Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 910.2008: Log file opened: 5.1.4r110228 g_hStartupLog=000000000000011c g_uNtVerCombined=0xa0295a00
- 910.2008: \SystemRoot\System32\ntdll.dll:
- 910.2008: CreationTime: 2016-05-11T12:05:10.014704600Z
- 910.2008: LastWriteTime: 2016-04-23T05:24:28.464629900Z
- 910.2008: ChangeTime: 2016-05-15T20:19:31.012649400Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0x1bc248
- 910.2008: NT Headers: 0xe0
- 910.2008: Timestamp: 0x571af2eb
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x571af2eb
- 910.2008: Image Version: 10.0
- 910.2008: SizeOfImage: 0x1c1000 (1839104)
- 910.2008: Resource Dir: 0x159000 LB 0x66218
- 910.2008: ProductName: Microsoft® Windows® Operating System
- 910.2008: ProductVersion: 10.0.10586.306
- 910.2008: FileVersion: 10.0.10586.306 (th2_release_sec.160422-1850)
- 910.2008: FileDescription: NT Layer DLL
- 910.2008: \SystemRoot\System32\kernel32.dll:
- 910.2008: CreationTime: 2015-10-30T07:16:20.331389100Z
- 910.2008: LastWriteTime: 2015-10-30T07:16:20.331389100Z
- 910.2008: ChangeTime: 2016-03-14T17:41:57.967766000Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0xac430
- 910.2008: NT Headers: 0xf0
- 910.2008: Timestamp: 0x5632d5aa
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x5632d5aa
- 910.2008: Image Version: 10.0
- 910.2008: SizeOfImage: 0xad000 (708608)
- 910.2008: Resource Dir: 0xab000 LB 0x528
- 910.2008: ProductName: Microsoft® Windows® Operating System
- 910.2008: ProductVersion: 10.0.10586.0
- 910.2008: FileVersion: 10.0.10586.0 (th2_release.151029-1700)
- 910.2008: FileDescription: Windows NT BASE API Client DLL
- 910.2008: \SystemRoot\System32\KernelBase.dll:
- 910.2008: CreationTime: 2016-07-13T07:44:02.748091300Z
- 910.2008: LastWriteTime: 2016-07-01T04:49:21.864958900Z
- 910.2008: ChangeTime: 2016-07-13T11:37:19.901820900Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0x1e7a10
- 910.2008: NT Headers: 0xf0
- 910.2008: Timestamp: 0x5775e4c5
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x5775e4c5
- 910.2008: Image Version: 10.0
- 910.2008: SizeOfImage: 0x1e8000 (1998848)
- 910.2008: Resource Dir: 0x1d1000 LB 0x548
- 910.2008: ProductName: Microsoft® Windows® Operating System
- 910.2008: ProductVersion: 10.0.10586.494
- 910.2008: FileVersion: 10.0.10586.494 (th2_release_sec.160630-1736)
- 910.2008: FileDescription: Windows NT BASE API Client DLL
- 910.2008: \SystemRoot\System32\apisetschema.dll:
- 910.2008: CreationTime: 2015-10-30T07:16:42.846943300Z
- 910.2008: LastWriteTime: 2015-10-30T07:16:42.862567900Z
- 910.2008: ChangeTime: 2016-03-14T17:41:53.529567100Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0x16d60
- 910.2008: NT Headers: 0xc8
- 910.2008: Timestamp: 0x5632d94c
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x5632d94c
- 910.2008: Image Version: 10.0
- 910.2008: SizeOfImage: 0x18000 (98304)
- 910.2008: Resource Dir: 0x17000 LB 0x400
- 910.2008: ProductName: Microsoft® Windows® Operating System
- 910.2008: ProductVersion: 10.0.10586.0
- 910.2008: FileVersion: 10.0.10586.0 (th2_release.151029-1700)
- 910.2008: FileDescription: ApiSet Schema DLL
- 910.2008: supR3HardenedWinFindAdversaries: 0x80
- 910.2008: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
- 910.2008: CreationTime: 2016-01-05T09:38:45.769859200Z
- 910.2008: LastWriteTime: 2016-08-16T15:17:33.175624300Z
- 910.2008: ChangeTime: 2016-08-16T15:17:33.175624300Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0x2eed8
- 910.2008: NT Headers: 0xe0
- 910.2008: Timestamp: 0x55b855d9
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x55b855d9
- 910.2008: Image Version: 6.1
- 910.2008: SizeOfImage: 0x33000 (208896)
- 910.2008: Resource Dir: 0x31000 LB 0x3b8
- 910.2008: ProductName: Malwarebytes Anti-Malware
- 910.2008: ProductVersion: 0.3.0.0
- 910.2008: FileVersion: 0.3.0.0
- 910.2008: FileDescription: Malwarebytes Anti-Malware
- 910.2008: \SystemRoot\System32\drivers\mwac.sys:
- 910.2008: CreationTime: 2016-01-05T09:38:10.192276800Z
- 910.2008: LastWriteTime: 2016-03-10T12:09:10.000000000Z
- 910.2008: ChangeTime: 2016-05-22T17:27:09.681502800Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0xff80
- 910.2008: NT Headers: 0xe0
- 910.2008: Timestamp: 0x53a0f444
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x53a0f444
- 910.2008: Image Version: 6.2
- 910.2008: SizeOfImage: 0x13000 (77824)
- 910.2008: Resource Dir: 0x11000 LB 0x3e0
- 910.2008: ProductName: Malwarebytes Web Access Control
- 910.2008: ProductVersion: 1.0.6.0
- 910.2008: FileVersion: 1.0.6.0
- 910.2008: FileDescription: Malwarebytes Web Access Control
- 910.2008: \SystemRoot\System32\drivers\mbamchameleon.sys:
- 910.2008: CreationTime: 2016-01-05T09:38:10.256320100Z
- 910.2008: LastWriteTime: 2016-03-10T12:08:58.000000000Z
