TimeThreadLineFunctionMessage
00:28:38.87610C8361ftw1Loading (pid: 11364)
00:28:38.87710C848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X8780000>6|2|1203372419
00:28:38.87810C848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XA160000>6|2|1203373081
00:28:38.8872FA0146ProcessHardwareRecorder::CommandThreadstarting recorder thread
00:28:38.97610C8172DXManager::DetectFound in 0
00:28:38.97710C8209Initialize::GetLocation@ 0X4660|18016
00:28:38.97710C8209Initialize::GetLocation@ 0X661F0|418288
00:28:38.97710C8209Initialize::GetLocation@ 0X19DB0|105904
00:28:38.97710C8209Initialize::GetLocation@ 0X1350|4944
00:28:38.97710C8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8780000 <> 0XA160000
00:28:38.97710C8209Initialize::GetLocation@ 0XFE742E80|-25940352
00:28:38.97710C8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8780000 <> 0XA160000
00:28:38.97710C8209Initialize::GetLocation@ 0XFE747F80|-25919616
00:28:38.97710C8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8780000 <> 0XA160000
00:28:38.97710C8209Initialize::GetLocation@ 0XFE73E620|-25958880
00:28:38.97710C8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X8780000 <> 0XA160000
00:28:38.97710C8209Initialize::GetLocation@ 0XFE62AD10|-27087600
00:28:39.1110C848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0XEB1A0000>6|2|1203372419
00:28:39.8910C8129DXManager::DetectOK
00:28:39.12810C8186DXManager::DetectDone
00:28:39.12910C8215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
00:28:39.12910C8209Initialize::GetLocation@ 0X3AC00|240640
00:28:39.12910C8209Initialize::GetLocation@ 0X2C5B0|181680
00:28:39.12910C8209Initialize::GetLocation@ 0X36D00|224512
00:28:39.12910C8209Initialize::GetLocation@ 0XAE020|712736
00:28:39.12910C8209Initialize::GetLocation@ 0XADB70|711536
00:28:39.12910C8209Initialize::GetLocation@ 0X5880|22656
00:28:39.12910C8209Initialize::GetLocation@ 0XADC10|711696
00:28:39.12910C8209Initialize::GetLocation@ 0X20FF0|135152
00:28:39.12910C8209Initialize::GetLocation@ 0X1CA60|117344
00:28:39.12910C8209Initialize::GetLocation@ 0X1C8E0|116960
00:28:39.12910C8209Initialize::GetLocation@ 0X1084E0|1082592
00:28:39.12910C8209Initialize::GetLocation@ 0X107F90|1081232
00:28:39.12910C8209Initialize::GetLocation@ 0X248B0|149680
00:28:39.12910C8209Initialize::GetLocation@ 0X247A0|149408
00:28:39.12910C8209Initialize::GetLocation@ 0X2C440|181312
00:28:39.12910C8209Initialize::GetLocation@ 0X3F210|258576
00:28:39.12910C8209Initialize::GetLocation@ 0XF3E0|62432
00:28:39.12910C8209Initialize::GetLocation@ 0XF4E0|62688
00:28:39.12910C8209Initialize::GetLocation@ 0XF5D0|62928
00:28:39.12910C8209Initialize::GetLocation@ 0XF3E0|62432
00:28:39.12910C8209Initialize::GetLocation@ 0XF280|62080
00:28:39.12910C8209Initialize::GetLocation@ 0XF430|62512
00:28:39.16710C848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XDA1C0000>6|2|1203372033
00:28:39.17710C883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
00:28:39.17710C8209Initialize::GetLocation@ 0X3CC0|15552
00:28:39.17710C8209Initialize::GetLocation@ 0X5FD0|24528
00:28:39.17710C8209Initialize::GetLocation@ 0X6180|24960
00:28:39.19710C848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XDA000000>6|2|1203372033
00:28:39.20510C893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
00:28:39.20510C8110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
00:28:39.20510C8209Initialize::GetLocation@ 0X10000|65536
00:28:39.20510C8209Initialize::GetLocation@ 0X12C80|76928
00:28:39.20510C8209Initialize::GetLocation@ 0X12A60|76384
00:28:39.25710C8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_2_11364 opened succesfuly
00:28:39.25710C872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
00:28:39.25710C8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_2_11364 close 2147483647 bytes
00:28:39.25710C8297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.0.14\OWExplorer.dll]
00:28:39.31310C8385ftw1OWExplorer injected
00:28:39.666324051`anonymous-namespace'::CreateProviderInitialize provider: NET
00:28:39.6663240117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
00:28:39.666324054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
00:28:39.666324051`anonymous-namespace'::CreateProviderInitialize provider: GPU
00:31:10.4893250394ProcessInjector::HandleElevatedProcessFail injection to process [4032] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
00:31:10.4893250333ProcessInjector::HandlePendingProccesssFail to inject pending process |4032|: MsMpEng.exe
