TimeThreadLineFunctionMessage
10:31:32.9352E4C361ftw1Loading (pid: 8320)
10:31:32.935A84146ProcessHardwareRecorder::CommandThreadstarting recorder thread
10:31:32.9372E4C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d11.dll) <0X85790000>6|2|1247870977
10:31:32.9372E4C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dxgi.dll) <0X87D70000>6|2|1247871464
10:31:33.662E4C172DXManager::DetectFound in 0
10:31:33.662E4C209Initialize::GetLocation@ 0X4F80|20352
10:31:33.662E4C209Initialize::GetLocation@ 0X69530|431408
10:31:33.662E4C209Initialize::GetLocation@ 0X20410|132112
10:31:33.662E4C209Initialize::GetLocation@ 0X1DE0|7648
10:31:33.662E4C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85790000 <> 0X87D70000
10:31:33.662E4C209Initialize::GetLocation@ 0XFDB48850|-38500272
10:31:33.662E4C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85790000 <> 0X87D70000
10:31:33.662E4C209Initialize::GetLocation@ 0XFDB4DE80|-38478208
10:31:33.662E4C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85790000 <> 0X87D70000
10:31:33.662E4C209Initialize::GetLocation@ 0XFDB4C5E0|-38484512
10:31:33.662E4C111Update::CaughtC:\WINDOWS\SYSTEM32\d3d11.dll|0X85790000 <> 0X87D70000
10:31:33.662E4C209Initialize::GetLocation@ 0XFDA2A7F0|-39671824
10:31:33.802E4C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\d3d9.dll) <0X80580000>6|2|1247871464
10:31:33.2212E4C129DXManager::DetectOK
10:31:33.2762E4C186DXManager::DetectDone
10:31:33.2762E4C215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
10:31:33.2772E4C209Initialize::GetLocation@ 0X41000|266240
10:31:33.2772E4C209Initialize::GetLocation@ 0X332C0|209600
10:31:33.2772E4C209Initialize::GetLocation@ 0X3CB30|248624
10:31:33.2772E4C209Initialize::GetLocation@ 0XB72C0|750272
10:31:33.2772E4C209Initialize::GetLocation@ 0XB6E10|749072
10:31:33.2772E4C209Initialize::GetLocation@ 0XA190|41360
10:31:33.2772E4C209Initialize::GetLocation@ 0XB6EB0|749232
10:31:33.2772E4C209Initialize::GetLocation@ 0X1AB50|109392
10:31:33.2772E4C209Initialize::GetLocation@ 0X1D5A0|120224
10:31:33.2772E4C209Initialize::GetLocation@ 0X25BD0|154576
10:31:33.2772E4C209Initialize::GetLocation@ 0X113530|1127728
10:31:33.2772E4C209Initialize::GetLocation@ 0X112FF0|1126384
10:31:33.2772E4C209Initialize::GetLocation@ 0X1AA40|109120
10:31:33.2772E4C209Initialize::GetLocation@ 0X1A950|108880
10:31:33.2772E4C209Initialize::GetLocation@ 0XCB20|52000
10:31:33.2772E4C209Initialize::GetLocation@ 0X47D50|294224
10:31:33.2772E4C209Initialize::GetLocation@ 0X9D00|40192
10:31:33.2772E4C209Initialize::GetLocation@ 0XCE4B0|844976
10:31:33.2772E4C209Initialize::GetLocation@ 0XCEB80|846720
10:31:33.2772E4C209Initialize::GetLocation@ 0X9D00|40192
10:31:33.2772E4C209Initialize::GetLocation@ 0XCF670|849520
10:31:33.2772E4C209Initialize::GetLocation@ 0XCFCD0|851152
10:31:33.2992E4C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput.dll) <0X49160000>6|2|1247870977
10:31:33.4162E4C83VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
10:31:33.4162E4C209Initialize::GetLocation@ 0X4040|16448
10:31:33.4162E4C209Initialize::GetLocation@ 0X6410|25616
10:31:33.4162E4C209Initialize::GetLocation@ 0X65C0|26048
10:31:33.4202E4C48Update::DetectEnv (C:\WINDOWS\SYSTEM32\dinput8.dll) <0X49110000>6|2|1247870977
10:31:33.5202E4C93VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
10:31:33.5202E4C110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
10:31:33.5202E4C209Initialize::GetLocation@ 0XA5D0|42448
10:31:33.5202E4C209Initialize::GetLocation@ 0XD4D0|54480
10:31:33.5202E4C209Initialize::GetLocation@ 0XD290|53904
10:31:33.5902E4C225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_80_2_8320 opened succesfuly
10:31:33.5902E4C72HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
10:31:33.5902E4C256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_80_2_8320 close 2147483647 bytes
10:31:33.5902E4C297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.156.0.19\OWExplorer.dll]
10:31:33.6662E4C385ftw1OWExplorer injected
10:31:34.221119C51`anonymous-namespace'::CreateProviderInitialize provider: NET
10:31:34.221119C117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
10:31:34.221119C54`anonymous-namespace'::CreateProviderFail to initlized provider: NET
10:31:34.221119C51`anonymous-namespace'::CreateProviderInitialize provider: GPU
