TimeThreadLineFunctionMessage
07:57:17.66592A8361ftw1Loading (pid: 7304)
07:57:17.66692A848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X65A50000>6|2|1203373203
07:57:17.66792A848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X675A0000>6|2|1203373081
07:57:17.67439C146ProcessHardwareRecorder::CommandThreadstarting recorder thread
07:57:18.14892A8172DXManager::DetectFound in 0
07:57:18.14992A8209Initialize::GetLocation@ 0X4660|18016
07:57:18.14992A8209Initialize::GetLocation@ 0X661F0|418288
07:57:18.14992A8209Initialize::GetLocation@ 0X19DB0|105904
07:57:18.14992A8209Initialize::GetLocation@ 0X1350|4944
07:57:18.14992A8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X65A50000 <> 0X675A0000
07:57:18.14992A8209Initialize::GetLocation@ 0XFE5D3020|-27447264
07:57:18.14992A8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X65A50000 <> 0X675A0000
07:57:18.14992A8209Initialize::GetLocation@ 0XFE5D8060|-27426720
07:57:18.14992A8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X65A50000 <> 0X675A0000
07:57:18.14992A8209Initialize::GetLocation@ 0XFE5CE620|-27466208
07:57:18.14992A8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X65A50000 <> 0X675A0000
07:57:18.14992A8209Initialize::GetLocation@ 0XFE4BAA80|-28595584
07:57:18.54992A848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X3EA30000>6|2|1203373142
07:57:18.67392A8129DXManager::DetectOK
07:57:18.74392A8186DXManager::DetectDone
07:57:18.74592A8215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
07:57:18.74792A8209Initialize::GetLocation@ 0X3AC00|240640
07:57:18.74792A8209Initialize::GetLocation@ 0X2C5B0|181680
07:57:18.74792A8209Initialize::GetLocation@ 0X36D00|224512
07:57:18.74792A8209Initialize::GetLocation@ 0XAE210|713232
07:57:18.74792A8209Initialize::GetLocation@ 0XADD60|712032
07:57:18.74792A8209Initialize::GetLocation@ 0X5880|22656
07:57:18.74792A8209Initialize::GetLocation@ 0XADE00|712192
07:57:18.74792A8209Initialize::GetLocation@ 0X20FF0|135152
07:57:18.74792A8209Initialize::GetLocation@ 0X1CA60|117344
07:57:18.74792A8209Initialize::GetLocation@ 0X1C8E0|116960
07:57:18.74792A8209Initialize::GetLocation@ 0X1086D0|1083088
07:57:18.74792A8209Initialize::GetLocation@ 0X108180|1081728
07:57:18.74792A8209Initialize::GetLocation@ 0X248B0|149680
07:57:18.74792A8209Initialize::GetLocation@ 0X247A0|149408
07:57:18.74792A8209Initialize::GetLocation@ 0X2C440|181312
07:57:18.74792A8209Initialize::GetLocation@ 0X3F3F0|259056
07:57:18.74792A8209Initialize::GetLocation@ 0XF3E0|62432
07:57:18.74792A8209Initialize::GetLocation@ 0XF4E0|62688
07:57:18.74792A8209Initialize::GetLocation@ 0XF5D0|62928
07:57:18.74792A8209Initialize::GetLocation@ 0XF3E0|62432
07:57:18.74792A8209Initialize::GetLocation@ 0XF280|62080
07:57:18.74792A8209Initialize::GetLocation@ 0XF430|62512
07:57:18.83692A848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X20BC0000>6|2|1203372033
07:57:18.84792A883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
07:57:18.84792A8209Initialize::GetLocation@ 0X3CC0|15552
07:57:18.84792A8209Initialize::GetLocation@ 0X5FD0|24528
07:57:18.84792A8209Initialize::GetLocation@ 0X6180|24960
07:57:18.85192A848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X1F660000>6|2|1203372033
07:57:18.85992A893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
07:57:18.85992A8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
07:57:18.85992A8209Initialize::GetLocation@ 0X10000|65536
07:57:18.85992A8209Initialize::GetLocation@ 0X12C80|76928
07:57:18.85992A8209Initialize::GetLocation@ 0X12A60|76384
07:57:18.91392A8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_7304 opened succesfuly
07:57:18.91392A872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
07:57:18.91392A8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_7304 close 2147483647 bytes
07:57:18.91392A8297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.31\OWExplorer.dll]
07:57:18.93692A8385ftw1OWExplorer injected
07:57:19.6719D5C51`anonymous-namespace'::CreateProviderInitialize provider: NET
07:57:19.6719D5C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
07:57:19.6719D5C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
07:57:19.6719D5C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
07:57:19.6819E4C629ProcessInjector::InjectProcessprocess |rtop_svc.exe| missing h
07:57:19.6819E4C629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
07:57:19.6819E4C629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
07:57:19.6819E4C629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
07:57:19.6819E4C629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
07:59:09.1229E4C629ProcessInjector::InjectProcessprocess |BraveUpdate.exe| missing h
07:59:09.1229E4C629ProcessInjector::InjectProcessprocess |BraveUpdate.exe| missing h
