TimeThreadLineFunctionMessage
13:15:42.7077188361ftw1Loading (pid: 1240)
13:15:42.709718848Update::DetectEnv (C:\Windows\SYSTEM32\d3d11.dll) <0XB7F80000>6|2|1203373203
13:15:42.709718848Update::DetectEnv (C:\Windows\SYSTEM32\dxgi.dll) <0XB9FC0000>6|2|1203373081
13:15:42.710695C146ProcessHardwareRecorder::CommandThreadstarting recorder thread
13:15:42.7557188172DXManager::DetectFound in 0
13:15:42.7557188209Initialize::GetLocation@ 0X4660|18016
13:15:42.7557188209Initialize::GetLocation@ 0X661F0|418288
13:15:42.7557188209Initialize::GetLocation@ 0X19DB0|105904
13:15:42.7557188209Initialize::GetLocation@ 0X1350|4944
13:15:42.7557188111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
13:15:42.7557188209Initialize::GetLocation@ 0XFE0E3020|-32624608
13:15:42.7557188111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
13:15:42.7557188209Initialize::GetLocation@ 0XFE0E8060|-32604064
13:15:42.7557188111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
13:15:42.7557188209Initialize::GetLocation@ 0XFE0DE620|-32643552
13:15:42.7557188111Update::CaughtC:\Windows\SYSTEM32\d3d11.dll|0XB7F80000 <> 0XB9FC0000
13:15:42.7557188209Initialize::GetLocation@ 0XFDFCAA80|-33772928
13:15:42.801718848Update::DetectEnv (C:\Windows\SYSTEM32\d3d9.dll) <0X8B930000>6|2|1203373142
13:15:42.8617188129DXManager::DetectOK
13:15:42.9187188186DXManager::DetectDone
13:15:42.9187188215VTableHolderD3d9::initd3d offsest [sht]: 0x4060 , 0x53c0
13:15:42.9187188209Initialize::GetLocation@ 0X3AC00|240640
13:15:42.9187188209Initialize::GetLocation@ 0X2C5B0|181680
13:15:42.9187188209Initialize::GetLocation@ 0X36D00|224512
13:15:42.9187188209Initialize::GetLocation@ 0XAE210|713232
13:15:42.9187188209Initialize::GetLocation@ 0XADD60|712032
13:15:42.9187188209Initialize::GetLocation@ 0X5880|22656
13:15:42.9187188209Initialize::GetLocation@ 0XADE00|712192
13:15:42.9187188209Initialize::GetLocation@ 0X20FF0|135152
13:15:42.9187188209Initialize::GetLocation@ 0X1CA60|117344
13:15:42.9187188209Initialize::GetLocation@ 0X1C8E0|116960
13:15:42.9187188209Initialize::GetLocation@ 0X1086D0|1083088
13:15:42.9187188209Initialize::GetLocation@ 0X108180|1081728
13:15:42.9187188209Initialize::GetLocation@ 0X248B0|149680
13:15:42.9187188209Initialize::GetLocation@ 0X247A0|149408
13:15:42.9187188209Initialize::GetLocation@ 0X2C440|181312
13:15:42.9187188209Initialize::GetLocation@ 0X3F3F0|259056
13:15:42.9187188209Initialize::GetLocation@ 0XF3E0|62432
13:15:42.9187188209Initialize::GetLocation@ 0XF4E0|62688
13:15:42.9187188209Initialize::GetLocation@ 0XF5D0|62928
13:15:42.9187188209Initialize::GetLocation@ 0XF3E0|62432
13:15:42.9187188209Initialize::GetLocation@ 0XF280|62080
13:15:42.9187188209Initialize::GetLocation@ 0XF430|62512
13:15:42.937718848Update::DetectEnv (C:\Windows\SYSTEM32\dinput.dll) <0X99610000>6|2|1203372033
13:15:42.950718883VTableHolderDInput::initm_pDIW->CreateDevice - succeded.
13:15:42.9517188209Initialize::GetLocation@ 0X3CC0|15552
13:15:42.9517188209Initialize::GetLocation@ 0X5FD0|24528
13:15:42.9517188209Initialize::GetLocation@ 0X6180|24960
13:15:42.952718848Update::DetectEnv (C:\Windows\SYSTEM32\dinput8.dll) <0X96690000>6|2|1203372033
13:15:42.962718893VTableHolderDInput8::initm_pDI8W->CreateDevice - succeded.
13:15:42.9637188110VTableHolderDInput8::initm_pDI8A->CreateDevice - succeded.
