TimeThreadLineFunctionMessage
09:06:38.3536130365ftw1Loading (pid: 9196)
09:06:38.355613048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X85DF0000>6|2|1247871522
09:06:38.355613048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X88320000>6|2|1247871522
09:06:38.3781AB8147ProcessHardwareRecorder::CommandThreadstarting recorder thread
09:06:38.5416130172DXManager::DetectFound in 0
09:06:38.5436130209Initialize::GetLocation@ 0X4F80|20352
09:06:38.5436130209Initialize::GetLocation@ 0X69640|431680
09:06:38.5436130209Initialize::GetLocation@ 0X206F0|132848
09:06:38.5436130209Initialize::GetLocation@ 0X1DE0|7648
09:06:38.5436130111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85DF0000 <> 0X88320000
09:06:38.5436130209Initialize::GetLocation@ 0XFDBF8860|-37779360
09:06:38.5436130111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85DF0000 <> 0X88320000
09:06:38.5436130209Initialize::GetLocation@ 0XFDBFDC30|-37757904
09:06:38.5436130111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85DF0000 <> 0X88320000
09:06:38.5436130209Initialize::GetLocation@ 0XFDBFC5F0|-37763600
09:06:38.5436130111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85DF0000 <> 0X88320000
09:06:38.5436130209Initialize::GetLocation@ 0XFDADA7F0|-38950928
09:06:38.577613048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X7A6D0000>6|2|1247871638
09:06:38.7576130129DXManager::DetectOK
09:06:38.8746130186DXManager::DetectDone
09:06:38.8746130215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
09:06:38.8756130209Initialize::GetLocation@ 0X41B90|269200
09:06:38.8756130209Initialize::GetLocation@ 0X33E20|212512
09:06:38.8756130209Initialize::GetLocation@ 0X3D6C0|251584
09:06:38.8756130209Initialize::GetLocation@ 0XB8E10|757264
09:06:38.8756130209Initialize::GetLocation@ 0XB8960|756064
09:06:38.8756130209Initialize::GetLocation@ 0XACF0|44272
09:06:38.8756130209Initialize::GetLocation@ 0XB8A00|756224
09:06:38.8756130209Initialize::GetLocation@ 0X1B6B0|112304
09:06:38.8756130209Initialize::GetLocation@ 0X1E100|123136
09:06:38.8756130209Initialize::GetLocation@ 0X26730|157488
09:06:38.8756130209Initialize::GetLocation@ 0X1146B0|1132208
09:06:38.8756130209Initialize::GetLocation@ 0X114170|1130864
09:06:38.8756130209Initialize::GetLocation@ 0X1B5A0|112032
09:06:38.8756130209Initialize::GetLocation@ 0X1B4B0|111792
09:06:38.8756130209Initialize::GetLocation@ 0XD680|54912
09:06:38.8756130209Initialize::GetLocation@ 0X493C0|299968
09:06:38.8756130209Initialize::GetLocation@ 0XA860|43104
09:06:38.8756130209Initialize::GetLocation@ 0XD0000|851968
09:06:38.8756130209Initialize::GetLocation@ 0XD06D0|853712
09:06:38.8756130209Initialize::GetLocation@ 0XA860|43104
09:06:38.8756130209Initialize::GetLocation@ 0XD11C0|856512
09:06:38.8756130209Initialize::GetLocation@ 0XD1820|858144
09:06:38.923613048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X76AF0000>6|2|1247870977
09:06:38.989613083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
09:06:38.9906130209Initialize::GetLocation@ 0X4040|16448
09:06:38.9906130209Initialize::GetLocation@ 0X6410|25616
09:06:38.9906130209Initialize::GetLocation@ 0X65C0|26048
09:06:38.996613048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X75760000>6|2|1247870977
09:06:39.53613093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
09:06:39.546130110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
09:06:39.556130209Initialize::GetLocation@ 0XA5D0|42448
09:06:39.556130209Initialize::GetLocation@ 0XD4D0|54480
09:06:39.556130209Initialize::GetLocation@ 0XD290|53904
09:06:39.1406130225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_8_9196 opened succesfuly
09:06:39.140613072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
09:06:39.1406130256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_8_9196 close 2147483647 bytes
09:06:39.1406130301InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.165.0.5\OWExplorer.dll]
09:06:39.1486130389ftw1OWExplorer injected
09:06:39.15165D870Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
09:06:39.661108C51`anonymous-namespace'::CreateProviderInitialize provider: NET
09:06:39.661108C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
09:06:39.661108C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
09:06:39.661108C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
09:06:39.67632C726ProcessInjector::InjectProcessprocess |RzSDKServer.exe| missing h
09:06:39.67632C726ProcessInjector::InjectProcessprocess |wmpnetwk.exe| missing h
09:06:39.67632C726ProcessInjector::InjectProcessprocess |LMS.exe| missing h
09:06:39.67732C726ProcessInjector::InjectProcessprocess |isa.exe| missing h
09:06:39.89432C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
09:06:39.89432C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
09:06:40.80232C726ProcessInjector::InjectProcessprocess |CTHelper.exe| missing h
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [2040] [t: 0 w_t_id: 0]- GoogleDriveFS.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |2040|: GoogleDriveFS.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [3640] [t: 0 w_t_id: 0]- RzSDKServer.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |3640|: RzSDKServer.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [3756] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |3756|: MsMpEng.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [5176] [t: 0 w_t_id: 0]- wmpnetwk.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |5176|: wmpnetwk.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [5396] [t: 0 w_t_id: 0]- isa.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |5396|: isa.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [9032] [t: 0 w_t_id: 0]- LMS.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |9032|: LMS.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [9876] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |9876|: NVIDIA Share.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [9920] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |9920|: MicrosoftEdgeUpdate.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [16640] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |16640|: nvcontainer.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [18256] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |18256|: NVIDIA Share.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [24360] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |24360|: GoogleUpdate.exe
09:09:10.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [24904] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
09:09:10.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |24904|: NVDisplay.Container.exe
