TimeThreadLineFunctionMessage
17:41:54.301405C361ftw1Loading (pid: 13096)
17:41:54.304405C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X581C0000>6|2|1203372419
17:41:54.304405C48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X59BC0000>6|2|1203372847
17:41:54.3194044146ProcessHardwareRecorder::CommandThreadstarting recorder thread
17:41:54.510405C172DXManager::DetectFound in 0
17:41:54.510405C209Initialize::GetLocation@ 0X4670|18032
17:41:54.510405C209Initialize::GetLocation@ 0X66400|418816
17:41:54.510405C209Initialize::GetLocation@ 0X19DE0|105952
17:41:54.510405C209Initialize::GetLocation@ 0X1350|4944
17:41:54.510405C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X581C0000 <> 0X59BC0000
17:41:54.510405C209Initialize::GetLocation@ 0XFE722E80|-26071424
17:41:54.510405C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X581C0000 <> 0X59BC0000
17:41:54.510405C209Initialize::GetLocation@ 0XFE727F80|-26050688
17:41:54.510405C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X581C0000 <> 0X59BC0000
17:41:54.510405C209Initialize::GetLocation@ 0XFE71E620|-26089952
17:41:54.510405C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X581C0000 <> 0X59BC0000
17:41:54.510405C209Initialize::GetLocation@ 0XFE60AD10|-27218672
17:41:54.790405C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X22E50000>6|2|1203372419
17:41:55.10405C129DXManager::DetectOK
17:41:55.162405C186DXManager::DetectDone
17:41:55.162405C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
17:41:55.163405C209Initialize::GetLocation@ 0X3AC00|240640
17:41:55.163405C209Initialize::GetLocation@ 0X2C5B0|181680
17:41:55.163405C209Initialize::GetLocation@ 0X36D00|224512
17:41:55.163405C209Initialize::GetLocation@ 0XAE020|712736
17:41:55.163405C209Initialize::GetLocation@ 0XADB70|711536
17:41:55.163405C209Initialize::GetLocation@ 0X5880|22656
17:41:55.163405C209Initialize::GetLocation@ 0XADC10|711696
17:41:55.163405C209Initialize::GetLocation@ 0X20FF0|135152
17:41:55.163405C209Initialize::GetLocation@ 0X1CA60|117344
17:41:55.163405C209Initialize::GetLocation@ 0X1C8E0|116960
17:41:55.163405C209Initialize::GetLocation@ 0X1084E0|1082592
17:41:55.163405C209Initialize::GetLocation@ 0X107F90|1081232
17:41:55.163405C209Initialize::GetLocation@ 0X248B0|149680
17:41:55.163405C209Initialize::GetLocation@ 0X247A0|149408
17:41:55.163405C209Initialize::GetLocation@ 0X2C440|181312
17:41:55.163405C209Initialize::GetLocation@ 0X3F210|258576
17:41:55.163405C209Initialize::GetLocation@ 0XF3E0|62432
17:41:55.163405C209Initialize::GetLocation@ 0XF4E0|62688
17:41:55.163405C209Initialize::GetLocation@ 0XF5D0|62928
17:41:55.163405C209Initialize::GetLocation@ 0XF3E0|62432
17:41:55.163405C209Initialize::GetLocation@ 0XF280|62080
17:41:55.163405C209Initialize::GetLocation@ 0XF430|62512
17:41:55.196405C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X36490000>6|2|1203372033
17:41:55.208405C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
17:41:55.208405C209Initialize::GetLocation@ 0X3CC0|15552
17:41:55.208405C209Initialize::GetLocation@ 0X5FD0|24528
17:41:55.208405C209Initialize::GetLocation@ 0X6180|24960
17:41:55.211405C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X21460000>6|2|1203372033
17:41:55.221405C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
17:41:55.223405C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
17:41:55.223405C209Initialize::GetLocation@ 0X10000|65536
17:41:55.223405C209Initialize::GetLocation@ 0X12C80|76928
17:41:55.223405C209Initialize::GetLocation@ 0X12A60|76384
17:41:55.274405C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_2_13096 opened succesfuly
17:41:55.275405C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
17:41:55.275405C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_2_13096 close 2147483647 bytes
17:41:55.275405C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.0.14\OWExplorer.dll]
17:41:55.383405C385ftw1OWExplorer injected
17:41:57.7437F851`anonymous-namespace'::CreateProviderInitialize provider: NET
17:41:57.7437F8117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
17:41:57.7437F854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
17:41:57.7437F851`anonymous-namespace'::CreateProviderInitialize provider: GPU
17:44:27.96546E0394ProcessInjector::HandleElevatedProcessFail injection to process [2252] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
17:44:27.96546E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |2252|: software_reporter_tool.exe
17:44:27.96546E0394ProcessInjector::HandleElevatedProcessFail injection to process [3816] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