- 910.2008: ChangeTime: 2016-05-22T17:27:09.728541000Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0x22580
- 910.2008: NT Headers: 0xe0
- 910.2008: Timestamp: 0x56a95753
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x56a95753
- 910.2008: Image Version: 6.1
- 910.2008: SizeOfImage: 0x26000 (155648)
- 910.2008: Resource Dir: 0x24000 LB 0xba8
- 910.2008: ProductName: Malwarebytes Chameleon
- 910.2008: ProductVersion: 1.1.22.0
- 910.2008: FileVersion: 1.1.22.0
- 910.2008: FileDescription: Malwarebytes Chameleon Protection Driver
- 910.2008: \SystemRoot\System32\drivers\mbam.sys:
- 910.2008: CreationTime: 2016-01-05T09:38:10.135239900Z
- 910.2008: LastWriteTime: 2016-03-10T12:08:54.000000000Z
- 910.2008: ChangeTime: 2016-05-22T17:27:09.298096400Z
- 910.2008: FileAttributes: 0x20
- 910.2008: Size: 0x6980
- 910.2008: NT Headers: 0xd8
- 910.2008: Timestamp: 0x55ca3257
- 910.2008: Machine: 0x8664 - amd64
- 910.2008: Timestamp: 0x55ca3257
- 910.2008: Image Version: 6.1
- 910.2008: SizeOfImage: 0xa000 (40960)
- 910.2008: Resource Dir: 0x8000 LB 0x3a0
- 910.2008: ProductName: Malwarebytes Anti-Malware
- 910.2008: ProductVersion: 0.1.16.0
- 910.2008: FileVersion: 0.1.16.0
- 910.2008: FileDescription: Malwarebytes Anti-Malware
- 910.2008: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 910.2008: Calling main()
- 910.2008: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 910.2008: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 910.2008: SUPR3HardenedMain: Respawn #1
- 910.2008: System32: \Device\HarddiskVolume4\Windows\System32
- 910.2008: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
- 910.2008: KnownDllPath: C:\WINDOWS\system32
- 910.2008: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 910.2008: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 910.2008: supR3HardNtEnableThreadCreation:
- 910.2008: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9f7c56d50 pvNtTerminateThread=00007ff9f7c85b30
- 910.2008: supR3HardenedWinDoReSpawn(1): New child 24e8.10f0 [kernel32].
- 910.2008: supR3HardNtChildGatherData: PebBaseAddress=0000000000746000 cbPeb=0x388
- 910.2008: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff9f7be0000 uNtDllChildAddr=00007ff9f7be0000
- 910.2008: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9f7c56d50
- 910.2008: supR3HardenedWinSetupChildInit: Start child.
- 910.2008: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 910.2008: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 54 sleeps
- 910.2008: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 910.2008: *0000000000000000-ffffffffffb9ffff 0x0001/0x0000 0x0000000
- 910.2008: *0000000000460000-000000000043ffff 0x0004/0x0004 0x0020000
- 910.2008: *0000000000480000-000000000046afff 0x0002/0x0002 0x0040000
- 910.2008: 0000000000495000-0000000000489fff 0x0001/0x0000 0x0000000
- 910.2008: *00000000004a0000-00000000003a4fff 0x0000/0x0004 0x0020000
- 910.2008: 000000000059b000-0000000000597fff 0x0104/0x0004 0x0020000
- 910.2008: 000000000059e000-000000000059bfff 0x0004/0x0004 0x0020000
- 910.2008: *00000000005a0000-000000000059bfff 0x0002/0x0002 0x0040000
- 910.2008: 00000000005a4000-0000000000597fff 0x0001/0x0000 0x0000000
- 910.2008: *00000000005b0000-00000000005adfff 0x0004/0x0004 0x0020000
- 910.2008: 00000000005b2000-0000000000563fff 0x0001/0x0000 0x0000000
- 910.2008: *0000000000600000-00000000004b9fff 0x0000/0x0004 0x0020000
- 910.2008: 0000000000746000-0000000000742fff 0x0004/0x0004 0x0020000
- 910.2008: 0000000000749000-0000000000691fff 0x0000/0x0004 0x0020000
- 910.2008: 0000000000800000-ffffffff8101ffff 0x0001/0x0000 0x0000000
- 910.2008: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 910.2008: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
- 910.2008: 000000007fff0000-ffff80099fe6ffff 0x0001/0x0000 0x0000000
- 910.2008: *00007ff760170000-00007ff76014cfff 0x0002/0x0002 0x0040000
- 910.2008: 00007ff760193000-00007ff75fbc5fff 0x0001/0x0000 0x0000000
- 910.2008: *00007ff760760000-00007ff760760fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff760761000-00007ff7607cffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff7607d0000-00007ff7607d0fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff7607d1000-00007ff760815fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff760816000-00007ff760816fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff760817000-00007ff760817fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff760818000-00007ff76081cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff76081d000-00007ff76081dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff76081e000-00007ff76081efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff76081f000-00007ff760822fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff760823000-00007ff76086afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 910.2008: 00007ff76086b000-00007ff4c94f5fff 0x0001/0x0000 0x0000000
