TimeThreadLineFunctionMessage
17:09:32.6382F44361ftw1Loading (pid: 7648)
17:09:32.6384CF8146ProcessHardwareRecorder::CommandThreadstarting recorder thread
17:09:32.6402F4448Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X951C0000>6|2|1203373203
17:09:32.6402F4448Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X96C80000>6|2|1203373081
17:09:32.7142F44172DXManager::DetectFound in 0
17:09:32.7142F44209Initialize::GetLocation@ 0X4660|18016
17:09:32.7142F44209Initialize::GetLocation@ 0X661F0|418288
17:09:32.7142F44209Initialize::GetLocation@ 0X19DB0|105904
17:09:32.7142F44209Initialize::GetLocation@ 0X1350|4944
17:09:32.7142F44111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X951C0000 <> 0X96C80000
17:09:32.7142F44209Initialize::GetLocation@ 0XFE663020|-26857440
17:09:32.7142F44111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X951C0000 <> 0X96C80000
17:09:32.7142F44209Initialize::GetLocation@ 0XFE668060|-26836896
17:09:32.7142F44111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X951C0000 <> 0X96C80000
17:09:32.7142F44209Initialize::GetLocation@ 0XFE65E620|-26876384
17:09:32.7142F44111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X951C0000 <> 0X96C80000
17:09:32.7142F44209Initialize::GetLocation@ 0XFE54AA80|-28005760
17:09:32.7202F4448Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X89CA0000>6|2|1203373142
17:09:32.7402F44129DXManager::DetectOK
17:09:32.7522F44186DXManager::DetectDone
17:09:32.7522F44215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
17:09:32.7532F44209Initialize::GetLocation@ 0X3AC00|240640
17:09:32.7532F44209Initialize::GetLocation@ 0X2C5B0|181680
17:09:32.7532F44209Initialize::GetLocation@ 0X36D00|224512
17:09:32.7532F44209Initialize::GetLocation@ 0XAE210|713232
17:09:32.7532F44209Initialize::GetLocation@ 0XADD60|712032
17:09:32.7532F44209Initialize::GetLocation@ 0X5880|22656
17:09:32.7532F44209Initialize::GetLocation@ 0XADE00|712192
17:09:32.7532F44209Initialize::GetLocation@ 0X20FF0|135152
17:09:32.7532F44209Initialize::GetLocation@ 0X1CA60|117344
17:09:32.7532F44209Initialize::GetLocation@ 0X1C8E0|116960
17:09:32.7532F44209Initialize::GetLocation@ 0X1086D0|1083088
17:09:32.7532F44209Initialize::GetLocation@ 0X108180|1081728
17:09:32.7532F44209Initialize::GetLocation@ 0X248B0|149680
17:09:32.7532F44209Initialize::GetLocation@ 0X247A0|149408
17:09:32.7532F44209Initialize::GetLocation@ 0X2C440|181312
17:09:32.7532F44209Initialize::GetLocation@ 0X3F3F0|259056
17:09:32.7532F44209Initialize::GetLocation@ 0XF3E0|62432
17:09:32.7532F44209Initialize::GetLocation@ 0XF4E0|62688
17:09:32.7532F44209Initialize::GetLocation@ 0XF5D0|62928
17:09:32.7532F44209Initialize::GetLocation@ 0XF3E0|62432
17:09:32.7532F44209Initialize::GetLocation@ 0XF280|62080
17:09:32.7532F44209Initialize::GetLocation@ 0XF430|62512
17:09:32.7602F4448Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X685D0000>6|2|1203372033
17:09:32.7722F4483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
17:09:32.7722F44209Initialize::GetLocation@ 0X3CC0|15552
17:09:32.7722F44209Initialize::GetLocation@ 0X5FD0|24528
17:09:32.7722F44209Initialize::GetLocation@ 0X6180|24960
17:09:32.7732F4448Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X76D20000>6|2|1203372033
17:09:32.7802F4493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
17:09:32.7812F44110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
17:09:32.7812F44209Initialize::GetLocation@ 0X10000|65536
17:09:32.7812F44209Initialize::GetLocation@ 0X12C80|76928
17:09:32.7812F44209Initialize::GetLocation@ 0X12A60|76384
17:09:32.8342F44225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_3_7648 opened succesfuly
17:09:32.8342F4472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
17:09:32.8342F44256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_3_7648 close 2147483647 bytes
17:09:32.8342F44297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.19\OWExplorer.dll]
17:09:32.8412F44385ftw1OWExplorer injected
17:09:33.1364FDC51`anonymous-namespace'::CreateProviderInitialize provider: NET
17:09:33.1364FDC117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
17:09:33.1364FDC54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
17:09:33.1364FDC51`anonymous-namespace'::CreateProviderInitialize provider: GPU
17:09:33.1943F24629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
17:09:33.1943F24629ProcessInjector::InjectProcessprocess |Sendevsvc.exe| missing h
17:09:33.1943F24629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
17:09:33.1943F24629ProcessInjector::InjectProcessprocess |MSI.CentralServer.exe| missing h
17:09:33.2813F24629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
17:09:33.2813F24629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
17:09:33.5013F24629ProcessInjector::InjectProcessprocess |IAStorDataMgrSvc.exe| missing h
17:09:33.8533F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [300] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |300|: obs-browser-page.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [2636] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |2636|: NVDisplay.Container.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [5368] [t: 0 w_t_id: 0]- agent_ovpnconnect_1594367036109.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |5368|: agent_ovpnconnect_1594367036109.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [5456] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |5456|: gameinputsvc.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [5488] [t: 0 w_t_id: 0]- Sendevsvc.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |5488|: Sendevsvc.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [5496] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |5496|: nvcontainer.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [5520] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |5520|: MsMpEng.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [5776] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |5776|: gameinputsvc.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [6180] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |6180|: Streamlabs OBS.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [7736] [t: 0 w_t_id: 0]- MSI.CentralServer.