TimeThreadLineFunctionMessage
09:17:59.6633328365ftw1Loading (pid: 17312)
09:17:59.66349F0147ProcessHardwareRecorder::CommandThreadstarting recorder thread
09:17:59.665332848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X6B0C0000>6|2|1247871722
09:17:59.666332848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X6D120000>6|2|1247871722
09:17:59.7393328172DXManager::DetectFound in 0
09:17:59.7393328209Initialize::GetLocation@ 0X4F80|20352
09:17:59.7393328209Initialize::GetLocation@ 0X69700|431872
09:17:59.7393328209Initialize::GetLocation@ 0X206F0|132848
09:17:59.7393328209Initialize::GetLocation@ 0X1DE0|7648
09:17:59.7393328111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:17:59.7393328209Initialize::GetLocation@ 0XFE0C8860|-32733088
09:17:59.7393328111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:17:59.7393328209Initialize::GetLocation@ 0XFE0CDC30|-32711632
09:17:59.7393328111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:17:59.7393328209Initialize::GetLocation@ 0XFE0CC5F0|-32717328
09:17:59.7393328111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X6B0C0000 <> 0X6D120000
09:17:59.7393328209Initialize::GetLocation@ 0XFDFAA7F0|-33904656
09:17:59.759332848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X3C950000>6|2|1247871638
09:17:59.8323328129DXManager::DetectOK
09:17:59.8973328186DXManager::DetectDone
09:17:59.8973328215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
09:17:59.8973328209Initialize::GetLocation@ 0X41B90|269200
09:17:59.8973328209Initialize::GetLocation@ 0X33E20|212512
09:17:59.8983328209Initialize::GetLocation@ 0X3D6C0|251584
09:17:59.8983328209Initialize::GetLocation@ 0XB8E10|757264
09:17:59.8983328209Initialize::GetLocation@ 0XB8960|756064
09:17:59.8983328209Initialize::GetLocation@ 0XACF0|44272
09:17:59.8983328209Initialize::GetLocation@ 0XB8A00|756224
09:17:59.8983328209Initialize::GetLocation@ 0X1B6B0|112304
09:17:59.8983328209Initialize::GetLocation@ 0X1E100|123136
09:17:59.8983328209Initialize::GetLocation@ 0X26730|157488
09:17:59.8983328209Initialize::GetLocation@ 0X1146B0|1132208
09:17:59.8983328209Initialize::GetLocation@ 0X114170|1130864
09:17:59.8983328209Initialize::GetLocation@ 0X1B5A0|112032
09:17:59.8983328209Initialize::GetLocation@ 0X1B4B0|111792
09:17:59.8983328209Initialize::GetLocation@ 0XD680|54912
09:17:59.8983328209Initialize::GetLocation@ 0X493C0|299968
09:17:59.8983328209Initialize::GetLocation@ 0XA860|43104
09:17:59.8983328209Initialize::GetLocation@ 0XD0000|851968
09:17:59.8983328209Initialize::GetLocation@ 0XD06D0|853712
09:17:59.8983328209Initialize::GetLocation@ 0XA860|43104
09:17:59.8983328209Initialize::GetLocation@ 0XD11C0|856512
09:17:59.8983328209Initialize::GetLocation@ 0XD1820|858144
09:17:59.917332848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X4A690000>6|2|1247870977
09:17:59.934332883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
09:17:59.9353328209Initialize::GetLocation@ 0X4040|16448
09:17:59.9353328209Initialize::GetLocation@ 0X6410|25616
09:17:59.9353328209Initialize::GetLocation@ 0X65C0|26048
09:17:59.936332848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X374C0000>6|2|1247870977
09:17:59.946332893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
09:17:59.9463328110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
09:17:59.9473328209Initialize::GetLocation@ 0XA5D0|42448
09:17:59.9473328209Initialize::GetLocation@ 0XD4D0|54480
09:17:59.9473328209Initialize::GetLocation@ 0XD290|53904
09:18:00.53328225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_14_17312 opened succesfuly
09:18:00.5332872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
09:18:00.53328256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_14_17312 close 2147483647 bytes
09:18:00.53328301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.168.0.12\OWExplorer.dll]
09:18:00.183328389ftw1OWExplorer injected
09:18:00.194F5C70Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
09:18:00.473211451`anonymous-namespace'::CreateProviderInitialize provider: NET
09:18:00.4742114117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
09:18:00.474211454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
09:18:00.474211451`anonymous-namespace'::CreateProviderInitialize provider: GPU
09:18:00.516145C646ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
09:18:00.516145C646ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
09:18:00.516145C646ProcessInjector::InjectProcessprocess |Lenovo.Vantage.AddinHost.exe| missing h
09:18:00.516145C646ProcessInjector::InjectProcessprocess |Lenovo.Vantage.AddinHost.x86.exe| missing h
09:18:01.249145C646ProcessInjector::InjectProcessprocess |enc-amf-test64.exe| missing h
09:18:01.249145C646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:18:01.258145C646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:18:22.147145C646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:18:22.147145C646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:20:30.650145C385ProcessInjector::HandleElevatedProcessFail injection to process [6772] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