- 910.2008: *00007ff9f7be0000-00007ff9f7be0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7be1000-00007ff9f7cddfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7cde000-00007ff9f7d1efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7d1f000-00007ff9f7d27fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7d28000-00007ff9f7d34fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7d35000-00007ff9f7d35fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7d36000-00007ff9f7d38fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7d39000-00007ff9f7da0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 910.2008: 00007ff9f7da1000-00007ff3efb61fff 0x0001/0x0000 0x0000000
- 910.2008: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
- 910.2008: VirtualBox.exe: timestamp 0x57b358f8 (rc=VINF_SUCCESS)
- 910.2008: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 910.2008: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
- 910.2008: supR3HardNtChildPurify: Done after 571 ms and 0 fixes (loop #0).
- 24e8.10f0: Log file opened: 5.1.4r110228 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0295a00
- 24e8.10f0: supR3HardenedVmProcessInit: uNtDllAddr=00007ff9f7be0000 g_uNtVerCombined=0xa0295a00
- 24e8.10f0: ntdll.dll: timestamp 0x571af2eb (rc=VINF_SUCCESS)
- 24e8.10f0: New simple heap: #1 0000000000900000 LB 0x400000 (for 1839104 allocation)
- 24e8.10f0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 24e8.10f0: System32: \Device\HarddiskVolume4\Windows\System32
- 24e8.10f0: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
- 24e8.10f0: KnownDllPath: C:\WINDOWS\system32
- 24e8.10f0: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- 910.2008: supR3HardNtEnableThreadCreation:
- 24e8.10f0: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 24e8.10f0: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 24e8.10f0: Registered Dll notification callback with NTDLL.
- 24e8.10f0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
- 24e8.10f0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
- 24e8.10f0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
- 24e8.10f0: supR3HardenedDllNotificationCallback: load 00007ff9f4bb0000 LB 0x001e8000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
- 24e8.10f0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
- 24e8.10f0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
- 24e8.10f0: supR3HardenedDllNotificationCallback: load 00007ff9f5270000 LB 0x000ad000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
- 24e8.10f0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 24e8.10f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f5270000 'C:\WINDOWS\system32\KERNEL32.DLL'
- 24e8.10f0: supR3HardenedDllNotificationCallback: load 00007ff760760000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
- 24e8.10f0: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 24e8.10f0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 24e8.10f0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9f7c56d50 pvNtTerminateThread=00007ff9f7c85b30
- 24e8.10f0: \SystemRoot\System32\ntdll.dll:
- 24e8.10f0: CreationTime: 2016-05-11T12:05:10.014704600Z
- 24e8.10f0: LastWriteTime: 2016-04-23T05:24:28.464629900Z
- 24e8.10f0: ChangeTime: 2016-05-15T20:19:31.012649400Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0x1bc248
- 24e8.10f0: NT Headers: 0xe0
- 24e8.10f0: Timestamp: 0x571af2eb
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x571af2eb
- 24e8.10f0: Image Version: 10.0
- 24e8.10f0: SizeOfImage: 0x1c1000 (1839104)
- 24e8.10f0: Resource Dir: 0x159000 LB 0x66218
- 24e8.10f0: ProductName: Microsoft® Windows® Operating System
- 24e8.10f0: ProductVersion: 10.0.10586.306
- 24e8.10f0: FileVersion: 10.0.10586.306 (th2_release_sec.160422-1850)
- 24e8.10f0: FileDescription: NT Layer DLL
- 24e8.10f0: \SystemRoot\System32\kernel32.dll:
- 24e8.10f0: CreationTime: 2015-10-30T07:16:20.331389100Z
- 24e8.10f0: LastWriteTime: 2015-10-30T07:16:20.331389100Z
- 24e8.10f0: ChangeTime: 2016-03-14T17:41:57.967766000Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0xac430
- 24e8.10f0: NT Headers: 0xf0
- 24e8.10f0: Timestamp: 0x5632d5aa
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x5632d5aa
- 24e8.10f0: Image Version: 10.0
- 24e8.10f0: SizeOfImage: 0xad000 (708608)
- 24e8.10f0: Resource Dir: 0xab000 LB 0x528
- 24e8.10f0: ProductName: Microsoft® Windows® Operating System
- 24e8.10f0: ProductVersion: 10.0.10586.0
- 24e8.10f0: FileVersion: 10.0.10586.0 (th2_release.151029-1700)
- 24e8.10f0: FileDescription: Windows NT BASE API Client DLL
- 24e8.10f0: \SystemRoot\System32\KernelBase.dll:
- 24e8.10f0: CreationTime: 2016-07-13T07:44:02.748091300Z
- 24e8.10f0: LastWriteTime: 2016-07-01T04:49:21.864958900Z
