TimeThreadLineFunctionMessage
09:57:49.70524AC146ProcessHardwareRecorder::CommandThreadstarting recorder thread
09:57:49.7052DE0361ftw1Loading (pid: 19300)
09:57:49.7062DE048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0XB8720000>6|2|1247871522
09:57:49.7072DE048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0XBAC20000>6|2|1247871522
09:57:49.8312DE0172DXManager::DetectFound in 0
09:57:49.8312DE0209Initialize::GetLocation@ 0X4F80|20352
09:57:49.8312DE0209Initialize::GetLocation@ 0X69640|431680
09:57:49.8312DE0209Initialize::GetLocation@ 0X206F0|132848
09:57:49.8312DE0209Initialize::GetLocation@ 0X1DE0|7648
09:57:49.8312DE0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000
09:57:49.8312DE0209Initialize::GetLocation@ 0XFDC28860|-37582752
09:57:49.8312DE0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000
09:57:49.8312DE0209Initialize::GetLocation@ 0XFDC2DC30|-37561296
09:57:49.8312DE0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000
09:57:49.8312DE0209Initialize::GetLocation@ 0XFDC2C5F0|-37566992
09:57:49.8312DE0111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0XB8720000 <> 0XBAC20000
09:57:49.8312DE0209Initialize::GetLocation@ 0XFDB0A7F0|-38754320
09:57:49.8432DE048Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0XB59E0000>6|2|1247871638
09:57:49.9202DE0129DXManager::DetectOK
09:57:49.9522DE0186DXManager::DetectDone
09:57:49.9522DE0215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
09:57:49.9532DE0209Initialize::GetLocation@ 0X41B90|269200
09:57:49.9532DE0209Initialize::GetLocation@ 0X33E20|212512
09:57:49.9532DE0209Initialize::GetLocation@ 0X3D6C0|251584
09:57:49.9532DE0209Initialize::GetLocation@ 0XB8E10|757264
09:57:49.9532DE0209Initialize::GetLocation@ 0XB8960|756064
09:57:49.9532DE0209Initialize::GetLocation@ 0XACF0|44272
09:57:49.9532DE0209Initialize::GetLocation@ 0XB8A00|756224
09:57:49.9532DE0209Initialize::GetLocation@ 0X1B6B0|112304
09:57:49.9532DE0209Initialize::GetLocation@ 0X1E100|123136
09:57:49.9532DE0209Initialize::GetLocation@ 0X26730|157488
09:57:49.9532DE0209Initialize::GetLocation@ 0X1146B0|1132208
09:57:49.9532DE0209Initialize::GetLocation@ 0X114170|1130864
09:57:49.9532DE0209Initialize::GetLocation@ 0X1B5A0|112032
09:57:49.9532DE0209Initialize::GetLocation@ 0X1B4B0|111792
09:57:49.9532DE0209Initialize::GetLocation@ 0XD680|54912
09:57:49.9532DE0209Initialize::GetLocation@ 0X493C0|299968
09:57:49.9532DE0209Initialize::GetLocation@ 0XA860|43104
09:57:49.9532DE0209Initialize::GetLocation@ 0XD0000|851968
09:57:49.9532DE0209Initialize::GetLocation@ 0XD06D0|853712
09:57:49.9532DE0209Initialize::GetLocation@ 0XA860|43104
09:57:49.9532DE0209Initialize::GetLocation@ 0XD11C0|856512
09:57:49.9532DE0209Initialize::GetLocation@ 0XD1820|858144
09:57:49.9722DE048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0XAA8C0000>6|2|1247870977
09:57:50.32DE083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
09:57:50.32DE0209Initialize::GetLocation@ 0X4040|16448
09:57:50.32DE0209Initialize::GetLocation@ 0X6410|25616
09:57:50.32DE0209Initialize::GetLocation@ 0X65C0|26048
09:57:50.72DE048Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0XA5E40000>6|2|1247870977
09:57:50.172DE093VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
09:57:50.172DE0110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
09:57:50.172DE0209Initialize::GetLocation@ 0XA5D0|42448
09:57:50.172DE0209Initialize::GetLocation@ 0XD4D0|54480
09:57:50.172DE0209Initialize::GetLocation@ 0XD290|53904
09:57:50.822DE0225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_19300 opened succesfuly
09:57:50.822DE072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
09:57:50.822DE0256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_19300 close 2147483647 bytes
09:57:50.822DE0297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.162.0.8\OWExplorer.dll]
09:57:50.882DE0385ftw1OWExplorer injected
09:57:50.32611B451`anonymous-namespace'::CreateProviderInitialize provider: NET
09:57:50.32611B4117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
09:57:50.32611B454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
09:57:50.32611B451`anonymous-namespace'::CreateProviderInitialize provider: GPU
09:57:50.33414E4629ProcessInjector::InjectProcessprocess |wmpnetwk.exe| missing h
09:57:50.33414E4629ProcessInjector::InjectProcessprocess |LEDKeeper2.exe| missing h
09:57:50.33414E4629ProcessInjector::InjectProcessprocess |MSI.CentralServer.exe| missing h
09:57:50.33414E4629ProcessInjector::InjectProcessprocess |CC_Engine_x64.exe| missing h
09:57:50.33414E4629ProcessInjector::InjectProcessprocess |lghub_updater.exe| missing h