09:09:11.31932C481ProcessInjector::HandleElevatedProcessFail injection to process [23748] [t: 0 w_t_id: 0]- CTHelper.exe (elevated True) 0x0
09:09:11.31932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |23748|: CTHelper.exe
09:11:26.28432C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:18:05.13432C481ProcessInjector::HandleElevatedProcessFail injection to process [14268] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
09:18:05.13432C413ProcessInjector::HandlePendingProccesssFail to inject pending process |14268|: fzsftp.exe
10:40:14.99632C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:40:14.99632C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:40:14.99632C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
11:04:17.69632C481ProcessInjector::HandleElevatedProcessFail injection to process [22480] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
11:04:17.69632C413ProcessInjector::HandlePendingProccesssFail to inject pending process |22480|: fzsftp.exe
11:14:20.42332C481ProcessInjector::HandleElevatedProcessFail injection to process [28628] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
11:14:20.42332C413ProcessInjector::HandlePendingProccesssFail to inject pending process |28628|: fzsftp.exe
11:18:26.46532C481ProcessInjector::HandleElevatedProcessFail injection to process [22604] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
11:18:26.46532C413ProcessInjector::HandlePendingProccesssFail to inject pending process |22604|: fzsftp.exe
11:32:10.20032C481ProcessInjector::HandleElevatedProcessFail injection to process [27152] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
11:32:10.20032C413ProcessInjector::HandlePendingProccesssFail to inject pending process |27152|: fzsftp.exe
12:01:29.10132C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
14:41:19.90932C481ProcessInjector::HandleElevatedProcessFail injection to process [22456] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x5
14:41:19.90932C413ProcessInjector::HandlePendingProccesssFail to inject pending process |22456|: fzsftp.exe
14:45:02.65632C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
14:45:18.75532C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:14:05.66232C481ProcessInjector::HandleElevatedProcessFail injection to process [18468] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x5
15:14:05.66232C413ProcessInjector::HandlePendingProccesssFail to inject pending process |18468|: fzsftp.exe
16:01:29.8932C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:11:27.41232C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:16:06.52432C481ProcessInjector::HandleElevatedProcessFail injection to process [21224] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x5
17:16:06.52432C413ProcessInjector::HandlePendingProccesssFail to inject pending process |21224|: fzsftp.exe
17:18:38.81532C481ProcessInjector::HandleElevatedProcessFail injection to process [21992] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x5
17:18:38.81532C413ProcessInjector::HandlePendingProccesssFail to inject pending process |21992|: fzsftp.exe
17:23:17.12932C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:23:17.12932C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
17:23:17.12932C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:04:35.82032C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
19:05:07.7632C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
19:45:02.11732C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:45:02.11732C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:47:32.25632C481ProcessInjector::HandleElevatedProcessFail injection to process [9888] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
19:47:32.25632C413ProcessInjector::HandlePendingProccesssFail to inject pending process |9888|: GoogleUpdate.exe
20:01:29.41032C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
20:04:34.85232C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
20:45:02.39732C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
21:11:26.90732C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
10:10:24.24532C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:10:24.24532C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
10:10:32.45332C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
10:20:24.31032C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:20:24.31032C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
10:29:50.7032C481ProcessInjector::HandleElevatedProcessFail injection to process [22048] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x0
10:29:50.7032C413ProcessInjector::HandlePendingProccesssFail to inject pending process |22048|: splwow64.exe
10:57:30.6632C481ProcessInjector::HandleElevatedProcessFail injection to process [29244] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x0
10:57:30.6632C413ProcessInjector::HandlePendingProccesssFail to inject pending process |29244|: splwow64.exe
12:01:28.71132C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:31:29.24632C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:51:05.3632C481ProcessInjector::HandleElevatedProcessFail injection to process [16044] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
13:51:05.3632C413ProcessInjector::HandlePendingProccesssFail to inject pending process |16044|: fzsftp.exe
15:45:03.37032C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:45:49.66832C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
15:45:49.66832C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
15:45:49.66832C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
15:45:49.66832C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
16:31:29.29132C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:45:02.40132C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
17:17:52.4632C481ProcessInjector::HandleElevatedProcessFail injection to process [29836] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
17:17:52.4632C413ProcessInjector::HandlePendingProccesssFail to inject pending process |29836|: fzsftp.exe
18:04:34.88732C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
18:45:02.40632C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:05:37.96732C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:05:37.96732C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:45:02.66332C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
20:01:29.53432C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
20:31:29.66532C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
20:45:03.25032C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
20:45:38.53532C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
21:04:35.70632C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
21:04:58.87632C726ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h