- 24e8.10f0: ChangeTime: 2016-07-13T11:37:19.901820900Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0x1e7a10
- 24e8.10f0: NT Headers: 0xf0
- 24e8.10f0: Timestamp: 0x5775e4c5
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x5775e4c5
- 24e8.10f0: Image Version: 10.0
- 24e8.10f0: SizeOfImage: 0x1e8000 (1998848)
- 24e8.10f0: Resource Dir: 0x1d1000 LB 0x548
- 24e8.10f0: ProductName: Microsoft® Windows® Operating System
- 24e8.10f0: ProductVersion: 10.0.10586.494
- 24e8.10f0: FileVersion: 10.0.10586.494 (th2_release_sec.160630-1736)
- 24e8.10f0: FileDescription: Windows NT BASE API Client DLL
- 24e8.10f0: \SystemRoot\System32\apisetschema.dll:
- 24e8.10f0: CreationTime: 2015-10-30T07:16:42.846943300Z
- 24e8.10f0: LastWriteTime: 2015-10-30T07:16:42.862567900Z
- 24e8.10f0: ChangeTime: 2016-03-14T17:41:53.529567100Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0x16d60
- 24e8.10f0: NT Headers: 0xc8
- 24e8.10f0: Timestamp: 0x5632d94c
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x5632d94c
- 24e8.10f0: Image Version: 10.0
- 24e8.10f0: SizeOfImage: 0x18000 (98304)
- 24e8.10f0: Resource Dir: 0x17000 LB 0x400
- 24e8.10f0: ProductName: Microsoft® Windows® Operating System
- 24e8.10f0: ProductVersion: 10.0.10586.0
- 24e8.10f0: FileVersion: 10.0.10586.0 (th2_release.151029-1700)
- 24e8.10f0: FileDescription: ApiSet Schema DLL
- 910.2008: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 88 ms.
- 24e8.10f0: supR3HardenedWinFindAdversaries: 0x80
- 24e8.10f0: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
- 24e8.10f0: CreationTime: 2016-01-05T09:38:45.769859200Z
- 24e8.10f0: LastWriteTime: 2016-08-16T15:17:33.175624300Z
- 24e8.10f0: ChangeTime: 2016-08-16T15:17:33.175624300Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0x2eed8
- 24e8.10f0: NT Headers: 0xe0
- 24e8.10f0: Timestamp: 0x55b855d9
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x55b855d9
- 24e8.10f0: Image Version: 6.1
- 24e8.10f0: SizeOfImage: 0x33000 (208896)
- 24e8.10f0: Resource Dir: 0x31000 LB 0x3b8
- 24e8.10f0: ProductName: Malwarebytes Anti-Malware
- 24e8.10f0: ProductVersion: 0.3.0.0
- 24e8.10f0: FileVersion: 0.3.0.0
- 24e8.10f0: FileDescription: Malwarebytes Anti-Malware
- 24e8.10f0: \SystemRoot\System32\drivers\mwac.sys:
- 24e8.10f0: CreationTime: 2016-01-05T09:38:10.192276800Z
- 24e8.10f0: LastWriteTime: 2016-03-10T12:09:10.000000000Z
- 24e8.10f0: ChangeTime: 2016-05-22T17:27:09.681502800Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0xff80
- 24e8.10f0: NT Headers: 0xe0
- 24e8.10f0: Timestamp: 0x53a0f444
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x53a0f444
- 24e8.10f0: Image Version: 6.2
- 24e8.10f0: SizeOfImage: 0x13000 (77824)
- 24e8.10f0: Resource Dir: 0x11000 LB 0x3e0
- 24e8.10f0: ProductName: Malwarebytes Web Access Control
- 24e8.10f0: ProductVersion: 1.0.6.0
- 24e8.10f0: FileVersion: 1.0.6.0
- 24e8.10f0: FileDescription: Malwarebytes Web Access Control
- 24e8.10f0: \SystemRoot\System32\drivers\mbamchameleon.sys:
- 24e8.10f0: CreationTime: 2016-01-05T09:38:10.256320100Z
- 24e8.10f0: LastWriteTime: 2016-03-10T12:08:58.000000000Z
- 24e8.10f0: ChangeTime: 2016-05-22T17:27:09.728541000Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0x22580
- 24e8.10f0: NT Headers: 0xe0
- 24e8.10f0: Timestamp: 0x56a95753
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x56a95753
- 24e8.10f0: Image Version: 6.1
- 24e8.10f0: SizeOfImage: 0x26000 (155648)
- 24e8.10f0: Resource Dir: 0x24000 LB 0xba8
- 24e8.10f0: ProductName: Malwarebytes Chameleon
- 24e8.10f0: ProductVersion: 1.1.22.0
- 24e8.10f0: FileVersion: 1.1.22.0
- 24e8.10f0: FileDescription: Malwarebytes Chameleon Protection Driver
- 24e8.10f0: \SystemRoot\System32\drivers\mbam.sys:
- 24e8.10f0: CreationTime: 2016-01-05T09:38:10.135239900Z
- 24e8.10f0: LastWriteTime: 2016-03-10T12:08:54.000000000Z
- 24e8.10f0: ChangeTime: 2016-05-22T17:27:09.298096400Z
- 24e8.10f0: FileAttributes: 0x20
- 24e8.10f0: Size: 0x6980
- 24e8.10f0: NT Headers: 0xd8
- 24e8.10f0: Timestamp: 0x55ca3257
- 24e8.10f0: Machine: 0x8664 - amd64
- 24e8.10f0: Timestamp: 0x55ca3257
- 24e8.10f0: Image Version: 6.1
- 24e8.10f0: SizeOfImage: 0xa000 (40960)
- 24e8.10f0: Resource Dir: 0x8000 LB 0x3a0
- 24e8.10f0: ProductName: Malwarebytes Anti-Malware
- 24e8.10f0: ProductVersion: 0.1.16.0
- 24e8.10f0: FileVersion: 0.1.16.0
- 24e8.10f0: FileDescription: Malwarebytes Anti-Malware
- 24e8.10f0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 24e8.10f0: Calling main()
- 24e8.10f0: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 24e8.10f0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 24e8.10f0: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 24e8.10f0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 24e8.10f0: SUPR3HardenedMain: Respawn #2
- 24e8.10f0: supR3HardNtEnableThreadCreation:
