Tue Oct 11 00:54:13 2022 UTC - Module file name: E:\Games\Steam\GameOverlayRenderer.dll Tue Oct 11 00:54:13 2022 UTC - GameID = 0, OverlayGameID = 0 Tue Oct 11 00:54:13 2022 UTC - System page size: 4096 Tue Oct 11 00:54:13 2022 UTC - Hooking SetCursorPos, GetCursorPos, ShowCursor, SetCursor, and GetCursor Tue Oct 11 00:54:13 2022 UTC - Game is using dxgi (dx10/dx11), preparing to hook. Tue Oct 11 00:54:13 2022 UTC - Modules at GameOverlayRenderer.dll attach Tue Oct 11 00:54:13 2022 UTC - 01: vulkandriverquery.exe - (006C0000 to 006E5000) Tue Oct 11 00:54:13 2022 UTC - 02: ntdll.dll - (77360000 to 77504000) Tue Oct 11 00:54:13 2022 UTC - 03: KERNEL32.DLL - (755B0000 to 756A0000) Tue Oct 11 00:54:13 2022 UTC - 04: KERNELBASE.dll - (75390000 to 755A9000) Tue Oct 11 00:54:13 2022 UTC - 05: vulkan-1.dll - (50680000 to 50799000) Tue Oct 11 00:54:13 2022 UTC - 06: CFGMGR32.dll - (768B0000 to 768EB000) Tue Oct 11 00:54:13 2022 UTC - 07: ucrtbase.dll - (76120000 to 76240000) Tue Oct 11 00:54:13 2022 UTC - 08: ADVAPI32.dll - (76830000 to 768AB000) Tue Oct 11 00:54:13 2022 UTC - 09: msvcrt.dll - (75700000 to 757BF000) Tue Oct 11 00:54:13 2022 UTC - 10: sechost.dll - (76350000 to 763C6000) Tue Oct 11 00:54:13 2022 UTC - 11: RPCRT4.dll - (763F0000 to 764AE000) Tue Oct 11 00:54:13 2022 UTC - 12: gdi32.dll - (752E0000 to 75303000) Tue Oct 11 00:54:13 2022 UTC - 13: win32u.dll - (76100000 to 76118000) Tue Oct 11 00:54:13 2022 UTC - 14: gdi32full.dll - (768F0000 to 769CD000) Tue Oct 11 00:54:13 2022 UTC - 15: msvcp_win.dll - (75310000 to 7538B000) Tue Oct 11 00:54:13 2022 UTC - 16: USER32.dll - (77100000 to 7729B000) Tue Oct 11 00:54:13 2022 UTC - 17: IMM32.DLL - (76240000 to 76265000) Tue Oct 11 00:54:13 2022 UTC - 18: dxgi.dll - (70860000 to 70923000) Tue Oct 11 00:54:13 2022 UTC - 19: kernel.appcore.dll - (70CE0000 to 70CEF000) Tue Oct 11 00:54:13 2022 UTC - 20: nvoglv32.dll - (7A720000 to 7CA3C000) Tue Oct 11 00:54:13 2022 UTC - 21: SHELL32.dll - (76A80000 to 77035000) Tue Oct 11 00:54:13 2022 UTC - 22: SETUPAPI.dll - (75A40000 to 75E79000) Tue Oct 11 00:54:13 2022 UTC - 23: bcrypt.dll - (770E0000 to 770F9000) Tue Oct 11 00:54:13 2022 UTC - 24: ole32.dll - (76010000 to 760F3000) Tue Oct 11 00:54:13 2022 UTC - 25: combase.dll - (764B0000 to 76730000) Tue Oct 11 00:54:13 2022 UTC - 26: OLEAUT32.dll - (77040000 to 770D6000) Tue Oct 11 00:54:13 2022 UTC - 27: WTSAPI32.dll - (723D0000 to 723DF000) Tue Oct 11 00:54:13 2022 UTC - 28: VERSION.dll - (724B0000 to 724B8000) Tue Oct 11 00:54:13 2022 UTC - 29: CRYPTBASE.DLL - (6FD80000 to 6FD8A000) Tue Oct 11 00:54:13 