09:57:50.33414E4629ProcessInjector::InjectProcessprocess |spd.exe| missing h
09:57:50.39014E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
09:57:50.39014E4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
09:57:50.45214E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
09:57:50.45214E4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
09:57:50.45214E4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
09:58:02.20814E4629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
09:58:02.20814E4629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
09:58:13.28214E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
09:58:16.29114E4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [3440] [t: 0 w_t_id: 0]- LEDKeeper2.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |3440|: LEDKeeper2.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [3700] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |3700|: MsMpEng.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [4028] [t: 0 w_t_id: 0]- wmpnetwk.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4028|: wmpnetwk.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [7528] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |7528|: NVDisplay.Container.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [8920] [t: 0 w_t_id: 0]- MSI.CentralServer.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |8920|: MSI.CentralServer.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [9140] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |9140|: MicrosoftEdgeUpdate.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [12440] [t: 0 w_t_id: 0]- CC_Engine_x64.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |12440|: CC_Engine_x64.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [15240] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |15240|: GoogleUpdate.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [16052] [t: 0 w_t_id: 0]- spd.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |16052|: spd.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [16696] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |16696|: lghub.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [17632] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |17632|: nvcontainer.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [19584] [t: 0 w_t_id: 0]- lghub.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |19584|: lghub.exe
10:00:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [19856] [t: 0 w_t_id: 0]- lghub_updater.exe (elevated True) 0x0
10:00:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |19856|: lghub_updater.exe
10:00:25.4114E4441ProcessInjector::HandleElevatedProcessFail injection to process [13616] [t: 0 w_t_id: 0]- kdd (elevated True) 0x0
10:00:25.4114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |13616|: kdd
10:00:25.4114E4441ProcessInjector::HandleElevatedProcessFail injection to process [19940] [t: 0 w_t_id: 0]- wdsync.exe (elevated True) 0x0
10:00:25.4114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |19940|: wdsync.exe
10:00:28.5414E4629ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
10:00:56.22414E4441ProcessInjector::HandleElevatedProcessFail injection to process [1148] [t: 0 w_t_id: 0]- wdsync.exe (elevated True) 0x0
10:00:56.22414E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |1148|: wdsync.exe
10:00:56.22414E4441ProcessInjector::HandleElevatedProcessFail injection to process [18608] [t: 0 w_t_id: 0]- wdsync-inotify.exe (elevated True) 0x0
10:00:56.22414E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |18608|: wdsync-inotify.exe
10:00:56.22414E4441ProcessInjector::HandleElevatedProcessFail injection to process [21292] [t: 0 w_t_id: 0]- wdsync.exe (elevated True) 0x0
10:00:56.22414E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |21292|: wdsync.exe
10:07:27.59714E4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
12:52:13.49614E4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
12:52:13.49614E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
12:56:14.88514E4629ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
13:48:18.36614E4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:48:18.36614E4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
13:48:18.36614E4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
14:02:45.63814E4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
14:13:36.54314E4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
14:56:14.77214E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:18:55.44214E4441ProcessInjector::HandleElevatedProcessFail injection to process [9708] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:18:55.44214E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |9708|: owobs-ffmpeg-mux.exe