17:44:27.96546E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |3816|: MsMpEng.exe
17:44:27.96546E0394ProcessInjector::HandleElevatedProcessFail injection to process [16060] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
17:44:27.96546E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |16060|: software_reporter_tool.exe
17:44:27.96546E0394ProcessInjector::HandleElevatedProcessFail injection to process [25884] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
17:44:27.96546E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |25884|: software_reporter_tool.exe
17:44:28.97046E0394ProcessInjector::HandleElevatedProcessFail injection to process [12684] [t: 0 w_t_id: 0]- docker-mutagen.exe (elevated True) 0x0
17:44:28.97046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |12684|: docker-mutagen.exe
17:44:28.97046E0394ProcessInjector::HandleElevatedProcessFail injection to process [16168] [t: 0 w_t_id: 0]- com.docker.backend.exe (elevated True) 0x0
17:44:28.97046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |16168|: com.docker.backend.exe
17:44:28.97046E0394ProcessInjector::HandleElevatedProcessFail injection to process [23688] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
17:44:28.97046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |23688|: Teams.exe
17:44:28.97046E0394ProcessInjector::HandleElevatedProcessFail injection to process [24344] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
17:44:28.97046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |24344|: Teams.exe
17:44:36.96646E0394ProcessInjector::HandleElevatedProcessFail injection to process [19832] [t: 0 w_t_id: 0]- vpnkit-bridge.exe (elevated True) 0x0
17:44:36.96646E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |19832|: vpnkit-bridge.exe
17:44:53.97146E0394ProcessInjector::HandleElevatedProcessFail injection to process [19552] [t: 0 w_t_id: 0]- vpnkit.exe (elevated True) 0x0
17:44:53.97146E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |19552|: vpnkit.exe
17:44:59.96946E0394ProcessInjector::HandleElevatedProcessFail injection to process [23672] [t: 0 w_t_id: 0]- com.docker.proxy.exe (elevated True) 0x0
17:44:59.96946E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |23672|: com.docker.proxy.exe
20:20:04.9046E0394ProcessInjector::HandleElevatedProcessFail injection to process [18976] [t: 0 w_t_id: 0]- Teams.exe (elevated True) 0x0
20:20:04.9046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |18976|: Teams.exe
20:23:33.18046E0394ProcessInjector::HandleElevatedProcessFail injection to process [11544] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:23:33.18046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |11544|: Code.exe
20:23:33.18046E0394ProcessInjector::HandleElevatedProcessFail injection to process [23296] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:23:33.18046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |23296|: Code.exe
20:23:34.19346E0394ProcessInjector::HandleElevatedProcessFail injection to process [24560] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:23:34.19346E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |24560|: Code.exe
20:23:35.17146E0394ProcessInjector::HandleElevatedProcessFail injection to process [6280] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:23:35.17146E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |6280|: Code.exe
20:23:35.17146E0394ProcessInjector::HandleElevatedProcessFail injection to process [15936] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:23:35.17146E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |15936|: Code.exe
20:23:41.16246E0394ProcessInjector::HandleElevatedProcessFail injection to process [10856] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x1f
20:23:41.16246E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |10856|: Code.exe
20:54:07.42046E0394ProcessInjector::HandleElevatedProcessFail injection to process [10224] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
20:54:07.42046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |10224|: Code.exe
20:54:07.42046E0394ProcessInjector::HandleElevatedProcessFail injection to process [23276] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
20:54:07.42046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |23276|: Code.exe
20:54:07.42046E0394ProcessInjector::HandleElevatedProcessFail injection to process [27216] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
20:54:07.42046E0333ProcessInjector::HandlePendingProccesssFail to inject pending process |27216|: Code.exe
00:25:24.121405C66ProcessesMonitor::Stopstopping PM...
00:25:24.1217F8119ProcessesMonitor::ProcessEnumerateThreadexit process listener