TimeThreadLineFunctionMessage
00:29:34.188313C361ftw1Loading (pid: 21824)
00:29:34.1883898146ProcessHardwareRecorder::CommandThreadstarting recorder thread
00:29:34.190313C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0X34220000>6|2|1247870977
00:29:34.190313C48Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0X3A1F0000>6|2|1247871464
00:29:34.250313C172DXManager::DetectFound in 0
00:29:34.250313C209Initialize::GetLocation@ 0X4F80|20352
00:29:34.250313C209Initialize::GetLocation@ 0X69530|431408
00:29:34.250313C209Initialize::GetLocation@ 0X20410|132112
00:29:34.250313C209Initialize::GetLocation@ 0X1DE0|7648
00:29:34.250313C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
00:29:34.250313C209Initialize::GetLocation@ 0XFA158850|-99252144
00:29:34.250313C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
00:29:34.250313C209Initialize::GetLocation@ 0XFA15DE80|-99230080
00:29:34.250313C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
00:29:34.250313C209Initialize::GetLocation@ 0XFA15C5E0|-99236384
00:29:34.250313C111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0X34220000 <> 0X3A1F0000
00:29:34.250313C209Initialize::GetLocation@ 0XFA03A7F0|-100423696
00:29:34.259313C48Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X26BA0000>6|2|1247871464
00:29:34.295313C129DXManager::DetectOK
00:29:34.314313C186DXManager::DetectDone
00:29:34.314313C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
00:29:34.315313C209Initialize::GetLocation@ 0X41000|266240
00:29:34.315313C209Initialize::GetLocation@ 0X332C0|209600
00:29:34.315313C209Initialize::GetLocation@ 0X3CB30|248624
00:29:34.315313C209Initialize::GetLocation@ 0XB72C0|750272
00:29:34.315313C209Initialize::GetLocation@ 0XB6E10|749072
00:29:34.315313C209Initialize::GetLocation@ 0XA190|41360
00:29:34.315313C209Initialize::GetLocation@ 0XB6EB0|749232
00:29:34.315313C209Initialize::GetLocation@ 0X1AB50|109392
00:29:34.315313C209Initialize::GetLocation@ 0X1D5A0|120224
00:29:34.315313C209Initialize::GetLocation@ 0X25BD0|154576
00:29:34.315313C209Initialize::GetLocation@ 0X113530|1127728
00:29:34.315313C209Initialize::GetLocation@ 0X112FF0|1126384
00:29:34.315313C209Initialize::GetLocation@ 0X1AA40|109120
00:29:34.315313C209Initialize::GetLocation@ 0X1A950|108880
00:29:34.315313C209Initialize::GetLocation@ 0XCB20|52000
00:29:34.315313C209Initialize::GetLocation@ 0X47D50|294224
00:29:34.315313C209Initialize::GetLocation@ 0X9D00|40192
00:29:34.315313C209Initialize::GetLocation@ 0XCE4B0|844976
00:29:34.315313C209Initialize::GetLocation@ 0XCEB80|846720
00:29:34.315313C209Initialize::GetLocation@ 0X9D00|40192
00:29:34.315313C209Initialize::GetLocation@ 0XCF670|849520
00:29:34.315313C209Initialize::GetLocation@ 0XCFCD0|851152
00:29:34.327313C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0XD92D0000>6|2|1247870977
00:29:34.345313C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
00:29:34.345313C209Initialize::GetLocation@ 0X4040|16448
00:29:34.345313C209Initialize::GetLocation@ 0X6410|25616
00:29:34.345313C209Initialize::GetLocation@ 0X65C0|26048
00:29:34.347313C48Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0XBDF20000>6|2|1247870977
00:29:34.357313C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
00:29:34.357313C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
00:29:34.357313C209Initialize::GetLocation@ 0XA5D0|42448
00:29:34.357313C209Initialize::GetLocation@ 0XD4D0|54480
00:29:34.357313C209Initialize::GetLocation@ 0XD290|53904
00:29:34.412313C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_21824 opened succesfuly
00:29:34.412313C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
00:29:34.413313C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_3_21824 close 2147483647 bytes
00:29:34.413313C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.1.1\OWExplorer.dll]
00:29:34.499313C385ftw1OWExplorer injected
00:29:35.1914CA051`anonymous-namespace'::CreateProviderInitialize provider: NET
00:29:35.1914CA0117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
00:29:35.1914CA054`anonymous-namespace'::CreateProviderFail to initlized provider: NET
00:29:35.1914CA051`anonymous-namespace'::CreateProviderInitialize provider: GPU
00:32:05.5182818394ProcessInjector::HandleElevatedProcessFail injection to process [2652] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x0
00:32:05.5182818333ProcessInjector::HandlePendingProccesssFail to inject pending process |2652|: NVDisplay.Container.exe
00:32:05.5182818394ProcessInjector::HandleElevatedProcessFail injection to process [4972] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x0
00:32:05.5182818333ProcessInjector::HandlePendingProccesssFail to inject pending process |4972|: nvcontainer.exe
00:32:05.5182818394ProcessInjector::HandleElevatedProcessFail injection to process [5360] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x0
00:32:05.5182818333ProcessInjector::HandlePendingProccesssFail to inject pending process |5360|: MsMpEng.exe
00:32:06.5372818394ProcessInjector::HandleElevatedProcessFail injection to process [480] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |480|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [3624] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |3624|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [4224] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |4224|: Code.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [4236] [t: 0 w_t_id: 0]- init (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |4236|: init
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [4404] [t: 0 w_t_id: 0]- init (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |4404|: init
