TimeThreadLineFunctionMessage
12:23:46.3392334361ftw1Loading (pid: 14448)
12:23:46.341233448Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XCA490000>6|2|1203372419
12:23:46.341233448Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XCBB30000>6|2|1203373081
12:23:46.368298C146ProcessHardwareRecorder::CommandThreadstarting recorder thread
12:23:46.4712334172DXManager::DetectFound in 0
12:23:46.4712334209Initialize::GetLocation@ 0X4660|18016
12:23:46.4712334209Initialize::GetLocation@ 0X661F0|418288
12:23:46.4712334209Initialize::GetLocation@ 0X19DB0|105904
12:23:46.4712334209Initialize::GetLocation@ 0X1350|4944
12:23:46.4722334111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XCA490000 <> 0XCBB30000
12:23:46.4722334209Initialize::GetLocation@ 0XFEA82E80|-22532480
12:23:46.4722334111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XCA490000 <> 0XCBB30000
12:23:46.4722334209Initialize::GetLocation@ 0XFEA87F80|-22511744
12:23:46.4722334111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XCA490000 <> 0XCBB30000
12:23:46.4722334209Initialize::GetLocation@ 0XFEA7E620|-22551008
12:23:46.4722334111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XCA490000 <> 0XCBB30000
12:23:46.4722334209Initialize::GetLocation@ 0XFE96AD10|-23679728
12:23:46.493233448Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0XA29B0000>6|2|1203372419
12:23:46.6572334129DXManager::DetectOK
12:23:46.7412334186DXManager::DetectDone
12:23:46.7422334215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
12:23:46.7422334209Initialize::GetLocation@ 0X3AC00|240640
12:23:46.7422334209Initialize::GetLocation@ 0X2C5B0|181680
12:23:46.7422334209Initialize::GetLocation@ 0X36D00|224512
12:23:46.7422334209Initialize::GetLocation@ 0XAE020|712736
12:23:46.7422334209Initialize::GetLocation@ 0XADB70|711536
12:23:46.7422334209Initialize::GetLocation@ 0X5880|22656
12:23:46.7422334209Initialize::GetLocation@ 0XADC10|711696
12:23:46.7422334209Initialize::GetLocation@ 0X20FF0|135152
12:23:46.7422334209Initialize::GetLocation@ 0X1CA60|117344
12:23:46.7422334209Initialize::GetLocation@ 0X1C8E0|116960
12:23:46.7422334209Initialize::GetLocation@ 0X1084E0|1082592
12:23:46.7422334209Initialize::GetLocation@ 0X107F90|1081232
12:23:46.7422334209Initialize::GetLocation@ 0X248B0|149680
12:23:46.7422334209Initialize::GetLocation@ 0X247A0|149408
12:23:46.7422334209Initialize::GetLocation@ 0X2C440|181312
12:23:46.7422334209Initialize::GetLocation@ 0X3F210|258576
12:23:46.7422334209Initialize::GetLocation@ 0XF3E0|62432
12:23:46.7422334209Initialize::GetLocation@ 0XF4E0|62688
12:23:46.7422334209Initialize::GetLocation@ 0XF5D0|62928
12:23:46.7422334209Initialize::GetLocation@ 0XF3E0|62432
12:23:46.7422334209Initialize::GetLocation@ 0XF280|62080
12:23:46.7422334209Initialize::GetLocation@ 0XF430|62512
12:23:46.781233448Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X7F770000>6|2|1203372033
12:23:46.793233483VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
12:23:46.7932334209Initialize::GetLocation@ 0X3CC0|15552
12:23:46.7932334209Initialize::GetLocation@ 0X5FD0|24528
12:23:46.7932334209Initialize::GetLocation@ 0X6180|24960
12:23:46.796233448Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X7F200000>6|2|1203372033
12:23:46.805233493VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
12:23:46.8062334110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
12:23:46.8062334209Initialize::GetLocation@ 0X10000|65536
12:23:46.8062334209Initialize::GetLocation@ 0X12C80|76928
12:23:46.8062334209Initialize::GetLocation@ 0X12A60|76384
12:23:46.8672334225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_14448 opened succesfuly
12:23:46.867233472HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
12:23:46.8672334256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_14448 close 2147483647 bytes
12:23:46.8672334297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.157.0.11\OWExplorer.dll]
12:23:46.9612334385ftw1OWExplorer injected
12:23:47.985523051`anonymous-namespace'::CreateProviderInitialize provider: NET
12:23:47.9855230117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
12:23:47.985523054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
12:23:47.985523051`anonymous-namespace'::CreateProviderInitialize provider: GPU
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [1708] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |1708|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [3136] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |3136|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [4008] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |4008|: MsMpEng.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [7212] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |7212|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [7640] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |7640|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [9444] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |9444|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [11380] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |11380|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [16852] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |16852|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [19580] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |19580|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [25144] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |25144|: Code.exe
12:26:18.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [27952] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
12:26:18.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |27952|: Teams.exe
12:26:20.9616F10394ProcessInjector::HandleElevatedProcessFail injection to process [11844] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
12:26:20.9616F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |11844|: Teams.exe
12:26:30.9806F10394ProcessInjector::HandleElevatedProcessFail injection to process [14360] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x5
