TimeThreadLineFunctionMessage
12:16:53.5573BE8361ftw1Loading (pid: 4712)
12:16:53.557DA4146ProcessHardwareRecorder::CommandThreadstarting recorder thread
12:16:53.5583BE848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X14800000>6|2|1247871522
12:16:53.5583BE848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X17760000>6|2|1247871522
12:16:53.6703BE8172DXManager::DetectFound in 0
12:16:53.6723BE8209Initialize::GetLocation@ 0X4F80|20352
12:16:53.6723BE8209Initialize::GetLocation@ 0X69640|431680
12:16:53.6723BE8209Initialize::GetLocation@ 0X206F0|132848
12:16:53.6723BE8209Initialize::GetLocation@ 0X1DE0|7648
12:16:53.6723BE8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000
12:16:53.6723BE8209Initialize::GetLocation@ 0XFD1C8860|-48461728
12:16:53.6723BE8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000
12:16:53.6723BE8209Initialize::GetLocation@ 0XFD1CDC30|-48440272
12:16:53.6723BE8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000
12:16:53.6723BE8209Initialize::GetLocation@ 0XFD1CC5F0|-48445968
12:16:53.6723BE8111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X14800000 <> 0X17760000
12:16:53.6723BE8209Initialize::GetLocation@ 0XFD0AA7F0|-49633296
12:16:53.7453BE848Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XF4BD0000>6|2|1247871638
12:16:53.8203BE8129DXManager::DetectOK
12:16:53.8663BE8186DXManager::DetectDone
12:16:53.8663BE8215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
12:16:53.8673BE8209Initialize::GetLocation@ 0X41B90|269200
12:16:53.8673BE8209Initialize::GetLocation@ 0X33E20|212512
12:16:53.8673BE8209Initialize::GetLocation@ 0X3D6C0|251584
12:16:53.8673BE8209Initialize::GetLocation@ 0XB8E10|757264
12:16:53.8673BE8209Initialize::GetLocation@ 0XB8960|756064
12:16:53.8673BE8209Initialize::GetLocation@ 0XACF0|44272
12:16:53.8673BE8209Initialize::GetLocation@ 0XB8A00|756224
12:16:53.8673BE8209Initialize::GetLocation@ 0X1B6B0|112304
12:16:53.8673BE8209Initialize::GetLocation@ 0X1E100|123136
12:16:53.8673BE8209Initialize::GetLocation@ 0X26730|157488
12:16:53.8673BE8209Initialize::GetLocation@ 0X1146B0|1132208
12:16:53.8673BE8209Initialize::GetLocation@ 0X114170|1130864
12:16:53.8673BE8209Initialize::GetLocation@ 0X1B5A0|112032
12:16:53.8673BE8209Initialize::GetLocation@ 0X1B4B0|111792
12:16:53.8673BE8209Initialize::GetLocation@ 0XD680|54912
12:16:53.8673BE8209Initialize::GetLocation@ 0X493C0|299968
12:16:53.8673BE8209Initialize::GetLocation@ 0XA860|43104
12:16:53.8673BE8209Initialize::GetLocation@ 0XD0000|851968
12:16:53.8673BE8209Initialize::GetLocation@ 0XD06D0|853712
12:16:53.8673BE8209Initialize::GetLocation@ 0XA860|43104
12:16:53.8673BE8209Initialize::GetLocation@ 0XD11C0|856512
12:16:53.8673BE8209Initialize::GetLocation@ 0XD1820|858144
12:16:53.8983BE848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XE3A40000>6|2|1247870977
12:16:53.9143BE883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
12:16:53.9143BE8209Initialize::GetLocation@ 0X4040|16448
12:16:53.9143BE8209Initialize::GetLocation@ 0X6410|25616
12:16:53.9143BE8209Initialize::GetLocation@ 0X65C0|26048
12:16:53.9183BE848Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XE39F0000>6|2|1247870977
12:16:53.9293BE893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
12:16:53.9293BE8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
12:16:53.9293BE8209Initialize::GetLocation@ 0XA5D0|42448
12:16:53.9293BE8209Initialize::GetLocation@ 0XD4D0|54480
12:16:53.9293BE8209Initialize::GetLocation@ 0XD290|53904
12:16:53.9893BE8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_4712 opened succesfuly
12:16:53.9893BE872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
12:16:53.9893BE8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_4712 close 2147483647 bytes
12:16:53.9903BE8297InjectOWExplorerExplorer file name [D:\Programs\Overwolf\0.162.0.8\OWExplorer.dll]
12:16:54.1383BE8385ftw1OWExplorer injected
12:16:54.568367851`anonymous-namespace'::CreateProviderInitialize provider: NET
12:16:54.5683678117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
12:16:54.568367854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
12:16:54.568367851`anonymous-namespace'::CreateProviderInitialize provider: GPU
12:16:54.5782EB4629ProcessInjector::InjectProcessprocess |officeclicktorun.exe| missing h
12:16:54.5782EB4629ProcessInjector::InjectProcessprocess |hamachi-2.exe| missing h
12:16:54.5782EB4629ProcessInjector::InjectProcessprocess |lghub_updater.exe| missing h
12:16:54.5782EB4629ProcessInjector::InjectProcessprocess |LMIGuardianSvc.exe| missing h
12:16:54.5782EB4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
12:16:54.5782EB4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
12:16:54.6412EB4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:17:16.3292EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
12:17:16.3302EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [232] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |232|: MicrosoftEdgeUpdate.exe
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [4084] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4084|: GoogleUpdate.exe
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [4588] [t: 0 w_t_id: 0]- officeclicktorun.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4588|: officeclicktorun.exe
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [4720] [t: 0 w_t_id: 0]- hamachi-2.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4720|: hamachi-2.exe