00:31:28.4913250394ProcessInjector::HandleElevatedProcessFail injection to process [7780] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
00:31:28.4913250333ProcessInjector::HandlePendingProccesssFail to inject pending process |7780|: Teams.exe
00:31:28.4913250394ProcessInjector::HandleElevatedProcessFail injection to process [13720] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
00:31:28.4913250333ProcessInjector::HandlePendingProccesssFail to inject pending process |13720|: Teams.exe
00:31:35.4973250394ProcessInjector::HandleElevatedProcessFail injection to process [8368] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0
00:31:35.4973250333ProcessInjector::HandlePendingProccesssFail to inject pending process |8368|: com.docker.backend.exe
00:31:35.4973250394ProcessInjector::HandleElevatedProcessFail injection to process [13328] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x0
00:31:35.4973250333ProcessInjector::HandlePendingProccesssFail to inject pending process |13328|: docker-mutagen.exe
00:31:44.5003250394ProcessInjector::HandleElevatedProcessFail injection to process [17340] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0
00:31:44.5003250333ProcessInjector::HandlePendingProccesssFail to inject pending process |17340|: vpnkit-bridge.exe
00:32:00.4963250394ProcessInjector::HandleElevatedProcessFail injection to process [4404] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0
00:32:00.4963250333ProcessInjector::HandlePendingProccesssFail to inject pending process |4404|: vpnkit.exe
00:32:00.4963250394ProcessInjector::HandleElevatedProcessFail injection to process [6340] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0
00:32:00.4963250333ProcessInjector::HandlePendingProccesssFail to inject pending process |6340|: com.docker.proxy.exe
10:36:34.7923250394ProcessInjector::HandleElevatedProcessFail injection to process [10588] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
10:36:34.7933250333ProcessInjector::HandlePendingProccesssFail to inject pending process |10588|: Teams.exe
10:46:35.5493250394ProcessInjector::HandleElevatedProcessFail injection to process [2316] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:46:35.5493250333ProcessInjector::HandlePendingProccesssFail to inject pending process |2316|: Code.exe
10:46:36.5503250394ProcessInjector::HandleElevatedProcessFail injection to process [3212] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:46:36.5503250333ProcessInjector::HandlePendingProccesssFail to inject pending process |3212|: Code.exe
10:46:39.5493250394ProcessInjector::HandleElevatedProcessFail injection to process [6020] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:46:39.5493250333ProcessInjector::HandlePendingProccesssFail to inject pending process |6020|: Code.exe
10:46:39.5493250394ProcessInjector::HandleElevatedProcessFail injection to process [7716] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:46:39.5493250333ProcessInjector::HandlePendingProccesssFail to inject pending process |7716|: Code.exe
10:46:39.5493250394ProcessInjector::HandleElevatedProcessFail injection to process [10296] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:46:39.5493250333ProcessInjector::HandlePendingProccesssFail to inject pending process |10296|: Code.exe
10:46:41.5763250394ProcessInjector::HandleElevatedProcessFail injection to process [5908] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
10:46:41.5763250333ProcessInjector::HandlePendingProccesssFail to inject pending process |5908|: Code.exe
10:46:44.5603250394ProcessInjector::HandleElevatedProcessFail injection to process [6624] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:46:44.5603250333ProcessInjector::HandlePendingProccesssFail to inject pending process |6624|: rg.exe
10:46:44.5603250394ProcessInjector::HandleElevatedProcessFail injection to process [17444] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:46:44.5603250333ProcessInjector::HandlePendingProccesssFail to inject pending process |17444|: rg.exe
10:46:44.5603250394ProcessInjector::HandleElevatedProcessFail injection to process [17744] [t: 0 w_t_id: 0]- rg.exe (elevated True) 0x5
10:46:44.5603250333ProcessInjector::HandlePendingProccesssFail to inject pending process |17744|: rg.exe
10:47:15.5683250394ProcessInjector::HandleElevatedProcessFail injection to process [12536] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x5
10:47:15.5683250333ProcessInjector::HandlePendingProccesssFail to inject pending process |12536|: Microsoft.ServiceHub.Controller.exe