13:15:42.9637188209Initialize::GetLocation@ 0X10000|65536
13:15:42.9637188209Initialize::GetLocation@ 0X12C80|76928
13:15:42.9637188209Initialize::GetLocation@ 0X12A60|76384
13:15:43.197188225InterProcessElement::openInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_1240 opened succesfuly
13:15:43.19718872HookFunctionsTableInitializer::SetHookFunctionsDataD3D9 Sht offsets 0x4060 , 0x53c0
13:15:43.197188256InterProcessElement::closeInterProcess Overwolf_SHARED_MEMORY_2_2_82_5_1240 close 2147483647 bytes
13:15:43.197188297InjectOWExplorerExplorer file name [C:\Program Files (x86)\Overwolf\0.159.0.23\OWExplorer.dll]
13:15:43.697188385ftw1OWExplorer injected
13:15:43.456700851`anonymous-namespace'::CreateProviderInitialize provider: NET
13:15:43.4567008117libprocess::NetworkTracer::Initializeinit res:0x5 [started:0 active:0 enbaled:0]
13:15:43.456700854`anonymous-namespace'::CreateProviderFail to initlized provider: NET
13:15:43.456700851`anonymous-namespace'::CreateProviderInitialize provider: GPU
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |vpnagent.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |com.docker.service| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |nassvc.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |httpd.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |mysqld.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |httpd.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |GoogleCrashHandler.exe| missing h
13:15:43.4685BF4629ProcessInjector::InjectProcessprocess |GoogleCrashHandler64.exe| missing h
13:15:43.5565BF4629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
13:15:43.5565BF4629ProcessInjector::InjectProcessprocess |TeamViewer_Desktop.exe| missing h
13:15:43.6005BF4629ProcessInjector::InjectProcessprocess |tv_w32.exe| missing h
13:15:43.6005BF4629ProcessInjector::InjectProcessprocess |tv_x64.exe| missing h
13:15:43.7785BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
13:18:03.1795BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [2672] [t: 0 w_t_id: 0]- vpnagent.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |2672|: vpnagent.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [2896] [t: 0 w_t_id: 0]- MsMpEng.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |2896|: MsMpEng.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [3684] [t: 0 w_t_id: 0]- com.docker.service (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |3684|: com.docker.service
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [3728] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |3728|: gameinputsvc.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [4048] [t: 0 w_t_id: 0]- nassvc.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4048|: nassvc.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [4148] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4148|: httpd.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [4596] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4596|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [4652] [t: 0 w_t_id: 0]- mysqld.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |4652|: mysqld.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [5680] [t: 0 w_t_id: 0]- GoogleCrashHandler64.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |5680|: GoogleCrashHandler64.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [5716] [t: 0 w_t_id: 0]- DropboxUpdate.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |5716|: DropboxUpdate.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [6668] [t: 0 w_t_id: 0]- httpd.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |6668|: httpd.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [7876] [t: 0 w_t_id: 0]- GoogleCrashHandler.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |7876|: GoogleCrashHandler.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [13452] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |13452|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [14280] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |14280|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [14996] [t: 0 w_t_id: 0]- tv_x64.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |14996|: tv_x64.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [15400] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |15400|: node.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [15732] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |15732|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [19656] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |19656|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [20648] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |20648|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [21328] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |21328|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [24996] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |24996|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [27132] [t: 0 w_t_id: 0]- tv_w32.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |27132|: tv_w32.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [28692] [t: 0 w_t_id: 0]- gameinputsvc.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |28692|: gameinputsvc.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [29172] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |29172|: Code.exe
13:18:14.1685BF4441ProcessInjector::HandleElevatedProcessFail injection to process [31832] [t: 0 w_t_id: 0]- node.exe (elevated True) 0x5
13:18:14.1685BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |31832|: node.exe
13:20:37.2375BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
14:18:02.8965BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
14:18:46.8935BF4441ProcessInjector::HandleElevatedProcessFail injection to process [11556] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
14:18:46.8935BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |11556|: software_reporter_tool.exe
14:18:46.8935BF4441ProcessInjector::HandleElevatedProcessFail injection to process [12244] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
14:18:46.8935BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |12244|: software_reporter_tool.exe
14:18:46.8935BF4441ProcessInjector::HandleElevatedProcessFail injection to process [22996] [t: 0 w_t_id: 0]- software_reporter_tool.exe (elevated True) 0x0
14:18:46.8935BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |22996|: software_reporter_tool.exe
14:44:02.9595BF4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
14:44:24.9565BF4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
15:14:58.475BF4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
15:14:58.475BF4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
15:14:58.475BF4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
15:18:02.9155BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
15:22:11.2375BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:22:35.2765BF4629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
15:22:35.2765BF4629ProcessInjector::InjectProcessprocess |OverwolfSetup.exe| missing h
15:22:49.2775BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
15:22:49.2775BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
16:18:02.5515BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
16:47:14.1815BF4629ProcessInjector::InjectProcessprocess |CCleaner64.exe| missing h
17:18:02.5465BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
17:18:24.5425BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
17:20:35.5495BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
17:20:36.5555BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
18:18:02.4985BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
18:28:15.8025BF4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
18:28:45.7895BF4629ProcessInjector::InjectProcessprocess |MicrosoftEdgeUpdate.exe| missing h
19:18:02.4125BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
19:22:11.5115BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
19:44:02.625BF4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:44:02.625BF4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:44:02.625BF4629ProcessInjector::InjectProcessprocess |GoogleUpdate.exe| missing h
19:46:32.855BF4441ProcessInjector::HandleElevatedProcessFail injection to process [13120] [t: 0 w_t_id: 0]- GoogleUpdate.exe (elevated True) 0x5
19:46:32.855BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |13120|: GoogleUpdate.exe
19:49:31.725BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
19:59:18.2165BF4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:59:19.2135BF4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
19:59:19.2135BF4629ProcessInjector::InjectProcessprocess |MpCmdRun.exe| missing h
20:18:02.4975BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
21:18:02.3885BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
21:20:35.4085BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
21:20:36.4125BF4629ProcessInjector::InjectProcessprocess |OverwolfUpdater.exe| missing h
22:11:54.3455BF4441ProcessInjector::HandleElevatedProcessFail injection to process [17792] [t: 0 w_t_id: 0]- Code.exe (elevated True) 0x5
22:11:54.3455BF4380ProcessInjector::HandlePendingProccesssFail to inject pending process |17792|: Code.exe
22:18:02.8855BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
22:18:26.9495BF4629ProcessInjector::InjectProcessprocess |DropboxUpdate.exe| missing h
22:28:19.4135BF4629ProcessInjector::InjectProcessprocess |gameinputsvc.exe| missing h
22:28:19.430718866ProcessesMonitor::Stopstopping PM...
22:28:19.4307008119ProcessesMonitor::ProcessEnumerateThreadexit process listener
22:28:19.4327188526ProcessInjector::Unhookunhook running process