TimeThreadLineFunctionMessage
13:15:44.5408AC361ftw1Loading (pid: 6352)
13:15:44.5403CF0146ProcessHardwareRecorder::CommandThreadstarting recorder thread
13:15:44.5468AC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X338C0000>6|2|1203373203
13:15:44.5468AC48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X35380000>6|2|1203373081
13:15:44.6158AC172DXManager::DetectFound in 0
13:15:44.6158AC209Initialize::GetLocation@ 0X4660|18016
13:15:44.6158AC209Initialize::GetLocation@ 0X661F0|418288
13:15:44.6158AC209Initialize::GetLocation@ 0X19DB0|105904
13:15:44.6158AC209Initialize::GetLocation@ 0X1350|4944
13:15:44.6158AC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X338C0000 <> 0X35380000
13:15:44.6158AC209Initialize::GetLocation@ 0XFE663020|-26857440
13:15:44.6158AC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X338C0000 <> 0X35380000
13:15:44.6158AC209Initialize::GetLocation@ 0XFE668060|-26836896
13:15:44.6158AC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X338C0000 <> 0X35380000
13:15:44.6158AC209Initialize::GetLocation@ 0XFE65E620|-26876384
13:15:44.6158AC111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X338C0000 <> 0X35380000
13:15:44.6158AC209Initialize::GetLocation@ 0XFE54AA80|-28005760
13:15:44.6208AC48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X28380000>6|2|1203373142
13:15:44.6358AC129DXManager::DetectOK
13:15:44.6438AC186DXManager::DetectDone
13:15:44.6438AC215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
13:15:44.6438AC209Initialize::GetLocation@ 0X3AC00|240640
13:15:44.6438AC209Initialize::GetLocation@ 0X2C5B0|181680
13:15:44.6438AC209Initialize::GetLocation@ 0X36D00|224512
13:15:44.6438AC209Initialize::GetLocation@ 0XAE210|713232
13:15:44.6438AC209Initialize::GetLocation@ 0XADD60|712032
13:15:44.6438AC209Initialize::GetLocation@ 0X5880|22656
13:15:44.6438AC209Initialize::GetLocation@ 0XADE00|712192
13:15:44.6438AC209Initialize::GetLocation@ 0X20FF0|135152
13:15:44.6438AC209Initialize::GetLocation@ 0X1CA60|117344
13:15:44.6438AC209Initialize::GetLocation@ 0X1C8E0|116960
13:15:44.6438AC209Initialize::GetLocation@ 0X1086D0|1083088
13:15:44.6438AC209Initialize::GetLocation@ 0X108180|1081728
13:15:44.6438AC209Initialize::GetLocation@ 0X248B0|149680
13:15:44.6438AC209Initialize::GetLocation@ 0X247A0|149408
13:15:44.6438AC209Initialize::GetLocation@ 0X2C440|181312
13:15:44.6438AC209Initialize::GetLocation@ 0X3F3F0|259056
13:15:44.6438AC209Initialize::GetLocation@ 0XF3E0|62432
13:15:44.6438AC209Initialize::GetLocation@ 0XF4E0|62688
13:15:44.6438AC209Initialize::GetLocation@ 0XF5D0|62928
13:15:44.6438AC209Initialize::GetLocation@ 0XF3E0|62432
13:15:44.6438AC209Initialize::GetLocation@ 0XF280|62080
13:15:44.6438AC209Initialize::GetLocation@ 0XF430|62512
13:15:44.6488AC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X181B0000>6|2|1203372033
13:15:44.6588AC83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
13:15:44.6588AC209Initialize::GetLocation@ 0X3CC0|15552
13:15:44.6588AC209Initialize::GetLocation@ 0X5FD0|24528
13:15:44.6588AC209Initialize::GetLocation@ 0X6180|24960
13:15:44.6598AC48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X6400000>6|2|1203372033
13:15:44.6638AC93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
13:15:44.6648AC110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
13:15:44.6648AC209Initialize::GetLocation@ 0X10000|65536
13:15:44.6648AC209Initialize::GetLocation@ 0X12C80|76928
13:15:44.6648AC209Initialize::GetLocation@ 0X12A60|76384
13:15:44.7158AC225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_6352 opened succesfuly
13:15:44.7158AC72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
13:15:44.7158AC256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_6352 close 2147483647 bytes
13:15:44.7158AC297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.24\OWExplorer.dll]
13:15:44.7218AC385ftw1OWExplorer injected
13:15:44.9702BF051`anonymous-namespace'::CreateProviderInitialize provider: NET
13:15:44.9702BF0117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
13:15:44.9702BF054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
13:15:44.9702BF051`anonymous-namespace'::CreateProviderInitialize provider: GPU
13:15:45.233D50629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
13:15:45.233D50629ProcessInjector::InjectProcessprocess |Sendevsvc.exe| missing h
13:15:45.233D50629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
13:15:45.233D50629ProcessInjector::InjectProcessprocess |MSI.CentralServer.exe| missing h
13:15:45.1113D50629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
13:15:45.1113D50629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
13:15:45.3303D50629ProcessInjector::InjectProcessprocess |IAStorDataMgrSvc.exe| missing h
13:15:45.5503D50629ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
