Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 12ec.d24: Log file opened: 5.0.1r101957 g_hStartupLog=00000058 g_uNtVerCombined=0xa0280000
- 12ec.d24: \SystemRoot\System32\ntdll.dll:
- 12ec.d24: CreationTime: 2015-08-06T06:28:10.077441700Z
- 12ec.d24: LastWriteTime: 2015-08-06T06:28:10.077441700Z
- 12ec.d24: ChangeTime: 2015-08-06T06:28:52.546189200Z
- 12ec.d24: FileAttributes: 0x20
- 12ec.d24: Size: 0x176c38
- 12ec.d24: NT Headers: 0xf0
- 12ec.d24: Timestamp: 0x55a85cc1
- 12ec.d24: Machine: 0x14c - i386
- 12ec.d24: Timestamp: 0x55a85cc1
- 12ec.d24: Image Version: 10.0
- 12ec.d24: SizeOfImage: 0x179000 (1544192)
- 12ec.d24: Resource Dir: 0x10e000 LB 0x65720
- 12ec.d24: ProductName: Microsoft® Windows® Operating System
- 12ec.d24: ProductVersion: 10.0.10240.16392
- 12ec.d24: FileVersion: 10.0.10240.16392 (th1_st1.150716-1608)
- 12ec.d24: FileDescription: NT Layer DLL
- 12ec.d24: \SystemRoot\System32\kernel32.dll:
- 12ec.d24: CreationTime: 2015-07-10T08:24:38.139724700Z
- 12ec.d24: LastWriteTime: 2015-07-10T08:24:38.139724700Z
- 12ec.d24: ChangeTime: 2015-08-06T06:15:08.921190400Z
- 12ec.d24: FileAttributes: 0x20
- 12ec.d24: Size: 0x986b8
- 12ec.d24: NT Headers: 0xf8
- 12ec.d24: Timestamp: 0x559f3b86
- 12ec.d24: Machine: 0x14c - i386
- 12ec.d24: Timestamp: 0x559f3b86
- 12ec.d24: Image Version: 10.0
- 12ec.d24: SizeOfImage: 0x95000 (610304)
- 12ec.d24: Resource Dir: 0x8f000 LB 0x518
- 12ec.d24: ProductName: Microsoft® Windows® Operating System
- 12ec.d24: ProductVersion: 10.0.10240.16384
- 12ec.d24: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 12ec.d24: FileDescription: Windows NT BASE API Client DLL
- 12ec.d24: \SystemRoot\System32\KernelBase.dll:
- 12ec.d24: CreationTime: 2015-07-10T08:24:56.031660300Z
- 12ec.d24: LastWriteTime: 2015-07-10T08:24:56.047288800Z
- 12ec.d24: ChangeTime: 2015-08-06T06:15:09.030566300Z
- 12ec.d24: FileAttributes: 0x20
- 12ec.d24: Size: 0x175610
- 12ec.d24: NT Headers: 0xf0
- 12ec.d24: Timestamp: 0x559f3b4c
- 12ec.d24: Machine: 0x14c - i386
- 12ec.d24: Timestamp: 0x559f3b4c
- 12ec.d24: Image Version: 10.0
- 12ec.d24: SizeOfImage: 0x177000 (1536000)
- 12ec.d24: Resource Dir: 0x15b000 LB 0x530
- 12ec.d24: ProductName: Microsoft® Windows® Operating System
- 12ec.d24: ProductVersion: 10.0.10240.16384
- 12ec.d24: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 12ec.d24: FileDescription: Windows NT BASE API Client DLL
- 12ec.d24: \SystemRoot\System32\apisetschema.dll:
- 12ec.d24: CreationTime: 2015-07-10T08:24:49.281165400Z
- 12ec.d24: LastWriteTime: 2015-07-10T08:24:49.281165400Z
- 12ec.d24: ChangeTime: 2015-08-06T06:15:07.639941700Z
- 12ec.d24: FileAttributes: 0x20
- 12ec.d24: Size: 0x16560
- 12ec.d24: NT Headers: 0xc8
- 12ec.d24: Timestamp: 0x559f4063
- 12ec.d24: Machine: 0x14c - i386
- 12ec.d24: Timestamp: 0x559f4063
- 12ec.d24: Image Version: 10.0
- 12ec.d24: SizeOfImage: 0x17000 (94208)
- 12ec.d24: Resource Dir: 0x16000 LB 0x3f0
- 12ec.d24: ProductName: Microsoft® Windows® Operating System
- 12ec.d24: ProductVersion: 10.0.10240.16384
- 12ec.d24: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 12ec.d24: FileDescription: ApiSet Schema DLL
- 12ec.d24: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 12ec.d24: supR3HardenedWinFindAdversaries: 0x0
- 12ec.d24: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 12ec.d24: Calling main()
- 12ec.d24: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 12ec.d24: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 12ec.d24: SUPR3HardenedMain: Respawn #1
- 12ec.d24: System32: \Device\HarddiskVolume3\Windows\System32
- 12ec.d24: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 12ec.d24: KnownDllPath: C:\WINDOWS\system32
- 12ec.d24: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 12ec.d24: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 12ec.d24: supR3HardNtEnableThreadCreation:
- 12ec.d24: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77de2e70 pvNtTerminateThread=77df0f10
- 12ec.d24: supR3HardenedWinDoReSpawn(1): New child 2580.1f44 [kernel32].