15:25:44.83114E4441ProcessInjector::HandleElevatedProcessFail injection to process [6788] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:25:44.83114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6788|: owobs-ffmpeg-mux.exe
15:28:58.51514E4441ProcessInjector::HandleElevatedProcessFail injection to process [7292] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:28:58.51514E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |7292|: owobs-ffmpeg-mux.exe
15:33:48.81414E4441ProcessInjector::HandleElevatedProcessFail injection to process [13076] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:33:48.81414E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |13076|: owobs-ffmpeg-mux.exe
15:38:05.97814E4441ProcessInjector::HandleElevatedProcessFail injection to process [7800] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:38:05.97814E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |7800|: owobs-ffmpeg-mux.exe
15:41:35.72514E4441ProcessInjector::HandleElevatedProcessFail injection to process [11720] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:41:35.72514E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |11720|: owobs-ffmpeg-mux.exe
15:57:23.69514E4441ProcessInjector::HandleElevatedProcessFail injection to process [15372] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
15:57:23.69514E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |15372|: owobs-ffmpeg-mux.exe
17:18:44.39714E4441ProcessInjector::HandleElevatedProcessFail injection to process [6508] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
17:18:44.39814E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6508|: owobs-ffmpeg-mux.exe
17:36:13.77814E4441ProcessInjector::HandleElevatedProcessFail injection to process [5796] [t: 0 w_t_id: 0]- NVIDIA GeForce Experience.exe (elevated True) 0x0
17:36:13.77814E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |5796|: NVIDIA GeForce Experience.exe
17:37:00.15114E4441ProcessInjector::HandleElevatedProcessFail injection to process [6548] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
17:37:00.15114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6548|: owobs-ffmpeg-mux.exe
17:47:55.9214E4441ProcessInjector::HandleElevatedProcessFail injection to process [6036] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
17:47:55.9214E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6036|: owobs-ffmpeg-mux.exe
18:02:46.26614E4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:10:49.15814E4441ProcessInjector::HandleElevatedProcessFail injection to process [5804] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
18:10:49.15814E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |5804|: owobs-ffmpeg-mux.exe
18:13:36.55514E4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:28:41.63614E4441ProcessInjector::HandleElevatedProcessFail injection to process [14548] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
18:28:41.63614E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |14548|: owobs-ffmpeg-mux.exe
18:33:04.54014E4441ProcessInjector::HandleElevatedProcessFail injection to process [20128] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
18:33:04.54014E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |20128|: owobs-ffmpeg-mux.exe
19:06:03.40914E4441ProcessInjector::HandleElevatedProcessFail injection to process [6744] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
19:06:03.40914E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6744|: owobs-ffmpeg-mux.exe
19:54:48.77314E4441ProcessInjector::HandleElevatedProcessFail injection to process [9676] [t: 0 w_t_id: 0]- owobs-ffmpeg-mux.exe (elevated True) 0x0
19:54:48.77314E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |9676|: owobs-ffmpeg-mux.exe
19:56:15.45814E4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
19:56:15.45814E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:56:36.66214E4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
20:28:50.90514E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
20:28:50.90514E4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
20:31:21.1114E4441ProcessInjector::HandleElevatedProcessFail injection to process [19296] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
20:31:21.1114E4380ProcessInjector::HandlePendingProccesssFail to inject pending process |19296|: GoogleUpdate.exe
20:31:41.292DE066ProcessesMonitor::Stopstopping PM...
20:31:41.2911B4119ProcessesMonitor::ProcessEnumerateThreadexit process listener
20:31:41.302DE0526ProcessInjector::Unhookunhook running process