- 24e8.10f0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\apphelp.dll)
- 24e8.10f0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\apphelp.dll
- 24e8.10f0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
- 24e8.10f0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
- 24e8.10f0: supR3HardenedDllNotificationCallback: load 00007ff9f29f0000 LB 0x00079000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
- 24e8.10f0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
- 24e8.10f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f29f0000 'C:\WINDOWS\system32\apphelp.dll'
- 24e8.10f0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9f7c56d50 pvNtTerminateThread=00007ff9f7c85b30
- 24e8.10f0: supR3HardenedWinDoReSpawn(2): New child 2630.ba4 [kernel32].
- 24e8.10f0: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
- 24e8.10f0: supR3HardNtChildGatherData: PebBaseAddress=0000000001080000 cbPeb=0x388
- 24e8.10f0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff9f7be0000 uNtDllChildAddr=00007ff9f7be0000
- 24e8.10f0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9f7c56d50
- 24e8.10f0: supR3HardenedWinSetupChildInit: Start child.
- 24e8.10f0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
- 24e8.10f0: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 54 sleeps
- 24e8.10f0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 24e8.10f0: *0000000000000000-ffffffffff07ffff 0x0001/0x0000 0x0000000
- 24e8.10f0: *0000000000f80000-0000000000f5ffff 0x0004/0x0004 0x0020000
- 24e8.10f0: *0000000000fa0000-0000000000f8afff 0x0002/0x0002 0x0040000
- 24e8.10f0: 0000000000fb5000-0000000000fa9fff 0x0001/0x0000 0x0000000
- 24e8.10f0: *0000000000fc0000-0000000000fbbfff 0x0002/0x0002 0x0040000
- 24e8.10f0: 0000000000fc4000-0000000000fb7fff 0x0001/0x0000 0x0000000
- 24e8.10f0: *0000000000fd0000-0000000000fcdfff 0x0004/0x0004 0x0020000
- 24e8.10f0: 0000000000fd2000-0000000000fa3fff 0x0001/0x0000 0x0000000
- 24e8.10f0: *0000000001000000-0000000000f7ffff 0x0000/0x0004 0x0020000
- 24e8.10f0: 0000000001080000-000000000107cfff 0x0004/0x0004 0x0020000
- 24e8.10f0: 0000000001083000-0000000000f05fff 0x0000/0x0004 0x0020000
- 24e8.10f0: *0000000001200000-0000000001104fff 0x0000/0x0004 0x0020000
- 24e8.10f0: 00000000012fb000-00000000012f7fff 0x0104/0x0004 0x0020000
- 24e8.10f0: 00000000012fe000-00000000012fbfff 0x0004/0x0004 0x0020000
- 24e8.10f0: 0000000001300000-ffffffff8261ffff 0x0001/0x0000 0x0000000
- 24e8.10f0: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 24e8.10f0: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
- 24e8.10f0: 000000007fff0000-ffff80099fa6ffff 0x0001/0x0000 0x0000000
- 24e8.10f0: *00007ff760570000-00007ff76054cfff 0x0002/0x0002 0x0040000
- 24e8.10f0: 00007ff760593000-00007ff7603c5fff 0x0001/0x0000 0x0000000
- 24e8.10f0: *00007ff760760000-00007ff760760fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff760761000-00007ff7607cffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff7607d0000-00007ff7607d0fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff7607d1000-00007ff760815fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff760816000-00007ff760816fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff760817000-00007ff760817fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff760818000-00007ff76081cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff76081d000-00007ff76081dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff76081e000-00007ff76081efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff76081f000-00007ff760822fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff760823000-00007ff76086afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24e8.10f0: 00007ff76086b000-00007ff4c94f5fff 0x0001/0x0000 0x0000000
- 24e8.10f0: *00007ff9f7be0000-00007ff9f7be0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7be1000-00007ff9f7cddfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7cde000-00007ff9f7d1efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7d1f000-00007ff9f7d27fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7d28000-00007ff9f7d34fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7d35000-00007ff9f7d35fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7d36000-00007ff9f7d38fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7d39000-00007ff9f7da0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 24e8.10f0: 00007ff9f7da1000-00007ff3efb61fff 0x0001/0x0000 0x0000000
- 24e8.10f0: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
- 24e8.10f0: VirtualBox.exe: timestamp 0x57b358f8 (rc=VINF_SUCCESS)
- 24e8.10f0: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 24e8.10f0: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
- 24e8.10f0: supR3HardNtChildPurify: Done after 575 ms and 0 fixes (loop #0).
