TimeThreadLineFunctionMessage
10:45:03.1193A70363ftw1Loading (pid: 1640)
10:45:03.119C94146ProcessHardwareRecorder::CommandThreadstarting recorder thread
10:45:03.1203A7048Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XF65B0000>6|2|1203372361
10:45:03.1203A7048Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XF7F30000>6|2|1203372361
10:45:03.1613A70169DXManager::DetectFound in 0
10:45:03.1613A70209Initialize::GetLocation@ 0X4300|17152
10:45:03.1613A70209Initialize::GetLocation@ 0X66290|418448
10:45:03.1613A70209Initialize::GetLocation@ 0X19A50|105040
10:45:03.1613A70209Initialize::GetLocation@ 0X1350|4944
10:45:03.1613A70111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF65B0000 <> 0XF7F30000
10:45:03.1613A70209Initialize::GetLocation@ 0XFE7A2E80|-25547136
10:45:03.1613A70111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF65B0000 <> 0XF7F30000
10:45:03.1613A70209Initialize::GetLocation@ 0XFE7A7F80|-25526400
10:45:03.1613A70111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF65B0000 <> 0XF7F30000
10:45:03.1613A70209Initialize::GetLocation@ 0XFE79E620|-25565664
10:45:03.1613A70111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XF65B0000 <> 0XF7F30000
10:45:03.1613A70209Initialize::GetLocation@ 0XFE68AD10|-26694384
10:45:03.1713A7048Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0XBE030000>6|2|1203372361
10:45:03.2173A70128DXManager::DetectOK
10:45:03.2483A70185DXManager::DetectDone
10:45:03.2483A70214VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
10:45:03.2483A70209Initialize::GetLocation@ 0X3AC00|240640
10:45:03.2493A70209Initialize::GetLocation@ 0X2C5B0|181680
10:45:03.2493A70209Initialize::GetLocation@ 0X36D00|224512
10:45:03.2493A70209Initialize::GetLocation@ 0XAE020|712736
10:45:03.2493A70209Initialize::GetLocation@ 0XADB70|711536
10:45:03.2493A70209Initialize::GetLocation@ 0X5880|22656
10:45:03.2493A70209Initialize::GetLocation@ 0XADC10|711696
10:45:03.2493A70209Initialize::GetLocation@ 0X20FF0|135152
10:45:03.2493A70209Initialize::GetLocation@ 0X1CA60|117344
10:45:03.2493A70209Initialize::GetLocation@ 0X1C8E0|116960
10:45:03.2493A70209Initialize::GetLocation@ 0X1084C0|1082560
10:45:03.2493A70209Initialize::GetLocation@ 0X107F70|1081200
10:45:03.2493A70209Initialize::GetLocation@ 0X248B0|149680
10:45:03.2493A70209Initialize::GetLocation@ 0X247A0|149408
10:45:03.2493A70209Initialize::GetLocation@ 0X2C440|181312
10:45:03.2493A70209Initialize::GetLocation@ 0X3F200|258560
10:45:03.2493A70209Initialize::GetLocation@ 0XF3E0|62432
10:45:03.2493A70209Initialize::GetLocation@ 0XF4E0|62688
10:45:03.2493A70209Initialize::GetLocation@ 0XF5D0|62928
10:45:03.2493A70209Initialize::GetLocation@ 0XF3E0|62432
10:45:03.2493A70209Initialize::GetLocation@ 0XF280|62080
10:45:03.2493A70209Initialize::GetLocation@ 0XF430|62512
10:45:03.2733A7048Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XD4270000>6|2|1203372033
10:45:03.3463A7083VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
10:45:03.3463A70209Initialize::GetLocation@ 0X3CC0|15552
10:45:03.3463A70209Initialize::GetLocation@ 0X5FD0|24528
10:45:03.3463A70209Initialize::GetLocation@ 0X6180|24960
10:45:03.3603A7048Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XC9110000>6|2|1203372033
10:45:03.3693A7091VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
10:45:03.3693A70108VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
10:45:03.3693A70209Initialize::GetLocation@ 0X10000|65536
10:45:03.3693A70209Initialize::GetLocation@ 0X12C80|76928
10:45:03.3693A70209Initialize::GetLocation@ 0X12A60|76384
10:45:03.4213A70225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_72_5_1640 opened succesfuly
10:45:03.4213A7072HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
10:45:03.4213A70256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_72_5_1640 close 2147483647 bytes