12:26:30.9806F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |14360|: com.docker.backend.exe
12:26:31.9836F10394ProcessInjector::HandleElevatedProcessFail injection to process [29884] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x5
12:26:31.9836F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |29884|: docker-mutagen.exe
12:26:45.9846F10394ProcessInjector::HandleElevatedProcessFail injection to process [10412] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
12:26:45.9846F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |10412|: Teams.exe
12:26:47.9886F10394ProcessInjector::HandleElevatedProcessFail injection to process [28028] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x5
12:26:47.9896F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |28028|: vpnkit-bridge.exe
12:27:03.9846F10394ProcessInjector::HandleElevatedProcessFail injection to process [15260] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x5
12:27:03.9846F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |15260|: vpnkit.exe
12:27:36.36F10394ProcessInjector::HandleElevatedProcessFail injection to process [19192] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x5
12:27:36.36F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |19192|: com.docker.proxy.exe
12:29:23.1016F10394ProcessInjector::HandleElevatedProcessFail injection to process [17952] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
12:29:23.1016F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |17952|: Teams.exe
12:41:30.6976F10394ProcessInjector::HandleElevatedProcessFail injection to process [9956] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
12:41:30.6976F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |9956|: Teams.exe
12:45:33.8036F10394ProcessInjector::HandleElevatedProcessFail injection to process [10804] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
12:45:33.8036F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |10804|: Teams.exe
12:48:08.8656F10394ProcessInjector::HandleElevatedProcessFail injection to process [24876] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
12:48:08.8656F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |24876|: Teams.exe
12:53:47.9786F10394ProcessInjector::HandleElevatedProcessFail injection to process [25420] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
12:53:47.9786F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |25420|: Teams.exe
13:04:52.1696F10394ProcessInjector::HandleElevatedProcessFail injection to process [15704] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
13:04:52.1696F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |15704|: Teams.exe
13:08:01.2086F10394ProcessInjector::HandleElevatedProcessFail injection to process [30352] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
13:08:01.2086F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |30352|: Teams.exe
13:20:07.3256F10394ProcessInjector::HandleElevatedProcessFail injection to process [7460] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
13:20:07.3256F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |7460|: Teams.exe
13:23:40.3436F10394ProcessInjector::HandleElevatedProcessFail injection to process [25412] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
13:23:40.3436F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |25412|: Teams.exe
13:37:42.5216F10394ProcessInjector::HandleElevatedProcessFail injection to process [6464] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
13:37:42.5216F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |6464|: Teams.exe
13:43:48.6836F10394ProcessInjector::HandleElevatedProcessFail injection to process [17812] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x1f
13:43:48.6836F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |17812|: Teams.exe
13:57:57.3046F10394ProcessInjector::HandleElevatedProcessFail injection to process [22108] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
13:57:57.3046F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |22108|: Teams.exe
14:03:38.5176F10394ProcessInjector::HandleElevatedProcessFail injection to process [2472] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x5
14:03:38.5176F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |2472|: Teams.exe
14:46:48.4806F10394ProcessInjector::HandleElevatedProcessFail injection to process [1800] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x1f
14:46:48.4806F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |1800|: Microsoft.ServiceHub.Controller.exe
14:47:06.4946F10394ProcessInjector::HandleElevatedProcessFail injection to process [5448] [t: 0 w_t_id: 0]- ServiceHub.TestWindowStoreHost.exe (elevated True) 0x1f
14:47:06.4946F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |5448|: ServiceHub.TestWindowStoreHost.exe
14:58:28.8526F10394ProcessInjector::HandleElevatedProcessFail injection to process [23256] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
14:58:28.8526F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |23256|: node.exe
14:58:28.8526F10394ProcessInjector::HandleElevatedProcessFail injection to process [24520] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
14:58:28.8526F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |24520|: node.exe
18:19:39.2916F10421ProcessInjector::DoElevetedInjectionFailed to inject process [14208] 0x57
18:19:39.2916F10377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [14208] [t: 12284 w_t_id: 12284]- git.exe (elevated True) 0x57
18:19:40.1926F10421ProcessInjector::DoElevetedInjectionFailed to inject process [14208] 0x57
18:19:40.1926F10394ProcessInjector::HandleElevatedProcessFail injection to process [14208] [t: 12284 w_t_id: 12284]- git.exe (elevated True) 0x57
18:19:40.1926F10333ProcessInjector::HandlePendingProccesssFail to inject pending process |14208|: git.exe
19:41:09.776233466ProcessesMonitor::Stopstopping PM...
19:41:09.7775230119ProcessesMonitor::ProcessEnumerateThreadexit process listener
19:41:15.791233466ProcessesMonitor::Stopstopping PM...