- 2630.ba4: Log file opened: 5.1.4r110228 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0295a00
- 2630.ba4: supR3HardenedVmProcessInit: uNtDllAddr=00007ff9f7be0000 g_uNtVerCombined=0xa0295a00
- 2630.ba4: ntdll.dll: timestamp 0x571af2eb (rc=VINF_SUCCESS)
- 2630.ba4: New simple heap: #1 0000000001400000 LB 0x400000 (for 1839104 allocation)
- 24e8.10f0: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000900000 LB 0x400000)
- 24e8.10f0: supR3HardNtEnableThreadCreation:
- 2630.ba4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 2630.ba4: System32: \Device\HarddiskVolume4\Windows\System32
- 2630.ba4: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
- 2630.ba4: KnownDllPath: C:\WINDOWS\system32
- 2630.ba4: supR3HardenedVmProcessInit: Opening vboxdrv...
- 2630.ba4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 2630.ba4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 2630.ba4: Registered Dll notification callback with NTDLL.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4bb0000 LB 0x001e8000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f5270000 LB 0x000ad000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f5270000 'C:\WINDOWS\system32\KERNEL32.DLL'
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff760760000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
- 2630.ba4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2630.ba4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9f7c56d50 pvNtTerminateThread=00007ff9f7c85b30
- 24e8.10f0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 110 ms.
- 2630.ba4: \SystemRoot\System32\ntdll.dll:
- 2630.ba4: CreationTime: 2016-05-11T12:05:10.014704600Z
- 2630.ba4: LastWriteTime: 2016-04-23T05:24:28.464629900Z
- 2630.ba4: ChangeTime: 2016-05-15T20:19:31.012649400Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0x1bc248
- 2630.ba4: NT Headers: 0xe0
- 2630.ba4: Timestamp: 0x571af2eb
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x571af2eb
- 2630.ba4: Image Version: 10.0
- 2630.ba4: SizeOfImage: 0x1c1000 (1839104)
- 2630.ba4: Resource Dir: 0x159000 LB 0x66218
- 2630.ba4: ProductName: Microsoft® Windows® Operating System
- 2630.ba4: ProductVersion: 10.0.10586.306
- 2630.ba4: FileVersion: 10.0.10586.306 (th2_release_sec.160422-1850)
- 2630.ba4: FileDescription: NT Layer DLL
- 2630.ba4: \SystemRoot\System32\kernel32.dll:
- 2630.ba4: CreationTime: 2015-10-30T07:16:20.331389100Z
- 2630.ba4: LastWriteTime: 2015-10-30T07:16:20.331389100Z
- 2630.ba4: ChangeTime: 2016-03-14T17:41:57.967766000Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0xac430
- 2630.ba4: NT Headers: 0xf0
- 2630.ba4: Timestamp: 0x5632d5aa
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x5632d5aa
- 2630.ba4: Image Version: 10.0
- 2630.ba4: SizeOfImage: 0xad000 (708608)
- 2630.ba4: Resource Dir: 0xab000 LB 0x528
- 2630.ba4: ProductName: Microsoft® Windows® Operating System
- 2630.ba4: ProductVersion: 10.0.10586.0
- 2630.ba4: FileVersion: 10.0.10586.0 (th2_release.151029-1700)
- 2630.ba4: FileDescription: Windows NT BASE API Client DLL
- 2630.ba4: \SystemRoot\System32\KernelBase.dll:
- 2630.ba4: CreationTime: 2016-07-13T07:44:02.748091300Z
- 2630.ba4: LastWriteTime: 2016-07-01T04:49:21.864958900Z
- 2630.ba4: ChangeTime: 2016-07-13T11:37:19.901820900Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0x1e7a10
- 2630.ba4: NT Headers: 0xf0
- 2630.ba4: Timestamp: 0x5775e4c5
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x5775e4c5
- 2630.ba4: Image Version: 10.0
- 2630.ba4: SizeOfImage: 0x1e8000 (1998848)
- 2630.ba4: Resource Dir: 0x1d1000 LB 0x548
- 2630.ba4: ProductName: Microsoft® Windows® Operating System
- 2630.ba4: ProductVersion: 10.0.10586.494
- 2630.ba4: FileVersion: 10.0.10586.494 (th2_release_sec.160630-1736)
- 2630.ba4: FileDescription: Windows NT BASE API Client DLL
- 2630.ba4: \SystemRoot\System32\apisetschema.dll:
- 2630.ba4: CreationTime: 2015-10-30T07:16:42.846943300Z
- 2630.ba4: LastWriteTime: 2015-10-30T07:16:42.862567900Z
- 2630.ba4: ChangeTime: 2016-03-14T17:41:53.529567100Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0x16d60
- 2630.ba4: NT Headers: 0xc8
- 2630.ba4: Timestamp: 0x5632d94c
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x5632d94c
- 2630.ba4: Image Version: 10.0
- 2630.ba4: SizeOfImage: 0x18000 (98304)
- 2630.ba4: Resource Dir: 0x17000 LB 0x400
- 2630.ba4: ProductName: Microsoft® Windows® Operating System
- 2630.ba4: ProductVersion: 10.0.10586.0
- 2630.ba4: FileVersion: 10.0.10586.0 (th2_release.151029-1700)
- 2630.ba4: FileDescription: ApiSet Schema DLL
- 2630.ba4: supR3HardenedWinFindAdversaries: 0x80
- 2630.ba4: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
- 2630.ba4: CreationTime: 2016-01-05T09:38:45.769859200Z
- 2630.ba4: LastWriteTime: 2016-08-16T15:17:33.175624300Z
- 2630.ba4: ChangeTime: 2016-08-16T15:17:33.175624300Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0x2eed8
- 2630.ba4: NT Headers: 0xe0
- 2630.ba4: Timestamp: 0x55b855d9
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x55b855d9
- 2630.ba4: Image Version: 6.1
- 2630.ba4: SizeOfImage: 0x33000 (208896)
- 2630.ba4: Resource Dir: 0x31000 LB 0x3b8
- 2630.ba4: ProductName: Malwarebytes Anti-Malware
- 2630.ba4: ProductVersion: 0.3.0.0
- 2630.ba4: FileVersion: 0.3.0.0
- 2630.ba4: FileDescription: Malwarebytes Anti-Malware
- 2630.ba4: \SystemRoot\System32\drivers\mwac.sys:
- 2630.ba4: CreationTime: 2016-01-05T09:38:10.192276800Z
- 2630.ba4: LastWriteTime: 2016-03-10T12:09:10.000000000Z
- 2630.ba4: ChangeTime: 2016-05-22T17:27:09.681502800Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0xff80
- 2630.ba4: NT Headers: 0xe0
- 2630.ba4: Timestamp: 0x53a0f444
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x53a0f444
- 2630.ba4: Image Version: 6.2
- 2630.ba4: SizeOfImage: 0x13000 (77824)
- 2630.ba4: Resource Dir: 0x11000 LB 0x3e0
- 2630.ba4: ProductName: Malwarebytes Web Access Control
- 2630.ba4: ProductVersion: 1.0.6.0
- 2630.ba4: FileVersion: 1.0.6.0
- 2630.ba4: FileDescription: Malwarebytes Web Access Control
- 2630.ba4: \SystemRoot\System32\drivers\mbamchameleon.sys:
- 2630.ba4: CreationTime: 2016-01-05T09:38:10.256320100Z
- 2630.ba4: LastWriteTime: 2016-03-10T12:08:58.000000000Z
- 2630.ba4: ChangeTime: 2016-05-22T17:27:09.728541000Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0x22580
- 2630.ba4: NT Headers: 0xe0
- 2630.ba4: Timestamp: 0x56a95753
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x56a95753
- 2630.ba4: Image Version: 6.1
- 2630.ba4: SizeOfImage: 0x26000 (155648)
- 2630.ba4: Resource Dir: 0x24000 LB 0xba8
- 2630.ba4: ProductName: Malwarebytes Chameleon
- 2630.ba4: ProductVersion: 1.1.22.0
- 2630.ba4: FileVersion: 1.1.22.0
- 2630.ba4: FileDescription: Malwarebytes Chameleon Protection Driver
- 2630.ba4: \SystemRoot\System32\drivers\mbam.sys:
- 2630.ba4: CreationTime: 2016-01-05T09:38:10.135239900Z
- 2630.ba4: LastWriteTime: 2016-03-10T12:08:54.000000000Z
- 2630.ba4: ChangeTime: 2016-05-22T17:27:09.298096400Z
- 2630.ba4: FileAttributes: 0x20
- 2630.ba4: Size: 0x6980
- 2630.ba4: NT Headers: 0xd8
- 2630.ba4: Timestamp: 0x55ca3257
- 2630.ba4: Machine: 0x8664 - amd64
- 2630.ba4: Timestamp: 0x55ca3257
- 2630.ba4: Image Version: 6.1
- 2630.ba4: SizeOfImage: 0xa000 (40960)
- 2630.ba4: Resource Dir: 0x8000 LB 0x3a0
- 2630.ba4: ProductName: Malwarebytes Anti-Malware
- 2630.ba4: ProductVersion: 0.1.16.0
- 2630.ba4: FileVersion: 0.1.16.0
- 2630.ba4: FileDescription: Malwarebytes Anti-Malware
- 2630.ba4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 2630.ba4: Calling main()
- 2630.ba4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 2630.ba4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
- 2630.ba4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 2630.ba4: SUPR3HardenedMain: Final process, opening VBoxDrv...