10:45:03.4213A70299InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.134.0.26\OWExplorer.dll]
10:45:03.4573A70387ftw1OWExplorer injected
10:45:03.656B2451`anonymous-namespace'::CreateProviderInitialize provider: NET
10:45:03.656B24120libprocess::NetworkTracer::Initializeinit res:0x0 [started:1 active:1 enbaled:1]
10:45:03.656B2451`anonymous-namespace'::CreateProviderInitialize provider: GPU
10:47:34.5362ED4349ProcessInjector::HandleElevatedProcessFail injection to process [5064] [t: 0 w_t_id: 0]- NisSrv.exe (elevated True) 0x0
10:47:34.5362ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |5064|: NisSrv.exe
10:47:34.5362ED4349ProcessInjector::HandleElevatedProcessFail injection to process [9652] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
10:47:34.5362ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |9652|: QtWebEngineProcess.exe
10:47:34.5362ED4349ProcessInjector::HandleElevatedProcessFail injection to process [9772] [t: 0 w_t_id: 0]- QtWebEngineProcess.exe (elevated True) 0x0
10:47:34.5362ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |9772|: QtWebEngineProcess.exe
10:47:34.5362ED4349ProcessInjector::HandleElevatedProcessFail injection to process [14524] [t: 0 w_t_id: 0]- browsernativehost.exe (elevated True) 0x0
10:47:34.5362ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |14524|: browsernativehost.exe
14:33:47.5562ED4349ProcessInjector::HandleElevatedProcessFail injection to process [18680] [t: 0 w_t_id: 0]- dynamiclinkmanager.exe (elevated True) 0x0
14:33:47.5582ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |18680|: dynamiclinkmanager.exe
14:33:50.5572ED4349ProcessInjector::HandleElevatedProcessFail injection to process [12388] [t: 0 w_t_id: 0]- TeamProjectsLocalHub.exe (elevated True) 0x0
14:33:50.5572ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |12388|: TeamProjectsLocalHub.exe
14:33:53.5572ED4349ProcessInjector::HandleElevatedProcessFail injection to process [19264] [t: 0 w_t_id: 0]- browsernativehost.exe (elevated True) 0x0
14:33:53.5572ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |19264|: browsernativehost.exe
16:49:39.1792ED4349ProcessInjector::HandleElevatedProcessFail injection to process [4260] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x0
16:49:39.1792ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |4260|: splwow64.exe
18:35:58.5842ED4349ProcessInjector::HandleElevatedProcessFail injection to process [25468] [t: 0 w_t_id: 0]- ffmpeg-win64.exe (elevated True) 0x0
18:35:58.5842ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |25468|: ffmpeg-win64.exe
18:50:43.8432ED4349ProcessInjector::HandleElevatedProcessFail injection to process [19764] [t: 0 w_t_id: 0]- TeamProjectsLocalHub.exe (elevated True) 0x0
18:50:43.8452ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |19764|: TeamProjectsLocalHub.exe
18:58:58.9232ED4349ProcessInjector::HandleElevatedProcessFail injection to process [6980] [t: 0 w_t_id: 0]- TeamProjectsLocalHub.exe (elevated True) 0x0
18:58:58.9242ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |6980|: TeamProjectsLocalHub.exe
19:03:36.9762ED4349ProcessInjector::HandleElevatedProcessFail injection to process [25184] [t: 0 w_t_id: 0]- dynamiclinkmanager.exe (elevated True) 0x0
19:03:36.9772ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |25184|: dynamiclinkmanager.exe
19:03:39.9792ED4349ProcessInjector::HandleElevatedProcessFail injection to process [15060] [t: 0 w_t_id: 0]- TeamProjectsLocalHub.exe (elevated True) 0x0
19:03:39.9792ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |15060|: TeamProjectsLocalHub.exe
19:13:54.1042ED4349ProcessInjector::HandleElevatedProcessFail injection to process [27760] [t: 0 w_t_id: 0]- TeamProjectsLocalHub.exe (elevated True) 0x0
19:13:54.1062ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |27760|: TeamProjectsLocalHub.exe