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [5080] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |5080|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [5152] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |5152|: Code.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [8960] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |8960|: Code.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [9084] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |9084|: Code.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [12032] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |12032|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [12364] [t: 0 w_t_id: 0]- bash (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |12364|: bash
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [13508] [t: 0 w_t_id: 0]- init (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |13508|: init
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [14156] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |14156|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [14400] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |14400|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [15068] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |15068|: node.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [15492] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |15492|: firefox.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [16316] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |16316|: Code.exe
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [16664] [t: 0 w_t_id: 0]- bash (elevated True) 0x0
00:32:06.5382818333ProcessInjector::HandlePendingProccesssFail to inject pending process |16664|: bash
00:32:06.5382818394ProcessInjector::HandleElevatedProcessFail injection to process [18632] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |18632|: firefox.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [19596] [t: 0 w_t_id: 0]- init (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |19596|: init
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [20364] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |20364|: firefox.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [20368] [t: 0 w_t_id: 0]- bash (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |20368|: bash
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [20380] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |20380|: Code.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [20660] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |20660|: firefox.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [21512] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |21512|: Code.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [22056] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |22056|: Code.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [22296] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |22296|: plugin-container.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [22940] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |22940|: firefox.exe
00:32:06.5392818394ProcessInjector::HandleElevatedProcessFail injection to process [23212] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x0
00:32:06.5392818333ProcessInjector::HandlePendingProccesssFail to inject pending process |23212|: Code.exe
00:47:12.6262818394ProcessInjector::HandleElevatedProcessFail injection to process [16460] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f
00:47:12.6262818333ProcessInjector::HandlePendingProccesssFail to inject pending process |16460|: openvpn.exe
01:02:34.6282818394ProcessInjector::HandleElevatedProcessFail injection to process [11112] [t: 0 w_t_id: 0]- plugin-container.exe (elevated True) 0x1f
01:02:34.6282818333ProcessInjector::HandlePendingProccesssFail to inject pending process |11112|: plugin-container.exe
01:27:27.5492818394ProcessInjector::HandleElevatedProcessFail injection to process [6296] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:27:27.5492818333ProcessInjector::HandlePendingProccesssFail to inject pending process |6296|: firefox.exe
01:29:25.1652818394ProcessInjector::HandleElevatedProcessFail injection to process [11584] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x1f
01:29:25.1652818333ProcessInjector::HandlePendingProccesssFail to inject pending process |11584|: firefox.exe
01:34:52.2452818394ProcessInjector::HandleElevatedProcessFail injection to process [15024] [t: 0 w_t_id: 0]- firefox.exe (elevated True) 0x0
01:34:52.2452818333ProcessInjector::HandlePendingProccesssFail to inject pending process |15024|: firefox.exe
01:39:13.92818394ProcessInjector::HandleElevatedProcessFail injection to process [16756] [t: 0 w_t_id: 0]- git.exe (elevated True) 0x1f
01:39:13.102818333ProcessInjector::HandlePendingProccesssFail to inject pending process |16756|: git.exe
01:39:13.102818394ProcessInjector::HandleElevatedProcessFail injection to process [18820] [t: 0 w_t_id: 0]- git.exe (elevated True) 0x1f
01:39:13.102818333ProcessInjector::HandlePendingProccesssFail to inject pending process |18820|: git.exe
01:39:27.1162818394ProcessInjector::HandleElevatedProcessFail injection to process [21704] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x1f
01:39:27.1162818333ProcessInjector::HandlePendingProccesssFail to inject pending process |21704|: node.exe
01:41:03.8172818394ProcessInjector::HandleElevatedProcessFail injection to process [9988] [t: 0 w_t_id: 0]- openvpn.exe (elevated True) 0x1f
01:41:03.8172818333ProcessInjector::HandlePendingProccesssFail to inject pending process |9988|: openvpn.exe
01:52:15.192313C66ProcessesMonitor::Stopstopping PM...
01:52:15.1924CA0119ProcessesMonitor::ProcessEnumerateThreadexit process listener