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [1696] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |1696|: Teams.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [4044] [t: 0 w_t_id: 0]- rtop_svc.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4044|: rtop_svc.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [4176] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |4176|: MsMpEng.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [6032] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |6032|: GoogleCrashHandler64.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [7932] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |7932|: GoogleCrashHandler.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [8252] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |8252|: EpicWebHelper.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [8380] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |8380|: GoogleUpdate.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [19304] [t: 0 w_t_id: 0]- Likezoid.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |19304|: Likezoid.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [32400] [t: 0 w_t_id: 0]- MicrosoftEdgeUpdate.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |32400|: MicrosoftEdgeUpdate.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [33600] [t: 0 w_t_id: 0]- Likezoid.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |33600|: Likezoid.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [36180] [t: 0 w_t_id: 0]- rzappengine.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |36180|: rzappengine.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [36196] [t: 0 w_t_id: 0]- rzappengine.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |36196|: rzappengine.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [37644] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |37644|: Teams.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [37836] [t: 0 w_t_id: 0]- rzappengine.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |37836|: rzappengine.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [38712] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |38712|: Teams.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [38868] [t: 0 w_t_id: 0]- EpicWebHelper.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |38868|: EpicWebHelper.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [39852] [t: 0 w_t_id: 0]- Medal.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |39852|: Medal.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [40300] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |40300|: Teams.exe
07:59:50.1209E4C441ProcessInjector::HandleElevatedProcessFail injection to process [40552] [t: 0 w_t_id: 0]- Medal.exe (elevated True) 0x0
07:59:50.1209E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |40552|: Medal.exe
07:59:51.1199E4C441ProcessInjector::HandleElevatedProcessFail injection to process [40216] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
07:59:51.1199E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |40216|: Teams.exe
08:02:10.1379E4C629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
08:20:52.3099E4C441ProcessInjector::HandleElevatedProcessFail injection to process [21876] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
08:20:52.3099E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |21876|: Teams.exe
08:24:46.7609E4C441ProcessInjector::HandleElevatedProcessFail injection to process [25188] [t: 0 w_t_id: 0]- EOSOverlayRenderer-Win64-Shipping.exe (elevated True) 0x578
08:24:46.7609E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |25188|: EOSOverlayRenderer-Win64-Shipping.exe
08:24:56.7639E4C441ProcessInjector::HandleElevatedProcessFail injection to process [41340] [t: 0 w_t_id: 0]- EOSOverlayRenderer-Win64-Shipping.exe (elevated True) 0x578
08:24:56.7639E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |41340|: EOSOverlayRenderer-Win64-Shipping.exe
08:28:24.9129E4C441ProcessInjector::HandleElevatedProcessFail injection to process [23964] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x578
08:28:24.9129E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |23964|: Teams.exe
08:33:35.2559E4C441ProcessInjector::HandleElevatedProcessFail injection to process [26244] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x578
08:33:35.2559E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |26244|: Teams.exe
08:43:17.3829E4C441ProcessInjector::HandleElevatedProcessFail injection to process [12824] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x578
08:43:17.3829E4C380ProcessInjector::HandlePendingProccesssFail to inject pending process |12824|: Teams.exe
08:45:10.97692A866ProcessesMonitor::Stopstopping PM...
08:45:10.9769D5C119ProcessesMonitor::ProcessEnumerateThreadexit process listener
08:45:10.98192A8526ProcessInjector::Unhookunhook running process
08:45:16.99592A866ProcessesMonitor::Stopstopping PM...