- 12ec.d24: supR3HardNtChildGatherData: PebBaseAddress=7fa8f000 cbPeb=0x250
- 12ec.d24: supR3HardNtPuChFindNtdll: uNtDllParentAddr=77d70000 uNtDllChildAddr=77d70000
- 12ec.d24: supR3HardenedWinSetupChildInit: uLdrInitThunk=77de2e70
- 12ec.d24: supR3HardenedWinSetupChildInit: Start child.
- 12ec.d24: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
- 12ec.d24: supR3HardNtChildPurify: Startup delay kludge #1/0: 263 ms, 0 sleeps
- 12ec.d24: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 12ec.d24: *00000000-ff4effff 0x0001/0x0000 0x0000000
- 12ec.d24: *00b10000-00b10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00b11000-00b86fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00b87000-00b87fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00b88000-00bc1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bc2000-00bc2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bc3000-00bc3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bc4000-00bc4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bc5000-00bc5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bc6000-00bc7fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bc8000-00bcafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00bcb000-00c0efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 12ec.d24: 00c0f000-00c0dfff 0x0001/0x0000 0x0000000
- 12ec.d24: *00c10000-00beffff 0x0004/0x0004 0x0020000
- 12ec.d24: *00c30000-00c1bfff 0x0002/0x0002 0x0040000
- 12ec.d24: 00c44000-00c37fff 0x0001/0x0000 0x0000000
- 12ec.d24: *00c50000-00b52fff 0x0000/0x0004 0x0020000
- 12ec.d24: 00d4d000-00d4afff 0x0104/0x0004 0x0020000
- 12ec.d24: 00d4f000-00d4dfff 0x0004/0x0004 0x0020000
- 12ec.d24: *00d50000-00d4bfff 0x0002/0x0002 0x0040000
- 12ec.d24: 00d54000-00d47fff 0x0001/0x0000 0x0000000
- 12ec.d24: *00d60000-00d5dfff 0x0004/0x0004 0x0020000
- 12ec.d24: 00d62000-89d53fff 0x0001/0x0000 0x0000000
- 12ec.d24: *77d70000-77d70fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 12ec.d24: 77d71000-77e75fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 12ec.d24: 77e76000-77e7afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 12ec.d24: 77e7b000-77e7bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 12ec.d24: 77e7c000-77e7dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 12ec.d24: 77e7e000-77ee8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 12ec.d24: 77ee9000-70381fff 0x0001/0x0000 0x0000000
- 12ec.d24: *7fa50000-7fa1cfff 0x0002/0x0002 0x0040000
- 12ec.d24: 7fa83000-7fa77fff 0x0001/0x0000 0x0000000
- 12ec.d24: *7fa8e000-7fa8cfff 0x0004/0x0004 0x0020000
- 12ec.d24: *7fa8f000-7fa8dfff 0x0004/0x0004 0x0020000
- 12ec.d24: 7fa90000-7f53ffff 0x0001/0x0000 0x0000000
- 12ec.d24: *7ffe0000-7ffdefff 0x0002/0x0002 0x0020000
- 12ec.d24: 7ffe1000-7ffd1fff 0x0001/0x0002 0x0020000
- 12ec.d24: VirtualBox.exe: timestamp 0x55c302e9 (rc=VINF_SUCCESS)
- 12ec.d24: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 12ec.d24: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 12ec.d24: supR3HardNtChildPurify: Done after 317 ms and 0 fixes (loop #0).
