TimeThreadLineFunctionMessage
09:11:28.2621438365ftw1Loading (pid: 19856)
09:11:28.264143848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X6B0C0000>6|2|1247871722
09:11:28.265143848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X6D120000>6|2|1247871722
09:11:28.2674DCC147ProcessHardwareRecorder::CommandThreadstarting recorder thread
09:11:28.3351438172DXManager::DetectFound in 0
09:11:28.3361438209Initialize::GetLocation@ 0X4F80|20352
09:11:28.3361438209Initialize::GetLocation@ 0X69700|431872
09:11:28.3361438209Initialize::GetLocation@ 0X206F0|132848
09:11:28.3361438209Initialize::GetLocation@ 0X1DE0|7648
09:11:28.3361438111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:11:28.3361438209Initialize::GetLocation@ 0XFE0C8860|-32733088
09:11:28.3361438111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:11:28.3361438209Initialize::GetLocation@ 0XFE0CDC30|-32711632
09:11:28.3361438111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:11:28.3361438209Initialize::GetLocation@ 0XFE0CC5F0|-32717328
09:11:28.3361438111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:11:28.3361438209Initialize::GetLocation@ 0XFDFAA7F0|-33904656
09:11:28.354143848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X3C950000>6|2|1247871638
09:11:28.4271438129DXManager::DetectOK
09:11:28.5021438186DXManager::DetectDone
09:11:28.5021438215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
09:11:28.5031438209Initialize::GetLocation@ 0X41B90|269200
09:11:28.5031438209Initialize::GetLocation@ 0X33E20|212512
09:11:28.5031438209Initialize::GetLocation@ 0X3D6C0|251584
09:11:28.5031438209Initialize::GetLocation@ 0XB8E10|757264
09:11:28.5031438209Initialize::GetLocation@ 0XB8960|756064
09:11:28.5031438209Initialize::GetLocation@ 0XACF0|44272
09:11:28.5031438209Initialize::GetLocation@ 0XB8A00|756224
09:11:28.5031438209Initialize::GetLocation@ 0X1B6B0|112304
09:11:28.5031438209Initialize::GetLocation@ 0X1E100|123136
09:11:28.5031438209Initialize::GetLocation@ 0X26730|157488
09:11:28.5031438209Initialize::GetLocation@ 0X1146B0|1132208
09:11:28.5031438209Initialize::GetLocation@ 0X114170|1130864
09:11:28.5031438209Initialize::GetLocation@ 0X1B5A0|112032
09:11:28.5031438209Initialize::GetLocation@ 0X1B4B0|111792
09:11:28.5031438209Initialize::GetLocation@ 0XD680|54912
09:11:28.5031438209Initialize::GetLocation@ 0X493C0|299968
09:11:28.5031438209Initialize::GetLocation@ 0XA860|43104
09:11:28.5031438209Initialize::GetLocation@ 0XD0000|851968
09:11:28.5031438209Initialize::GetLocation@ 0XD06D0|853712
09:11:28.5031438209Initialize::GetLocation@ 0XA860|43104
09:11:28.5031438209Initialize::GetLocation@ 0XD11C0|856512
09:11:28.5031438209Initialize::GetLocation@ 0XD1820|858144
09:11:28.540143848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X4AFF0000>6|2|1247870977
09:11:28.557143883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
09:11:28.5581438209Initialize::GetLocation@ 0X4040|16448
09:11:28.5581438209Initialize::GetLocation@ 0X6410|25616
09:11:28.5581438209Initialize::GetLocation@ 0X65C0|26048
09:11:28.559143848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X352A0000>6|2|1247870977
09:11:28.570143893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
09:11:28.5711438110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
09:11:28.5711438209Initialize::GetLocation@ 0XA5D0|42448
09:11:28.5711438209Initialize::GetLocation@ 0XD4D0|54480
09:11:28.5711438209Initialize::GetLocation@ 0XD290|53904
09:11:28.6271438225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_14_19856 opened succesfuly
09:11:28.627143872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
09:11:28.6271438256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_14_19856 close 2147483647 bytes
09:11:28.6271438301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.168.0.12\OWExplorer.dll]
09:11:28.6361438389ftw1OWExplorer injected
09:11:28.6363BFC70Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
09:11:28.9793D5451`anonymous-namespace'::CreateProviderInitialize provider: NET
09:11:28.9793D54117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
09:11:28.9793D5454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
09:11:28.9793D5451`anonymous-namespace'::CreateProviderInitialize provider: GPU
09:11:28.99637C0646ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
09:11:28.99637C0646ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
09:11:28.99637C0646ProcessInjector::InjectProcessprocess |Lenovo.Vantage.AddinHost.exe| missing h
09:11:28.99637C0646ProcessInjector::InjectProcessprocess |Lenovo.Vantage.AddinHost.x86.exe| missing h
