2524EC119ProcessesMonitor::ProcessEnumerateThreadexit process listener