TimeThreadLineFunctionMessage
20:58:58.2742AB4365ftw1Loading (pid: 9488)
20:58:58.2742D34147ProcessHardwareRecorder::CommandThreadstarting recorder thread
20:58:58.2752AB448Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XBF7D0000>6|2|1247871722
20:58:58.2762AB448Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XC1BC0000>6|2|1247871722
20:58:58.3302AB4172DXManager::DetectFound in 0
20:58:58.3302AB4209Initialize::GetLocation@ 0X4F80|20352
20:58:58.3302AB4209Initialize::GetLocation@ 0X69700|431872
20:58:58.3302AB4209Initialize::GetLocation@ 0X206F0|132848
20:58:58.3302AB4209Initialize::GetLocation@ 0X1DE0|7648
20:58:58.3302AB4111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XBF7D0000 <> 0XC1BC0000
20:58:58.3302AB4209Initialize::GetLocation@ 0XFDD38860|-36468640
20:58:58.3302AB4111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XBF7D0000 <> 0XC1BC0000
20:58:58.3302AB4209Initialize::GetLocation@ 0XFDD3DC30|-36447184
20:58:58.3302AB4111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XBF7D0000 <> 0XC1BC0000
20:58:58.3302AB4209Initialize::GetLocation@ 0XFDD3C5F0|-36452880
20:58:58.3302AB4111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XBF7D0000 <> 0XC1BC0000
20:58:58.3302AB4209Initialize::GetLocation@ 0XFDC1A7F0|-37640208
20:58:58.3382AB448Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X93480000>6|2|1247871638
20:58:58.3782AB4129DXManager::DetectOK
20:58:58.3992AB4186DXManager::DetectDone
20:58:58.3992AB4215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
20:58:58.3992AB4209Initialize::GetLocation@ 0X41B90|269200
20:58:58.3992AB4209Initialize::GetLocation@ 0X33E20|212512
20:58:58.3992AB4209Initialize::GetLocation@ 0X3D6C0|251584
20:58:58.3992AB4209Initialize::GetLocation@ 0XB8E10|757264
20:58:58.3992AB4209Initialize::GetLocation@ 0XB8960|756064
20:58:58.3992AB4209Initialize::GetLocation@ 0XACF0|44272
20:58:58.3992AB4209Initialize::GetLocation@ 0XB8A00|756224
20:58:58.4002AB4209Initialize::GetLocation@ 0X1B6B0|112304
20:58:58.4002AB4209Initialize::GetLocation@ 0X1E100|123136
20:58:58.4002AB4209Initialize::GetLocation@ 0X26730|157488
20:58:58.4002AB4209Initialize::GetLocation@ 0X1146B0|1132208
20:58:58.4002AB4209Initialize::GetLocation@ 0X114170|1130864
20:58:58.4002AB4209Initialize::GetLocation@ 0X1B5A0|112032
20:58:58.4002AB4209Initialize::GetLocation@ 0X1B4B0|111792
20:58:58.4002AB4209Initialize::GetLocation@ 0XD680|54912
20:58:58.4002AB4209Initialize::GetLocation@ 0X493C0|299968
20:58:58.4002AB4209Initialize::GetLocation@ 0XA860|43104
20:58:58.4002AB4209Initialize::GetLocation@ 0XD0000|851968
20:58:58.4002AB4209Initialize::GetLocation@ 0XD06D0|853712
20:58:58.4002AB4209Initialize::GetLocation@ 0XA860|43104
20:58:58.4002AB4209Initialize::GetLocation@ 0XD11C0|856512
20:58:58.4002AB4209Initialize::GetLocation@ 0XD1820|858144
20:58:58.4082AB448Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X81B50000>6|2|1247870977
20:58:58.4412AB483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
20:58:58.4412AB4209Initialize::GetLocation@ 0X4040|16448
20:58:58.4412AB4209Initialize::GetLocation@ 0X6410|25616
20:58:58.4412AB4209Initialize::GetLocation@ 0X65C0|26048
20:58:58.4432AB448Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X816F0000>6|2|1247870977
20:58:58.4472AB493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
20:58:58.4482AB4110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
20:58:58.4482AB4209Initialize::GetLocation@ 0XA5D0|42448
20:58:58.4482AB4209Initialize::GetLocation@ 0XD4D0|54480
20:58:58.4482AB4209Initialize::GetLocation@ 0XD290|53904
20:58:58.5072AB4225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_9488 opened succesfuly
20:58:58.5072AB472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
20:58:58.5072AB4256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_9488 close 2147483647 bytes
20:58:58.5072AB4301InjectOWExplorerExplorer file name [C:\Program Files\Overwolf\0.166.1.16\OWExplorer.dll]
20:58:58.5152AB4389ftw1OWExplorer injected
20:58:58.5152C2070Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
20:58:58.6382C2451`anonymous-namespace'::CreateProviderInitialize provider: NET
20:58:58.6382C24117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
20:58:58.6382C2454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
20:58:58.6382C2451`anonymous-namespace'::CreateProviderInitialize provider: GPU
21:00:31.9642C1C726ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
21:01:29.3212C1C481ProcessInjector::HandleElevatedProcessFail injection to process [4044] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
21:01:29.3212C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |4044|: MsMpEng.exe
21:01:29.3212C1C481ProcessInjector::HandleElevatedProcessFail injection to process [10552] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x0
21:01:29.3212C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |10552|: CCXProcess.exe
21:01:29.3212C1C481ProcessInjector::HandleElevatedProcessFail injection to process [10568] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
21:01:29.3212C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |10568|: node.exe
21:02:26.5852C1C481ProcessInjector::HandleElevatedProcessFail injection to process [12804] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:26.5852C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |12804|: firefox.exe
21:02:27.5922C1C481ProcessInjector::HandleElevatedProcessFail injection to process [7692] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:27.5922C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |7692|: firefox.exe
21:02:27.5922C1C481ProcessInjector::HandleElevatedProcessFail injection to process [12376] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:27.5922C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |12376|: firefox.exe
21:02:27.5922C1C481ProcessInjector::HandleElevatedProcessFail injection to process [12528] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:27.5922C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |12528|: firefox.exe
21:02:27.5922C1C481ProcessInjector::HandleElevatedProcessFail injection to process [12952] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:27.5922C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |12952|: firefox.exe
21:02:38.6542C1C481ProcessInjector::HandleElevatedProcessFail injection to process [13116] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:38.6542C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |13116|: firefox.exe
21:02:46.6962C1C481ProcessInjector::HandleElevatedProcessFail injection to process [13456] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
21:02:46.6962C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |13456|: firefox.exe
21:03:07.8352C1C726ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
21:03:55.1622C1C726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:05:37.9222C1C481ProcessInjector::HandleElevatedProcessFail injection to process [3612] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
21:05:37.9232C1C413ProcessInjector::HandlePendingProccesssFail to inject pending process |3612|: EasyAntiCheat.exe
21:08:33.2092C1C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
21:08:33.2092C1C726ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h