09:12:18.85037C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:13:50.23937C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:13:51.24237C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:13:55.25337C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:13:59.28737C0385ProcessInjector::HandleElevatedProcessFail injection to process [6632] [t: 0 w_t_id: 0]- conemu-msys2-64.exe (elevated True) 0x0
09:13:59.28737C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |6632|: conemu-msys2-64.exe
09:13:59.28737C0385ProcessInjector::HandleElevatedProcessFail injection to process [6772] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
09:13:59.28737C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |6772|: GoogleCrashHandler64.exe
09:13:59.28737C0385ProcessInjector::HandleElevatedProcessFail injection to process [7316] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
09:13:59.28737C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |7316|: GoogleCrashHandler.exe
09:13:59.28737C0385ProcessInjector::HandleElevatedProcessFail injection to process [9436] [t: 0 w_t_id: 0]- git-cmd.exe (elevated True) 0x0
09:13:59.28737C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |9436|: git-cmd.exe
09:13:59.28737C0385ProcessInjector::HandleElevatedProcessFail injection to process [13316] [t: 0 w_t_id: 0]- Lenovo.Vantage.AddinHost.exe (elevated True) 0x0
09:13:59.28737C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |13316|: Lenovo.Vantage.AddinHost.exe
09:13:59.28837C0385ProcessInjector::HandleElevatedProcessFail injection to process [15416] [t: 0 w_t_id: 0]- Lenovo.Vantage.AddinHost.x86.exe (elevated True) 0x0
09:13:59.28837C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |15416|: Lenovo.Vantage.AddinHost.x86.exe
09:13:59.28837C0385ProcessInjector::HandleElevatedProcessFail injection to process [16836] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x0
09:13:59.28837C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |16836|: bash.exe
09:14:00.30037C0385ProcessInjector::HandleElevatedProcessFail injection to process [1916] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |1916|: Code.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [7492] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |7492|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [8908] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |8908|: Code.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [9360] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |9360|: Code.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [9468] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |9468|: Code.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [10496] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |10496|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [10660] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |10660|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [11528] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |11528|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [13132] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |13132|: Code.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [18156] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |18156|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [19444] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |19444|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [19632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |19632|: firefox.exe
09:14:00.30137C0385ProcessInjector::HandleElevatedProcessFail injection to process [19896] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:14:00.30137C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |19896|: Code.exe
09:14:14.35037C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:14:18.36737C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:15:03.59737C0385ProcessInjector::HandleElevatedProcessFail injection to process [14788] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:15:03.59737C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |14788|: firefox.exe
09:16:24.82937C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:16:59.92537C0385ProcessInjector::HandleElevatedProcessFail injection to process [8660] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:16:59.92537C0317ProcessInjector::HandlePendingProccesssFail to inject pending process |8660|: firefox.exe
09:17:13.4037C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:17:44.15937C0646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:17:49.9723BFC75Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
09:17:51.484143866ProcessesMonitor::Stopstopping PM...
09:17:51.4843D54119ProcessesMonitor::ProcessEnumerateThreadexit process listener
09:17:51.4861438529ProcessInjector::Unhookunhook running process
09:17:57.499143866ProcessesMonitor::Stopstopping PM...