10:34:04.7081654394ProcessInjector::HandleElevatedProcessFail injection to process [1844] [t: 0 w_t_id: 0]- NVDisplay.Container.exe (elevated True) 0x1f
10:34:04.7081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |1844|: NVDisplay.Container.exe
10:34:04.7081654394ProcessInjector::HandleElevatedProcessFail injection to process [2172] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
10:34:04.7081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |2172|: NVIDIA Share.exe
10:34:04.7081654394ProcessInjector::HandleElevatedProcessFail injection to process [4016] [t: 0 w_t_id: 0]- nvcontainer.exe (elevated True) 0x1f
10:34:04.7081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |4016|: nvcontainer.exe
10:34:04.7081654394ProcessInjector::HandleElevatedProcessFail injection to process [4236] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x1f
10:34:04.7081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |4236|: MsMpEng.exe
10:34:04.7081654394ProcessInjector::HandleElevatedProcessFail injection to process [16324] [t: 0 w_t_id: 0]- NVIDIA Share.exe (elevated True) 0x1f
10:34:04.7081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |16324|: NVIDIA Share.exe
10:34:05.7081654394ProcessInjector::HandleElevatedProcessFail injection to process [16504] [t: 0 w_t_id: 0]- GoogleDriveFS.exe (elevated True) 0x1f
10:34:05.7081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |16504|: GoogleDriveFS.exe
12:08:45.2721654394ProcessInjector::HandleElevatedProcessFail injection to process [2388] [t: 0 w_t_id: 0]- script-fu.exe (elevated True) 0x0
12:08:45.2721654333ProcessInjector::HandlePendingProccesssFail to inject pending process |2388|: script-fu.exe
12:50:27.4601654394ProcessInjector::HandleElevatedProcessFail injection to process [8592] [t: 0 w_t_id: 0]- script-fu.exe (elevated True) 0x0
12:50:27.4601654333ProcessInjector::HandlePendingProccesssFail to inject pending process |8592|: script-fu.exe
13:11:22.3871654394ProcessInjector::HandleElevatedProcessFail injection to process [9924] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
13:11:22.3871654333ProcessInjector::HandlePendingProccesssFail to inject pending process |9924|: fzsftp.exe
13:19:57.111654394ProcessInjector::HandleElevatedProcessFail injection to process [9860] [t: 0 w_t_id: 0]- script-fu.exe (elevated True) 0x0
13:19:57.111654333ProcessInjector::HandlePendingProccesssFail to inject pending process |9860|: script-fu.exe
14:03:11.4431654394ProcessInjector::HandleElevatedProcessFail injection to process [15616] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x0
14:03:11.4431654333ProcessInjector::HandlePendingProccesssFail to inject pending process |15616|: splwow64.exe
14:46:31.1081654394ProcessInjector::HandleElevatedProcessFail injection to process [6452] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
14:46:31.1081654333ProcessInjector::HandlePendingProccesssFail to inject pending process |6452|: fzsftp.exe
14:47:16.5301654394ProcessInjector::HandleElevatedProcessFail injection to process [8692] [t: 0 w_t_id: 0]- script-fu.exe (elevated True) 0x0
14:47:16.5301654333ProcessInjector::HandlePendingProccesssFail to inject pending process |8692|: script-fu.exe
15:20:10.7291654394ProcessInjector::HandleElevatedProcessFail injection to process [10900] [t: 0 w_t_id: 0]- splwow64.exe (elevated True) 0x0
15:20:10.7291654333ProcessInjector::HandlePendingProccesssFail to inject pending process |10900|: splwow64.exe
15:32:35.341654394ProcessInjector::HandleElevatedProcessFail injection to process [5664] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
15:32:35.341654333ProcessInjector::HandlePendingProccesssFail to inject pending process |5664|: fzsftp.exe
15:37:02.3411654394ProcessInjector::HandleElevatedProcessFail injection to process [1044] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
15:37:02.3411654333ProcessInjector::HandlePendingProccesssFail to inject pending process |1044|: fzsftp.exe
17:22:15.2581654394ProcessInjector::HandleElevatedProcessFail injection to process [13112] [t: 0 w_t_id: 0]- fzsftp.exe (elevated True) 0x0
17:22:15.2581654333ProcessInjector::HandlePendingProccesssFail to inject pending process |13112|: fzsftp.exe
21:31:01.8072E4C66ProcessesMonitor::Stopstopping PM...
21:31:01.807119C119ProcessesMonitor::ProcessEnumerateThreadexit process listener
21:31:07.8232E4C66ProcessesMonitor::Stopstopping PM...