13:15:45.5943D50629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [2712] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |2712|: NVDisplay.Container.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [3460] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |3460|: software_reporter_tool.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5184] [t: 0 w_t_id: 0]- agent_ovpnconnect_1594367036109.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5184|: agent_ovpnconnect_1594367036109.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5224] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5224|: gameinputsvc.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5284] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5284|: Streamlabs OBS.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5472] [t: 0 w_t_id: 0]- Sendevsvc.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5472|: Sendevsvc.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5488] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5488|: gameinputsvc.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5600] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5600|: nvcontainer.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [5756] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5756|: MsMpEng.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [6488] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |6488|: MicrosoftEdgeUpdate.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [7572] [t: 0 w_t_id: 0]- MSI.CentralServer.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |7572|: MSI.CentralServer.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [8340] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |8340|: Streamlabs OBS.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [10308] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |10308|: Streamlabs OBS.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [10324] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |10324|: Streamlabs OBS.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [10604] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |10604|: software_reporter_tool.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [11656] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |11656|: GoogleCrashHandler.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [11720] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |11720|: GoogleCrashHandler64.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [12140] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |12140|: software_reporter_tool.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [12460] [t: 0 w_t_id: 0]- Streamlabs OBS.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |12460|: Streamlabs OBS.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [12808] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |12808|: NVIDIA Share.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [14284] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |14284|: NVIDIA Share.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [16960] [t: 0 w_t_id: 0]- crash-handler-process.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |16960|: crash-handler-process.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [17412] [t: 0 w_t_id: 0]- IAStorDataMgrSvc.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |17412|: IAStorDataMgrSvc.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [18016] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |18016|: EasyAntiCheat.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [19080] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |19080|: obs-browser-page.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [19184] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |19184|: obs-browser-page.exe
13:18:15.7283D50441ProcessInjector::HandleElevatedProcessFail injection to process [19216] [t: 0 w_t_id: 0]- obs-browser-page.exe (elevated True) 0x1f
13:18:15.7283D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |19216|: obs-browser-page.exe
13:19:23.7293D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:20:40.7313D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:20:41.7273D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:44:47.6953D50441ProcessInjector::HandleElevatedProcessFail injection to process [5056] [t: 0 w_t_id: 0]- git-bash.exe (elevated True) 0x0
13:44:47.6953D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |5056|: git-bash.exe
13:44:49.6953D50441ProcessInjector::HandleElevatedProcessFail injection to process [6024] [t: 0 w_t_id: 0]- bash.exe (elevated True) 0x0
13:44:49.6953D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |6024|: bash.exe
13:48:28.6723D50441ProcessInjector::HandleElevatedProcessFail injection to process [7872] [t: 0 w_t_id: 0]- git.exe (elevated True) 0x0
13:48:28.6723D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |7872|: git.exe
13:48:28.6723D50441ProcessInjector::HandleElevatedProcessFail injection to process [11052] [t: 0 w_t_id: 0]- ssh.exe (elevated True) 0x0
13:48:28.6723D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |11052|: ssh.exe
13:48:28.6723D50441ProcessInjector::HandleElevatedProcessFail injection to process [17772] [t: 0 w_t_id: 0]- git.exe (elevated True) 0x0
13:48:28.6723D50380ProcessInjector::HandlePendingProccesssFail to inject pending process |17772|: git.exe
14:21:20.6143D50629ProcessInjector::InjectProcessprocess |ServiceSwitch.exe| missing h
16:25:37.103D50629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
16:25:37.103D50629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:19:23.7243D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:19:37.7263D50629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
17:19:38.7263D50629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
17:19:40.7273D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:19:40.7273D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:20:40.7273D50629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:44:54.3628AC66ProcessesMonitor::Stopstopping PM...
17:44:54.3622BF0119ProcessesMonitor::ProcessEnumerateThreadexit process listener