09:20:30.650145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |6772|: GoogleCrashHandler64.exe
09:20:30.650145C385ProcessInjector::HandleElevatedProcessFail injection to process [7316] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
09:20:30.650145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |7316|: GoogleCrashHandler.exe
09:20:30.650145C385ProcessInjector::HandleElevatedProcessFail injection to process [13316] [t: 0 w_t_id: 0]- Lenovo.Vantage.AddinHost.exe (elevated True) 0x0
09:20:30.650145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |13316|: Lenovo.Vantage.AddinHost.exe
09:20:30.650145C385ProcessInjector::HandleElevatedProcessFail injection to process [15416] [t: 0 w_t_id: 0]- Lenovo.Vantage.AddinHost.x86.exe (elevated True) 0x0
09:20:30.650145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |15416|: Lenovo.Vantage.AddinHost.x86.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [1916] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |1916|: Code.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [6632] [t: 0 w_t_id: 0]- conemu-msys2-64.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |6632|: conemu-msys2-64.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [8908] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |8908|: Code.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [9360] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |9360|: Code.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [9436] [t: 0 w_t_id: 0]- git-cmd.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |9436|: git-cmd.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [9468] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |9468|: Code.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [10660] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |10660|: firefox.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [11528] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |11528|: firefox.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [13132] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |13132|: Code.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [14216] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |14216|: firefox.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [16836] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |16836|: bash.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [19444] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |19444|: firefox.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [19632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |19632|: firefox.exe
09:20:31.654145C385ProcessInjector::HandleElevatedProcessFail injection to process [19896] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:20:31.654145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |19896|: Code.exe
09:22:56.81145C646ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:23:03.155145C385ProcessInjector::HandleElevatedProcessFail injection to process [20856] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:23:03.155145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |20856|: firefox.exe
09:24:21.679145C385ProcessInjector::HandleElevatedProcessFail injection to process [17164] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:24:21.679145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |17164|: firefox.exe
09:25:17.885145C385ProcessInjector::HandleElevatedProcessFail injection to process [16408] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:25:17.885145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |16408|: Code.exe
09:25:17.885145C385ProcessInjector::HandleElevatedProcessFail injection to process [19020] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:25:17.885145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |19020|: Code.exe
09:25:17.885145C385ProcessInjector::HandleElevatedProcessFail injection to process [20272] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:25:17.885145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |20272|: Code.exe
09:25:18.884145C385ProcessInjector::HandleElevatedProcessFail injection to process [9652] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:25:18.884145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |9652|: Code.exe
09:26:24.61145C385ProcessInjector::HandleElevatedProcessFail injection to process [4004] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
09:26:24.61145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |4004|: Code.exe
09:27:20.269145C385ProcessInjector::HandleElevatedProcessFail injection to process [11252] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
09:27:20.269145C317ProcessInjector::HandlePendingProccesssFail to inject pending process |11252|: firefox.exe
09:42:02.2654F5C75Common::ProcessExplorer::ProcessTrackerIPCAgent::OnDisconnecteddisconnected to process tracker server
09:42:03.975332866ProcessesMonitor::Stopstopping PM...
09:42:03.9752114119ProcessesMonitor::ProcessEnumerateThreadexit process listener
09:42:03.9773328529ProcessInjector::Unhookunhook running process
09:42:09.993332866ProcessesMonitor::Stopstopping PM...