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [4804] [t: 0 w_t_id: 0]- lghub_updater.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4804|: lghub_updater.exe
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [4824] [t: 0 w_t_id: 0]- LMIGuardianSvc.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4824|: LMIGuardianSvc.exe
12:19:24.5722EB4441ProcessInjector::HandleElevatedProcessFail injection to process [5084] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
12:19:24.5722EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |5084|: MsMpEng.exe
12:21:38.6602EB4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:21:39.6762EB4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
12:24:15.9692EB4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
12:29:26.6692EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
12:59:26.3352EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
13:29:26.5672EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
13:31:32.6012EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
13:43:44.2062EB4441ProcessInjector::HandleElevatedProcessFail injection to process [16572] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
13:43:44.2062EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |16572|: owobs-ffmpeg-mux.exe
13:56:43.1092EB4441ProcessInjector::HandleElevatedProcessFail injection to process [14856] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
13:56:43.1092EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |14856|: owobs-ffmpeg-mux.exe
14:20:56.472EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
14:40:41.6642EB4629ProcessInjector::InjectProcessprocess |officec2rclient.exe| missing h
14:45:48.252EB4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:19:05.2142EB4441ProcessInjector::HandleElevatedProcessFail injection to process [8564] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0
15:19:05.2142EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |8564|: EpicWebHelper.exe
15:19:19.2862EB4441ProcessInjector::HandleElevatedProcessFail injection to process [6452] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0
15:19:19.2862EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6452|: EpicWebHelper.exe
15:19:19.2862EB4441ProcessInjector::HandleElevatedProcessFail injection to process [14960] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0
15:19:19.2862EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |14960|: EpicWebHelper.exe
15:21:19.1322EB4441ProcessInjector::HandleElevatedProcessFail injection to process [896] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
15:21:19.1322EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |896|: firefox.exe
15:21:19.1322EB4441ProcessInjector::HandleElevatedProcessFail injection to process [17568] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
15:21:19.1322EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |17568|: firefox.exe
15:21:22.1462EB4441ProcessInjector::HandleElevatedProcessFail injection to process [2068] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
15:21:22.1462EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |2068|: firefox.exe
15:21:35.1942EB4441ProcessInjector::HandleElevatedProcessFail injection to process [4132] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
15:21:35.1942EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4132|: firefox.exe
15:33:40.3692EB4441ProcessInjector::HandleElevatedProcessFail injection to process [16972] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x578
15:33:40.3692EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |16972|: EpicWebHelper.exe
15:38:05.4212EB4441ProcessInjector::HandleElevatedProcessFail injection to process [18372] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
15:38:05.4212EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |18372|: firefox.exe
15:38:15.5172EB4441ProcessInjector::HandleElevatedProcessFail injection to process [11632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
15:38:15.5172EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |11632|: firefox.exe
15:41:18.1052EB4441ProcessInjector::HandleElevatedProcessFail injection to process [9100] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x578
15:41:18.1052EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |9100|: firefox.exe
15:46:32.8862EB4441ProcessInjector::HandleElevatedProcessFail injection to process [18128] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x578
15:46:32.8862EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |18128|: EpicWebHelper.exe
15:46:54.632EB4441ProcessInjector::HandleElevatedProcessFail injection to process [13200] [t: 0 w_t_id: 0]- EOSOverlayRenderer-Win64-Shipping.exe (elevated True) 0x578
15:46:54.632EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |13200|: EOSOverlayRenderer-Win64-Shipping.exe
15:47:00.1362EB4441ProcessInjector::HandleElevatedProcessFail injection to process [12848] [t: 0 w_t_id: 0]- EOSOverlayRenderer-Win64-Shipping.exe (elevated True) 0x578
15:47:00.1362EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |12848|: EOSOverlayRenderer-Win64-Shipping.exe
15:50:15.5552EB4441ProcessInjector::HandleElevatedProcessFail injection to process [952] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x578
15:50:15.5552EB4380ProcessInjector::HandlePendingProccesssFail to inject pending process |952|: EpicWebHelper.exe