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |7736|: MSI.CentralServer.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [7840] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |7840|: Streamlabs OBS.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [7984] [t: 0 w_t_id: 0]- git-bash.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |7984|: git-bash.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [8400] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |8400|: bash.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [9668] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |9668|: Streamlabs OBS.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [12000] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |12000|: GoogleCrashHandler.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [12012] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |12012|: GoogleCrashHandler64.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [12516] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |12516|: NVIDIA Share.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [12800] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |12800|: NVIDIA Share.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [13648] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |13648|: obs-browser-page.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [14800] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |14800|: Streamlabs OBS.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [15220] [t: 0 w_t_id: 0]- IAStorDataMgrSvc.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |15220|: IAStorDataMgrSvc.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [15868] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |15868|: obs-browser-page.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [16596] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |16596|: Streamlabs OBS.exe
17:12:03.8513F24441ProcessInjector::HandleElevatedProcessFail injection to process [18692] [t: 0 w_t_id: 0]- crash-handler-process.exe (elevated True) 0x0
17:12:03.8513F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |18692|: crash-handler-process.exe
17:14:28.8833F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:19:23.8863F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:51:03.393F24629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:51:03.393F24629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:37:26.9593F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
20:09:44.8733F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
20:10:01.8693F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
20:10:06.8693F24629ProcessInjector::InjectProcessprocess |MicrosoftEdge_X64_87.0.664.47_87.0.664.41.exe| missing h
20:10:14.8673F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
21:14:28.6883F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:14:47.6883F24629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
21:14:47.6883F24629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
21:14:49.6893F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:14:49.6893F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:19:23.6673F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
23:37:26.3773F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
00:37:27.2153F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
00:37:36.2153F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
01:14:29.1113F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
01:19:24.863F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
05:14:28.6903F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
05:19:23.6793F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
05:37:26.6503F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
06:09:44.5963F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
08:37:26.3993F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
11:27:09.313F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
11:27:54.263F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
12:56:43.8143F24629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
12:56:43.8143F24629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:14:28.7603F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:19:23.7603F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:09:45.8773F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
17:09:56.8753F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
17:14:28.8603F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:19:23.8493F24629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:27:08.8083F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
17:27:46.8043F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:49:47.3033F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:49:47.3043F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:49:53.2743F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:49:53.2743F24629ProcessInjector::InjectProcessprocess |MSI.CentralServer.exe| missing h
13:51:21.2593F24629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:51:21.2603F24629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:52:47.2633F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:52:47.2633F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:52:47.2633F24629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
13:52:47.2633F24629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
13:52:47.2633F24629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
13:52:47.2633F24629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:54:37.2293F24629ProcessInjector::InjectProcessprocess |LEDKeeper2.exe| missing h
13:55:18.2163F24441ProcessInjector::HandleElevatedProcessFail injection to process [17524] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x5
13:55:18.2163F24380ProcessInjector::HandlePendingProccesssFail to inject pending process |17524|: MicrosoftEdgeUpdate.exe
14:22:44.1712F4466ProcessesMonitor::Stopstopping PM...
14:22:44.1724FDC119ProcessesMonitor::ProcessEnumerateThreadexit process listener
14:22:44.1742F44526ProcessInjector::Unhookunhook running process
14:22:50.1912F4466ProcessesMonitor::Stopstopping PM...