12:38:29.3413250394ProcessInjector::HandleElevatedProcessFail injection to process [16564] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:38:29.3423250333ProcessInjector::HandlePendingProccesssFail to inject pending process |16564|: Code.exe
12:38:29.3423250394ProcessInjector::HandleElevatedProcessFail injection to process [21940] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:38:29.3423250333ProcessInjector::HandlePendingProccesssFail to inject pending process |21940|: Code.exe
12:38:31.3433250394ProcessInjector::HandleElevatedProcessFail injection to process [7080] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:38:31.3433250333ProcessInjector::HandlePendingProccesssFail to inject pending process |7080|: Code.exe
12:38:31.3433250394ProcessInjector::HandleElevatedProcessFail injection to process [18388] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:38:31.3433250333ProcessInjector::HandlePendingProccesssFail to inject pending process |18388|: Code.exe
12:38:32.3413250394ProcessInjector::HandleElevatedProcessFail injection to process [19132] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:38:32.3413250333ProcessInjector::HandlePendingProccesssFail to inject pending process |19132|: Code.exe
12:38:32.3413250394ProcessInjector::HandleElevatedProcessFail injection to process [21540] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
12:38:32.3413250333ProcessInjector::HandlePendingProccesssFail to inject pending process |21540|: Code.exe
12:38:46.3453250394ProcessInjector::HandleElevatedProcessFail injection to process [17496] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
12:38:46.3453250333ProcessInjector::HandlePendingProccesssFail to inject pending process |17496|: node.exe
12:38:47.3423250394ProcessInjector::HandleElevatedProcessFail injection to process [20132] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
12:38:47.3423250333ProcessInjector::HandlePendingProccesssFail to inject pending process |20132|: node.exe
13:48:49.9653250394ProcessInjector::HandleElevatedProcessFail injection to process [17356] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:48:49.9653250333ProcessInjector::HandlePendingProccesssFail to inject pending process |17356|: Code.exe
13:48:49.9653250394ProcessInjector::HandleElevatedProcessFail injection to process [21080] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:48:49.9653250333ProcessInjector::HandlePendingProccesssFail to inject pending process |21080|: Code.exe
13:48:49.9653250394ProcessInjector::HandleElevatedProcessFail injection to process [21384] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:48:49.9653250333ProcessInjector::HandlePendingProccesssFail to inject pending process |21384|: Code.exe
13:50:35.9553250394ProcessInjector::HandleElevatedProcessFail injection to process [18664] [t: 0 w_t_id: 0]- Microsoft.ServiceHub.Controller.exe (elevated True) 0x5
13:50:35.9553250333ProcessInjector::HandlePendingProccesssFail to inject pending process |18664|: Microsoft.ServiceHub.Controller.exe
13:58:52.2823250394ProcessInjector::HandleElevatedProcessFail injection to process [17324] [t: 0 w_t_id: 0]- ServiceHub.TestWindowStoreHost.exe (elevated True) 0x5
13:58:52.2823250333ProcessInjector::HandlePendingProccesssFail to inject pending process |17324|: ServiceHub.TestWindowStoreHost.exe
14:07:49.9473250394ProcessInjector::HandleElevatedProcessFail injection to process [13428] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
14:07:49.9473250333ProcessInjector::HandlePendingProccesssFail to inject pending process |13428|: Code.exe
14:33:51.2713250394ProcessInjector::HandleElevatedProcessFail injection to process [2608] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
14:33:51.2713250333ProcessInjector::HandlePendingProccesssFail to inject pending process |2608|: Code.exe
15:11:48.5073250421ProcessInjector::DoElevetedInjectionFailed to inject process [22372] 0x57
15:11:48.5073250377ProcessInjector::HandleElevatedProcessFail injection to process (will retry again in 5 ses) [22372] [t: 9036 w_t_id: 9036]- sh.exe (elevated True) 0x57
15:11:49.4323250421ProcessInjector::DoElevetedInjectionFailed to inject process [22372] 0x57
15:11:49.4323250394ProcessInjector::HandleElevatedProcessFail injection to process [22372] [t: 9036 w_t_id: 9036]- sh.exe (elevated True) 0x57
15:11:49.4323250333ProcessInjector::HandlePendingProccesssFail to inject pending process |22372|: sh.exe
15:20:34.58810C866ProcessesMonitor::Stopstopping PM...
15:20:34.5893240119ProcessesMonitor::ProcessEnumerateThreadexit process listener
15:20:40.60910C866ProcessesMonitor::Stopstopping PM...