TimeThreadLineFunctionMessage
16:19:41.313AA0365ftw1Loading (pid: 17528)
16:19:41.314B54147ProcessHardwareRecorder::CommandThreadstarting recorder thread
16:19:41.333AA048Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X6C0C0000>6|2|1247871722
16:19:41.343AA048Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X6E5F0000>6|2|1247871722
16:19:41.913AA0172DXManager::DetectFound in 0
16:19:41.923AA0209Initialize::GetLocation@ 0X4F80|20352
16:19:41.923AA0209Initialize::GetLocation@ 0X69700|431872
16:19:41.923AA0209Initialize::GetLocation@ 0X206F0|132848
16:19:41.923AA0209Initialize::GetLocation@ 0X1DE0|7648
16:19:41.923AA0111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X6C0C0000 <> 0X6E5F0000
16:19:41.923AA0209Initialize::GetLocation@ 0XFDBF8860|-37779360
16:19:41.923AA0111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X6C0C0000 <> 0X6E5F0000
16:19:41.923AA0209Initialize::GetLocation@ 0XFDBFDC30|-37757904
16:19:41.923AA0111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X6C0C0000 <> 0X6E5F0000
16:19:41.923AA0209Initialize::GetLocation@ 0XFDBFC5F0|-37763600
16:19:41.923AA0111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X6C0C0000 <> 0X6E5F0000
16:19:41.923AA0209Initialize::GetLocation@ 0XFDADA7F0|-38950928
16:19:41.1143AA048Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X3A3B0000>6|2|1247871638
16:19:41.1573AA0129DXManager::DetectOK
16:19:41.1813AA0186DXManager::DetectDone
16:19:41.1813AA0215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
16:19:41.1813AA0209Initialize::GetLocation@ 0X41B90|269200
16:19:41.1813AA0209Initialize::GetLocation@ 0X33E20|212512
16:19:41.1813AA0209Initialize::GetLocation@ 0X3D6C0|251584
16:19:41.1813AA0209Initialize::GetLocation@ 0XB8E10|757264
16:19:41.1813AA0209Initialize::GetLocation@ 0XB8960|756064
16:19:41.1813AA0209Initialize::GetLocation@ 0XACF0|44272
16:19:41.1813AA0209Initialize::GetLocation@ 0XB8A00|756224
16:19:41.1813AA0209Initialize::GetLocation@ 0X1B6B0|112304
16:19:41.1813AA0209Initialize::GetLocation@ 0X1E100|123136
16:19:41.1813AA0209Initialize::GetLocation@ 0X26730|157488
16:19:41.1813AA0209Initialize::GetLocation@ 0X1146B0|1132208
16:19:41.1813AA0209Initialize::GetLocation@ 0X114170|1130864
16:19:41.1813AA0209Initialize::GetLocation@ 0X1B5A0|112032
16:19:41.1813AA0209Initialize::GetLocation@ 0X1B4B0|111792
16:19:41.1813AA0209Initialize::GetLocation@ 0XD680|54912
16:19:41.1813AA0209Initialize::GetLocation@ 0X493C0|299968
16:19:41.1813AA0209Initialize::GetLocation@ 0XA860|43104
16:19:41.1813AA0209Initialize::GetLocation@ 0XD0000|851968
16:19:41.1813AA0209Initialize::GetLocation@ 0XD06D0|853712
16:19:41.1813AA0209Initialize::GetLocation@ 0XA860|43104
16:19:41.1813AA0209Initialize::GetLocation@ 0XD11C0|856512
16:19:41.1813AA0209Initialize::GetLocation@ 0XD1820|858144
16:19:41.1913AA048Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X36AB0000>6|2|1247870977
16:19:41.2013AA083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
16:19:41.2013AA0209Initialize::GetLocation@ 0X4040|16448
16:19:41.2013AA0209Initialize::GetLocation@ 0X6410|25616
16:19:41.2013AA0209Initialize::GetLocation@ 0X65C0|26048
16:19:41.2023AA048Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X35A50000>6|2|1247870977
16:19:41.2063AA093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
16:19:41.2063AA0110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
16:19:41.2073AA0209Initialize::GetLocation@ 0XA5D0|42448
16:19:41.2073AA0209Initialize::GetLocation@ 0XD4D0|54480
16:19:41.2073AA0209Initialize::GetLocation@ 0XD290|53904
16:19:41.2613AA0225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_17528 opened succesfuly
16:19:41.2613AA072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
16:19:41.2613AA0256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_84_12_17528 close 2147483647 bytes
16:19:41.2623AA0301InjectOWExplorerExplorer file name [C:\Program Files\Overwolf\0.166.87.21\OWExplorer.dll]
16:19:41.3013AA0389ftw1OWExplorer injected
16:19:41.3011A4870Common::ProcessExplorer::ProcessTrackerIPCAgent::OnConnectedconnected to process tracker server
16:19:41.4132E9451`anonymous-namespace'::CreateProviderInitialize provider: NET
16:19:41.4132E94117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
16:19:41.4132E9454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
16:19:41.4132E9451`anonymous-namespace'::CreateProviderInitialize provider: GPU
16:19:42.37DFC726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:19:42.311DFC726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:20:42.847DFC726ProcessInjector::InjectProcessprocess |EasyAntiCheat.exe| missing h
16:22:11.477DFC481ProcessInjector::HandleElevatedProcessFail injection to process [3920] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
16:22:11.477DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |3920|: MsMpEng.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [1408] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |1408|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [1976] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |1976|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [2532] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |2532|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [4648] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |4648|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [6448] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |6448|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [7496] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |7496|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [9260] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |9260|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [10124] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |10124|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [10368] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |10368|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [10680] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |10680|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [14384] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |14384|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [15060] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |15060|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [15520] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |15520|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [15612] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |15612|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [16524] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |16524|: node.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [16656] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |16656|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [16700] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |16700|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [17960] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |17960|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [18012] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |18012|: Code.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [18488] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |18488|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [19356] [t: 0 w_t_id: 0]- CCXProcess.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |19356|: CCXProcess.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [19360] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |19360|: firefox.exe
16:22:12.481DFC481ProcessInjector::HandleElevatedProcessFail injection to process [20252] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
16:22:12.481DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |20252|: Code.exe
16:23:12.928DFC481ProcessInjector::HandleElevatedProcessFail injection to process [12568] [t: 0 w_t_id: 0]- EasyAntiCheat.exe (elevated True) 0x0
16:23:12.928DFC413ProcessInjector::HandlePendingProccesssFail to inject pending process |12568|: EasyAntiCheat.exe
16:24:25.482DFC726ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h