2022 UTC - 30: bcryptPrimitives.dll - (769D0000 to 76A2F000) Tue Oct 11 00:54:13 2022 UTC - 31: msasn1.dll - (6FFA0000 to 6FFAE000) Tue Oct 11 00:54:13 2022 UTC - 32: cryptnet.dll - (6BAC0000 to 6BAE6000) Tue Oct 11 00:54:13 2022 UTC - 33: CRYPT32.dll - (75E80000 to 75F7A000) Tue Oct 11 00:54:13 2022 UTC - 34: drvstore.dll - (64E90000 to 64F90000) Tue Oct 11 00:54:13 2022 UTC - 35: devobj.dll - (6C110000 to 6C134000) Tue Oct 11 00:54:13 2022 UTC - 36: wldp.dll - (70CF0000 to 70D17000) Tue Oct 11 00:54:13 2022 UTC - 37: WINTRUST.dll - (75230000 to 7527E000) Tue Oct 11 00:54:13 2022 UTC - 38: ntmarta.dll - (721D0000 to 721F9000) Tue Oct 11 00:54:13 2022 UTC - 39: SteamOverlayVulkanLayer.dll - (58C50000 to 58C7D000) Tue Oct 11 00:54:13 2022 UTC - 40: graphics-hook32.dll - (55540000 to 55572000) Tue Oct 11 00:54:13 2022 UTC - 41: dxcore.dll - (62A30000 to 62A5C000) Tue Oct 11 00:54:13 2022 UTC - 42: windows.storage.dll - (71990000 to 71F9D000) Tue Oct 11 00:54:13 2022 UTC - 43: SHCORE.dll - (759B0000 to 75A37000) Tue Oct 11 00:54:13 2022 UTC - 44: shlwapi.dll - (76A30000 to 76A75000) Tue Oct 11 00:54:13 2022 UTC - 45: nvspcap.dll - (62210000 to 6242F000) Tue Oct 11 00:54:13 2022 UTC - 46: profapi.dll - (6F700000 to 6F718000) Tue Oct 11 00:54:13 2022 UTC - 47: dwmapi.dll - (70D20000 to 70D46000) Tue Oct 11 00:54:13 2022 UTC - 48: uxtheme.dll - (722E0000 to 72354000) Tue Oct 11 00:54:13 2022 UTC - 49: GameOverlayRenderer.dll - (50530000 to 50679000) Tue Oct 11 00:54:13 2022 UTC - 50: PSAPI.DLL - (763E0000 to 763E6000) Tue Oct 11 00:54:13 2022 UTC - 51: WINMM.dll - (71FC0000 to 71FE8000) Tue Oct 11 00:54:13 2022 UTC - ---------------------------- Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:13 2022 UTC - hookCreateDXGIFactory1 called Tue Oct 11 00:54:13 2022 UTC - Hooking vtable for factory Tue Oct 11 00:54:13 2022 UTC - DXGIFactory2_CreateSwapChain already hooked via IDXGIFactory or IDXGIFactory1 Tue Oct 11 00:54:14 2022 UTC - Found a hooked function in now unloaded module, removing from map. Tue Oct 11 00:54:14 2022 UTC - Found a hooked function in now unloaded module, removing from map. Tue Oct 11 00:54:14 2022 UTC - Found a hooked function in now unloaded module, removing from map. Tue Oct 11 00:54:14 2022 UTC - Found a hooked function in now unloaded module, removing from map. Tue Oct 11 00:54:14 2022 UTC - Found a hooked function in now unloaded module, removing from map. Tue Oct 11 00:54:14 2022 UTC - Found a hooked function in now unloaded module, removing from map. Tue Oct 11 00:54:14 2022 UTC - GameOverlayRenderer.dll detaching