TimeThreadLineFunctionMessage
16:19:06.54835E8363ftw1Loading (pid: 14356)
16:19:06.5483650146ProcessHardwareRecorder::CommandThreadstarting recorder thread
16:19:06.54935E848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X9F280000>6|2|1164115969
16:19:06.54935E848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XA0D30000>6|2|1164116739
16:19:06.60235E8169DXManager::DetectFound in 0
16:19:06.60335E8209Initialize::GetLocation@ 0X4910|18704
16:19:06.60335E8209Initialize::GetLocation@ 0X632C0|406208
16:19:06.60335E8209Initialize::GetLocation@ 0X1EEC0|126656
16:19:06.60335E8209Initialize::GetLocation@ 0X1D70|7536
16:19:06.60335E8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9F280000 <> 0XA0D30000
16:19:06.60335E8209Initialize::GetLocation@ 0XFE67AB00|-26760448
16:19:06.60335E8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9F280000 <> 0XA0D30000
16:19:06.60335E8209Initialize::GetLocation@ 0XFE681400|-26733568
16:19:06.60335E8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9F280000 <> 0XA0D30000
16:19:06.60335E8209Initialize::GetLocation@ 0XFE676DE0|-26776096
16:19:06.60335E8111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X9F280000 <> 0XA0D30000
16:19:06.60335E8209Initialize::GetLocation@ 0XFE55E9B0|-27924048
16:19:06.61335E848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X86EC0000>6|2|1164115969
16:19:06.67035E8128DXManager::DetectOK
16:19:06.69135E8185DXManager::DetectDone
16:19:06.69135E8214VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
16:19:06.69135E8209Initialize::GetLocation@ 0X3A040|237632
16:19:06.69135E8209Initialize::GetLocation@ 0X2DDD0|187856
16:19:06.69135E8209Initialize::GetLocation@ 0X35C40|220224
16:19:06.69135E8209Initialize::GetLocation@ 0XAA4D0|697552
16:19:06.69135E8209Initialize::GetLocation@ 0XAA020|696352
16:19:06.69135E8209Initialize::GetLocation@ 0X62B0|25264
16:19:06.69135E8209Initialize::GetLocation@ 0XAA0C0|696512
16:19:06.69135E8209Initialize::GetLocation@ 0X25DA0|155040
16:19:06.69135E8209Initialize::GetLocation@ 0X1E230|123440
16:19:06.69135E8209Initialize::GetLocation@ 0X1E0B0|123056
16:19:06.69135E8209Initialize::GetLocation@ 0XEBAA0|965280
16:19:06.69135E8209Initialize::GetLocation@ 0XEB550|963920
16:19:06.69135E8209Initialize::GetLocation@ 0X25ED0|155344
16:19:06.69135E8209Initialize::GetLocation@ 0X25C90|154768
16:19:06.69135E8209Initialize::GetLocation@ 0X2DC80|187520
16:19:06.69135E8209Initialize::GetLocation@ 0X3CFB0|249776
16:19:06.69135E8209Initialize::GetLocation@ 0X10CD0|68816
16:19:06.69135E8209Initialize::GetLocation@ 0X10DD0|69072
16:19:06.69135E8209Initialize::GetLocation@ 0X10EC0|69312
16:19:06.69135E8209Initialize::GetLocation@ 0X10CD0|68816
16:19:06.69135E8209Initialize::GetLocation@ 0X10B70|68464
16:19:06.69135E8209Initialize::GetLocation@ 0X10D20|68896
16:19:06.70635E848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X99FA0000>6|2|1164115969
16:19:06.71235E883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
16:19:06.71235E8209Initialize::GetLocation@ 0X3D10|15632
16:19:06.71235E8209Initialize::GetLocation@ 0X6130|24880
16:19:06.71235E8209Initialize::GetLocation@ 0X62E0|25312
16:19:06.71335E848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X91FF0000>6|2|1164115969
16:19:06.71735E891VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
16:19:06.71735E8108VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
16:19:06.71735E8209Initialize::GetLocation@ 0X100B0|65712
16:19:06.71735E8209Initialize::GetLocation@ 0X12DE0|77280
16:19:06.71735E8209Initialize::GetLocation@ 0X12BB0|76720
16:19:06.76935E8225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_73_6_14356 opened succesfuly
16:19:06.76935E872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
16:19:06.76935E8256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_73_6_14356 close 2147483647 bytes
16:19:06.76935E8299InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.135.0.24\OWExplorer.dll]
16:19:06.77035E8387ftw1OWExplorer injected
16:19:06.8731B7851`anonymous-namespace'::CreateProviderInitialize provider: NET
16:19:06.8731B78117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
16:19:06.8731B7854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
16:19:06.8731B7851`anonymous-namespace'::CreateProviderInitialize provider: GPU
16:21:37.7672F84349ProcessInjector::HandleElevatedProcessFail injection to process [1580] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
16:21:37.7672F84288ProcessInjector::HandlePendingProccesssFail to inject pending process |1580|: NVDisplay.Container.exe
16:21:37.7672F84349ProcessInjector::HandleElevatedProcessFail injection to process [3500] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
16:21:37.7672F84288ProcessInjector::HandlePendingProccesssFail to inject pending process |3500|: nvcontainer.exe
16:21:37.7672F84349ProcessInjector::HandleElevatedProcessFail injection to process [3540] [t: 0 w_t_id: 0]- NvTelemetryContainer.exe (elevated True) 0x0
16:21:37.7672F84288ProcessInjector::HandlePendingProccesssFail to inject pending process |3540|: NvTelemetryContainer.exe
16:21:37.7672F84349ProcessInjector::HandleElevatedProcessFail injection to process [3744] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
16:21:37.7672F84288ProcessInjector::HandlePendingProccesssFail to inject pending process |3744|: MsMpEng.exe
16:21:37.7672F84349ProcessInjector::HandleElevatedProcessFail injection to process [13008] [t: 0 w_t_id: 0]- plugin_host.exe (elevated True) 0x0
16:21:37.7672F84288ProcessInjector::HandlePendingProccesssFail to inject pending process |13008|: plugin_host.exe