- 2580.1f44: Log file opened: 5.0.1r101957 g_hStartupLog=00000004 g_uNtVerCombined=0xa0280000
- 2580.1f44: supR3HardenedVmProcessInit: uNtDllAddr=77d70000
- 2580.1f44: ntdll.dll: timestamp 0x55a85cc1 (rc=VINF_SUCCESS)
- 2580.1f44: New simple heap: #1 00e70000 LB 0x400000 (for 1544192 allocation)
- 12ec.d24: supR3HardNtEnableThreadCreation:
- 2580.1f44: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 2580.1f44: System32: \Device\HarddiskVolume3\Windows\System32
- 2580.1f44: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 2580.1f44: KnownDllPath: C:\WINDOWS\system32
- 2580.1f44: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- 2580.1f44: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 2580.1f44: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 2580.1f44: Registered Dll notification callback with NTDLL.
- 2580.1f44: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
- 2580.1f44: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 2580.1f44: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000801:<flags> [calling]
- 2580.1f44: supR3HardenedDllNotificationCallback: load 74f20000 LB 0x00177000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
- 2580.1f44: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
- 2580.1f44: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 2580.1f44: supR3HardenedDllNotificationCallback: load 77be0000 LB 0x00095000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
- 2580.1f44: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 2580.1f44: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77be0000 'C:\WINDOWS\system32\KERNEL32.DLL'
- 2580.1f44: supR3HardenedDllNotificationCallback: load 00b10000 LB 0x000ff000 H:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
- 2580.1f44: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2580.1f44: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 2580.1f44: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77de2e70 pvNtTerminateThread=77df0f10
- 12ec.d24: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 127 ms.
- 2580.1f44: \SystemRoot\System32\ntdll.dll:
- 2580.1f44: CreationTime: 2015-08-06T06:28:10.077441700Z
- 2580.1f44: LastWriteTime: 2015-08-06T06:28:10.077441700Z
- 2580.1f44: ChangeTime: 2015-08-06T06:28:52.546189200Z
- 2580.1f44: FileAttributes: 0x20
- 2580.1f44: Size: 0x176c38
- 2580.1f44: NT Headers: 0xf0
- 2580.1f44: Timestamp: 0x55a85cc1
- 2580.1f44: Machine: 0x14c - i386
- 2580.1f44: Timestamp: 0x55a85cc1
- 2580.1f44: Image Version: 10.0
- 2580.1f44: SizeOfImage: 0x179000 (1544192)
- 2580.1f44: Resource Dir: 0x10e000 LB 0x65720
- 2580.1f44: ProductName: Microsoft® Windows® Operating System
- 2580.1f44: ProductVersion: 10.0.10240.16392
- 2580.1f44: FileVersion: 10.0.10240.16392 (th1_st1.150716-1608)
- 2580.1f44: FileDescription: NT Layer DLL
- 2580.1f44: \SystemRoot\System32\kernel32.dll:
- 2580.1f44: CreationTime: 2015-07-10T08:24:38.139724700Z
- 2580.1f44: LastWriteTime: 2015-07-10T08:24:38.139724700Z
- 2580.1f44: ChangeTime: 2015-08-06T06:15:08.921190400Z
- 2580.1f44: FileAttributes: 0x20
- 2580.1f44: Size: 0x986b8
- 2580.1f44: NT Headers: 0xf8
- 2580.1f44: Timestamp: 0x559f3b86
- 2580.1f44: Machine: 0x14c - i386
- 2580.1f44: Timestamp: 0x559f3b86
- 2580.1f44: Image Version: 10.0
- 2580.1f44: SizeOfImage: 0x95000 (610304)
- 2580.1f44: Resource Dir: 0x8f000 LB 0x518
- 2580.1f44: ProductName: Microsoft® Windows® Operating System
- 2580.1f44: ProductVersion: 10.0.10240.16384
- 2580.1f44: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 2580.1f44: FileDescription: Windows NT BASE API Client DLL