20:04:18.8862ED4349ProcessInjector::HandleElevatedProcessFail injection to process [6224] [t: 0 w_t_id: 0]- Adobe Spaces Helper.exe (elevated True) 0x0
20:04:18.8862ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |6224|: Adobe Spaces Helper.exe
20:04:18.8862ED4349ProcessInjector::HandleElevatedProcessFail injection to process [13864] [t: 0 w_t_id: 0]- Adobe Spaces Helper.exe (elevated True) 0x0
20:04:18.8862ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |13864|: Adobe Spaces Helper.exe
20:04:18.8862ED4349ProcessInjector::HandleElevatedProcessFail injection to process [31248] [t: 0 w_t_id: 0]- Adobe Spaces Helper.exe (elevated True) 0x0
20:04:18.8862ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |31248|: Adobe Spaces Helper.exe
20:04:19.8902ED4349ProcessInjector::HandleElevatedProcessFail injection to process [7560] [t: 0 w_t_id: 0]- CEPHtmlEngine.exe (elevated True) 0x0
20:04:19.8902ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |7560|: CEPHtmlEngine.exe
20:04:19.8902ED4349ProcessInjector::HandleElevatedProcessFail injection to process [13440] [t: 0 w_t_id: 0]- dynamiclinkmanager.exe (elevated True) 0x0
20:04:19.8902ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |13440|: dynamiclinkmanager.exe
20:04:19.8902ED4349ProcessInjector::HandleElevatedProcessFail injection to process [17748] [t: 0 w_t_id: 0]- Adobe Spaces Helper.exe (elevated True) 0x0
20:04:19.8902ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |17748|: Adobe Spaces Helper.exe
20:04:19.8902ED4349ProcessInjector::HandleElevatedProcessFail injection to process [27020] [t: 0 w_t_id: 0]- CEPHtmlEngine.exe (elevated True) 0x0
20:04:19.8902ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |27020|: CEPHtmlEngine.exe
20:04:53.8872ED4349ProcessInjector::HandleElevatedProcessFail injection to process [27516] [t: 0 w_t_id: 0]- CEPHtmlEngine.exe (elevated True) 0x0
20:04:53.8872ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |27516|: CEPHtmlEngine.exe
20:07:16.9002ED4349ProcessInjector::HandleElevatedProcessFail injection to process [1936] [t: 0 w_t_id: 0]- cef-bootstrap.exe (elevated True) 0x0
20:07:16.9002ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |1936|: cef-bootstrap.exe
20:07:16.9002ED4349ProcessInjector::HandleElevatedProcessFail injection to process [13208] [t: 0 w_t_id: 0]- cef-bootstrap.exe (elevated True) 0x0
20:07:16.9002ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |13208|: cef-bootstrap.exe
20:07:16.9002ED4349ProcessInjector::HandleElevatedProcessFail injection to process [13880] [t: 0 w_t_id: 0]- cef-bootstrap.exe (elevated True) 0x0
20:07:16.9002ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |13880|: cef-bootstrap.exe
20:07:16.9002ED4349ProcessInjector::HandleElevatedProcessFail injection to process [15588] [t: 0 w_t_id: 0]- cef-bootstrap.exe (elevated True) 0x0
20:07:16.9002ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |15588|: cef-bootstrap.exe
20:07:17.9022ED4349ProcessInjector::HandleElevatedProcessFail injection to process [21000] [t: 0 w_t_id: 0]- cef-bootstrap.exe (elevated True) 0x0
20:07:17.9022ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |21000|: cef-bootstrap.exe
20:07:17.9022ED4349ProcessInjector::HandleElevatedProcessFail injection to process [28444] [t: 0 w_t_id: 0]- cef-bootstrap.exe (elevated True) 0x0
20:07:17.9022ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |28444|: cef-bootstrap.exe
23:03:32.3212ED4349ProcessInjector::HandleElevatedProcessFail injection to process [18892] [t: 0 w_t_id: 0]- browsernativehost.exe (elevated True) 0x0
23:03:32.3212ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |18892|: browsernativehost.exe
00:35:02.5052ED4349ProcessInjector::HandleElevatedProcessFail injection to process [31316] [t: 0 w_t_id: 0]- browsernativehost.exe (elevated True) 0x0
00:35:02.5052ED4288ProcessInjector::HandlePendingProccesssFail to inject pending process |31316|: browsernativehost.exe