- 2630.ba4: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001400000 LB 0x400000)
- 2630.ba4: supR3HardNtEnableThreadCreation:
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2630.ba4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9edd70000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9edd70000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9edd70000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9edd70000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msasn1.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f58c0000 LB 0x0009d000 C:\WINDOWS\system32\msvcrt.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4200000 LB 0x00010000 C:\WINDOWS\system32\MSASN1.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4e10000 LB 0x001c8000 C:\WINDOWS\system32\CRYPT32.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f7540000 LB 0x0011c000 C:\WINDOWS\system32\RPCRT4.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4340000 LB 0x00055000 C:\WINDOWS\system32\Wintrust.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\WINDOWS\system32\Wintrust.dll'
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2630.ba4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4130000 LB 0x00029000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4130000 'C:\WINDOWS\system32\bcrypt.dll'
- 2630.ba4: bcrypt.dll loaded at 00007ff9f4130000, BCryptOpenAlgorithmProvider at 00007ff9f4133b50, preloading providers:
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4b40000 LB 0x0006a000 C:\WINDOWS\system32\bcryptprimitives.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4b40000 'C:\WINDOWS\system32\bcryptprimitives.dll'
- 2630.ba4: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000019b9a00)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000019ba0c0)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000019ba390)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000019ba6f0)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000019bb210)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000019bb520)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000019bb830)
- 2630.ba4: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000019bbb00)
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f3b80000 LB 0x00017000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'bcrypt.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f3810000 LB 0x00034000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f3ca0000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f5270000 'C:\WINDOWS\system32\kernel32.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4e10000 'C:\WINDOWS\system32\CRYPT32.dll'
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f5dc0000 LB 0x0001c000 C:\WINDOWS\system32\imagehlp.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f5640000 LB 0x0005b000 C:\WINDOWS\system32\sechost.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f3200000 LB 0x00024000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f4270000 LB 0x00014000 C:\WINDOWS\system32\profapi.dll [fFlags=0x0]
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9e4270000 LB 0x0002f000 C:\WINDOWS\system32\cryptnet.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9e4270000 'C:\WINDOWS\system32\cryptnet.dll'
- 2630.ba4: supR3HardenedDllNotificationCallback: load 00007ff9f5aa0000 LB 0x000a7000 C:\WINDOWS\system32\advapi32.dll [fFlags=0x0]
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'.
- 2630.ba4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
- 2630.ba4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
- 2630.ba4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2630.ba4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2630.ba4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4e10000 'C:\WINDOWS\system32\crypt32.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\SystemRoot\System32\ntdll.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001a39700
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001a39700
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=056BDD821FDC5EB443883F1928BBEC403ED3FC46
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f7540000 'C:\WINDOWS\system32\rpcrt4.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4340000 'C:\Windows\System32\WINTRUST.DLL'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4e10000 'C:\WINDOWS\system32\crypt32.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1999_for_KB3176493~31bf3856ad364e35~amd64~~10.0.1.7.cat'; file='\SystemRoot\System32\ntdll.dll'
- 2630.ba4: g_pfnWinVerifyTrust=00007ff9f43474d0
- 2630.ba4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f4e10000 'C:\WINDOWS\system32\crypt32.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
- 2630.ba4: supR3HardenedScreenImage/preload: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedScreenImage/preload: cached rc=Unknown Status -22919 (0xffffa679) fImage=0 fProtect=0x0 fAccess=0x0 cHits=6 \Device\HarddiskVolume4\Windows\System32\crypt32.dll
- 2630.ba4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=8 \Device\HarddiskVolume4\Windows\System32\crypt32.dll
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\WINDOWS\system32\crypt32.dll': rcNt=0xc0000190
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\WINDOWS\system32\crypt32.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
- 2630.ba4: supR3HardenedScreenImage/preload: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000374 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001a39700
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001a39700
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=357A4685FBBF5E8A1472AE56D4B122532A042630
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10586.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9f3810000 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume4\Windows\System32\crypt32.dll
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\WINDOWS\system32\crypt32.dll': rcNt=0xc0000190
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\WINDOWS\system32\crypt32.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x80092026 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
- 2630.ba4: Error (rc=0):
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\WINDOWS\system32\rsaenh.dll' (C:\WINDOWS\system32\rsaenh.dll): rcNt=0xc0000190
- 2630.ba4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\WINDOWS\system32\rsaenh.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
- 2630.ba4: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x8 (<NULL>) on '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
- 2630.ba4: supR3HardenedWinVerifyCacheProcessWvtTodos: -22919 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
- 2630.ba4: Fatal error:
- 2630.ba4: Error loading 'crypt32.dll': 1790 [C:\WINDOWS\system32\crypt32.dll]
- 24e8.10f0: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 310 ms, the end);
- 910.2008: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 1024 ms, the end);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement