TimeThreadLineFunctionMessage
11:09:44.2471C68361ftw1Loading (pid: 1384)
11:09:44.2491C6848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X58560000>6|2|1203373203
11:09:44.2491C6848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X59FB0000>6|2|1203373081
11:09:44.2693C70146ProcessHardwareRecorder::CommandThreadstarting recorder thread
11:09:44.5801C68172DXManager::DetectFound in 0
11:09:44.5801C68209Initialize::GetLocation@ 0X4660|18016
11:09:44.5801C68209Initialize::GetLocation@ 0X661F0|418288
11:09:44.5801C68209Initialize::GetLocation@ 0X19DB0|105904
11:09:44.5801C68209Initialize::GetLocation@ 0X1350|4944
11:09:44.5801C68111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000
11:09:44.5801C68209Initialize::GetLocation@ 0XFE6D3020|-26398688
11:09:44.5801C68111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000
11:09:44.5801C68209Initialize::GetLocation@ 0XFE6D8060|-26378144
11:09:44.5801C68111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000
11:09:44.5801C68209Initialize::GetLocation@ 0XFE6CE620|-26417632
11:09:44.5801C68111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X58560000 <> 0X59FB0000
11:09:44.5801C68209Initialize::GetLocation@ 0XFE5BAA80|-27547008
11:09:45.8131C6848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X2DCE0000>6|2|1203373142
11:09:46.8921C68129DXManager::DetectOK
11:09:47.1721C68186DXManager::DetectDone
11:09:47.1721C68215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
11:09:47.3131C68209Initialize::GetLocation@ 0X3AC00|240640
11:09:47.3131C68209Initialize::GetLocation@ 0X2C5B0|181680
11:09:47.3131C68209Initialize::GetLocation@ 0X36D00|224512
11:09:47.3131C68209Initialize::GetLocation@ 0XAE210|713232
11:09:47.3131C68209Initialize::GetLocation@ 0XADD60|712032
11:09:47.3131C68209Initialize::GetLocation@ 0X5880|22656
11:09:47.3131C68209Initialize::GetLocation@ 0XADE00|712192
11:09:47.3131C68209Initialize::GetLocation@ 0X20FF0|135152
11:09:47.3131C68209Initialize::GetLocation@ 0X1CA60|117344
11:09:47.3131C68209Initialize::GetLocation@ 0X1C8E0|116960
11:09:47.3131C68209Initialize::GetLocation@ 0X1086D0|1083088
11:09:47.3131C68209Initialize::GetLocation@ 0X108180|1081728
11:09:47.3131C68209Initialize::GetLocation@ 0X248B0|149680
11:09:47.3131C68209Initialize::GetLocation@ 0X247A0|149408
11:09:47.3131C68209Initialize::GetLocation@ 0X2C440|181312
11:09:47.3131C68209Initialize::GetLocation@ 0X3F3F0|259056
11:09:47.3131C68209Initialize::GetLocation@ 0XF3E0|62432
11:09:47.3131C68209Initialize::GetLocation@ 0XF4E0|62688
11:09:47.3131C68209Initialize::GetLocation@ 0XF5D0|62928
11:09:47.3131C68209Initialize::GetLocation@ 0XF3E0|62432
11:09:47.3131C68209Initialize::GetLocation@ 0XF280|62080
11:09:47.3131C68209Initialize::GetLocation@ 0XF430|62512
11:09:47.5701C6848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X2C3F0000>6|2|1203372033
11:09:47.5821C6883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
11:09:47.5831C68209Initialize::GetLocation@ 0X3CC0|15552
11:09:47.5831C68209Initialize::GetLocation@ 0X5FD0|24528
11:09:47.5831C68209Initialize::GetLocation@ 0X6180|24960
11:09:47.5841C6848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X13160000>6|2|1203372033
11:09:47.5941C6893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
11:09:47.5941C68110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
11:09:47.5941C68209Initialize::GetLocation@ 0X10000|65536
11:09:47.5941C68209Initialize::GetLocation@ 0X12C80|76928
11:09:47.5941C68209Initialize::GetLocation@ 0X12A60|76384
11:09:47.6471C68225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_1384 opened succesfuly
11:09:47.6471C6872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
11:09:47.6471C68256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_83_1_1384 close 2147483647 bytes
11:09:47.6471C68297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.162.0.7\OWExplorer.dll]
11:09:47.6671C68385ftw1OWExplorer injected
11:09:53.150300451`anonymous-namespace'::CreateProviderInitialize provider: NET
11:09:53.1503004117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
11:09:53.150300454`anonymous-namespace'::CreateProviderFail to initlized provider: NET
11:09:53.150300451`anonymous-namespace'::CreateProviderInitialize provider: GPU
11:09:53.195798629ProcessInjector::InjectProcessprocess |vpnagent.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |com.docker.service| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |nassvc.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |httpd.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |mysqld.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |httpd.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |tv_w32.exe| missing h
11:09:53.196798629ProcessInjector::InjectProcessprocess |tv_x64.exe| missing h
11:10:46.999798629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
11:10:46.999798629ProcessInjector::InjectProcessprocess |VSIXAutoUpdate.exe| missing h
11:11:16.190798629ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
11:11:37.196798629ProcessInjector::InjectProcessprocess |VSHiveStub.exe| missing h
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [2968] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |2968|: vpnagent.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [3652] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |3652|: com.docker.service
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [3720] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |3720|: gameinputsvc.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [3984] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |3984|: nassvc.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [4024] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |4024|: MsMpEng.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [4044] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |4044|: httpd.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [4092] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |4092|: MicrosoftEdgeUpdate.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [4464] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |4464|: mysqld.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [5204] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |5204|: DropboxUpdate.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [6484] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |6484|: GoogleCrashHandler64.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [7992] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |7992|: httpd.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [11176] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |11176|: gameinputsvc.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [11244] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |11244|: GoogleCrashHandler.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [17132] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |17132|: GoogleUpdate.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [18216] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |18216|: tv_w32.exe
11:12:23.217798441ProcessInjector::HandleElevatedProcessFail injection to process [23084] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x5
11:12:23.217798380ProcessInjector::HandlePendingProccesssFail to inject pending process |23084|: tv_x64.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [3304] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |3304|: rg.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [4548] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |4548|: rg.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [6368] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |6368|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [8208] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |8208|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [8576] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |8576|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [10936] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |10936|: Teams.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [11716] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |11716|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [11836] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |11836|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [13380] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |13380|: Teams.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [13916] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |13916|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [13996] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |13996|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [15768] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |15768|: Teams.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [16456] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |16456|: rg.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [18012] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |18012|: rg.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [18716] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |18716|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [21096] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |21096|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [22188] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |22188|: Code.exe
11:12:25.218798441ProcessInjector::HandleElevatedProcessFail injection to process [23988] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:12:25.218798380ProcessInjector::HandlePendingProccesssFail to inject pending process |23988|: Teams.exe
11:12:31.219798441ProcessInjector::HandleElevatedProcessFail injection to process [16592] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:12:31.219798380ProcessInjector::HandlePendingProccesssFail to inject pending process |16592|: Teams.exe
11:13:34.242798441ProcessInjector::HandleElevatedProcessFail injection to process [5876] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x5
11:13:34.242798380ProcessInjector::HandlePendingProccesssFail to inject pending process |5876|: docker-mutagen.exe
11:13:34.242798441ProcessInjector::HandleElevatedProcessFail injection to process [18372] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x5
11:13:34.242798380ProcessInjector::HandlePendingProccesssFail to inject pending process |18372|: com.docker.backend.exe
11:13:54.253798629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
11:14:12.247798441ProcessInjector::HandleElevatedProcessFail injection to process [12712] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x5
11:14:12.247798380ProcessInjector::HandlePendingProccesssFail to inject pending process |12712|: vpnkit-bridge.exe
11:14:22.251798441ProcessInjector::HandleElevatedProcessFail injection to process [17948] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x5
11:14:22.251798380ProcessInjector::HandlePendingProccesssFail to inject pending process |17948|: vpnkit.exe
11:14:26.250798441ProcessInjector::HandleElevatedProcessFail injection to process [20632] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x5
11:14:26.250798380ProcessInjector::HandlePendingProccesssFail to inject pending process |20632|: com.docker.proxy.exe
11:17:47.266798629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
11:18:03.273798629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
11:20:38.293798441ProcessInjector::HandleElevatedProcessFail injection to process [11320] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:20:38.293798380ProcessInjector::HandlePendingProccesssFail to inject pending process |11320|: Teams.exe
11:22:11.385798629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
11:25:33.731798441ProcessInjector::HandleElevatedProcessFail injection to process [12116] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
11:25:33.731798380ProcessInjector::HandlePendingProccesssFail to inject pending process |12116|: node.exe
11:25:34.727798441ProcessInjector::HandleElevatedProcessFail injection to process [22552] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
11:25:34.727798380ProcessInjector::HandlePendingProccesssFail to inject pending process |22552|: node.exe
11:30:43.18798441ProcessInjector::HandleElevatedProcessFail injection to process [16496] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
11:30:43.18798380ProcessInjector::HandlePendingProccesssFail to inject pending process |16496|: Teams.exe
11:32:40.254798629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
11:33:07.155798441ProcessInjector::HandleElevatedProcessFail injection to process [940] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
11:33:07.155798380ProcessInjector::HandlePendingProccesssFail to inject pending process |940|: Code.exe
11:45:30.970798441ProcessInjector::HandleElevatedProcessFail injection to process [4716] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
11:45:30.970798380ProcessInjector::HandlePendingProccesssFail to inject pending process |4716|: Teams.exe
11:49:51.179798629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
11:51:31.300798441ProcessInjector::HandleElevatedProcessFail injection to process [15704] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
11:51:31.300798380ProcessInjector::HandlePendingProccesssFail to inject pending process |15704|: Teams.exe
12:16:48.119798441ProcessInjector::HandleElevatedProcessFail injection to process [15716] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
12:16:48.119798380ProcessInjector::HandlePendingProccesssFail to inject pending process |15716|: Teams.exe
12:18:03.229798629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
12:20:48.578798441ProcessInjector::HandleElevatedProcessFail injection to process [17844] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
12:20:48.578798380ProcessInjector::HandlePendingProccesssFail to inject pending process |17844|: Teams.exe
12:30:09.430798441ProcessInjector::HandleElevatedProcessFail injection to process [13912] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
12:30:09.430798380ProcessInjector::HandlePendingProccesssFail to inject pending process |13912|: Teams.exe
12:31:17.9721C6866ProcessesMonitor::Stopstopping PM...
12:31:17.9723004119ProcessesMonitor::ProcessEnumerateThreadexit process listener
12:31:24.901C6866ProcessesMonitor::Stopstopping PM...