- 2580.1f44: \SystemRoot\System32\KernelBase.dll:
- 2580.1f44: CreationTime: 2015-07-10T08:24:56.031660300Z
- 2580.1f44: LastWriteTime: 2015-07-10T08:24:56.047288800Z
- 2580.1f44: ChangeTime: 2015-08-06T06:15:09.030566300Z
- 2580.1f44: FileAttributes: 0x20
- 2580.1f44: Size: 0x175610
- 2580.1f44: NT Headers: 0xf0
- 2580.1f44: Timestamp: 0x559f3b4c
- 2580.1f44: Machine: 0x14c - i386
- 2580.1f44: Timestamp: 0x559f3b4c
- 2580.1f44: Image Version: 10.0
- 2580.1f44: SizeOfImage: 0x177000 (1536000)
- 2580.1f44: Resource Dir: 0x15b000 LB 0x530
- 2580.1f44: ProductName: Microsoft® Windows® Operating System
- 2580.1f44: ProductVersion: 10.0.10240.16384
- 2580.1f44: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 2580.1f44: FileDescription: Windows NT BASE API Client DLL
- 2580.1f44: \SystemRoot\System32\apisetschema.dll:
- 2580.1f44: CreationTime: 2015-07-10T08:24:49.281165400Z
- 2580.1f44: LastWriteTime: 2015-07-10T08:24:49.281165400Z
- 2580.1f44: ChangeTime: 2015-08-06T06:15:07.639941700Z
- 2580.1f44: FileAttributes: 0x20
- 2580.1f44: Size: 0x16560
- 2580.1f44: NT Headers: 0xc8
- 2580.1f44: Timestamp: 0x559f4063
- 2580.1f44: Machine: 0x14c - i386
- 2580.1f44: Timestamp: 0x559f4063
- 2580.1f44: Image Version: 10.0
- 2580.1f44: SizeOfImage: 0x17000 (94208)
- 2580.1f44: Resource Dir: 0x16000 LB 0x3f0
- 2580.1f44: ProductName: Microsoft® Windows® Operating System
- 2580.1f44: ProductVersion: 10.0.10240.16384
- 2580.1f44: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 2580.1f44: FileDescription: ApiSet Schema DLL
- 2580.1f44: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 2580.1f44: supR3HardenedWinFindAdversaries: 0x0
- 2580.1f44: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 2580.1f44: Calling main()
- 2580.1f44: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 2580.1f44: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 2580.1f44: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2580.1f44: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 2580.1f44: SUPR3HardenedMain: Respawn #2
- 2580.1f44: supR3HardNtEnableThreadCreation:
- 2580.1f44: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77de2e70 pvNtTerminateThread=77df0f10
- 2580.1f44: supR3HardenedWinDoReSpawn(2): New child 1b68.1ae4 [kernel32].
- 2580.1f44: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
- 2580.1f44: supR3HardNtChildGatherData: PebBaseAddress=7f73c000 cbPeb=0x250
- 2580.1f44: supR3HardNtPuChFindNtdll: uNtDllParentAddr=77d70000 uNtDllChildAddr=77d70000
- 2580.1f44: supR3HardenedWinSetupChildInit: uLdrInitThunk=77de2e70
- 2580.1f44: supR3HardenedWinSetupChildInit: Start child.
- 2580.1f44: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 2580.1f44: supR3HardNtChildPurify: Startup delay kludge #1/0: 263 ms, 0 sleeps
- 2580.1f44: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 2580.1f44: *00000000-ff55ffff 0x0001/0x0000 0x0000000
- 2580.1f44: *00aa0000-00a7ffff 0x0004/0x0004 0x0020000
- 2580.1f44: *00ac0000-00aabfff 0x0002/0x0002 0x0040000
- 2580.1f44: 00ad4000-00ac7fff 0x0001/0x0000 0x0000000
- 2580.1f44: *00ae0000-00adbfff 0x0002/0x0002 0x0040000
- 2580.1f44: 00ae4000-00ad7fff 0x0001/0x0000 0x0000000
- 2580.1f44: *00af0000-00aedfff 0x0004/0x0004 0x0020000
- 2580.1f44: 00af2000-00ad3fff 0x0001/0x0000 0x0000000
- 2580.1f44: *00b10000-00b10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00b11000-00b86fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00b87000-00b87fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00b88000-00bc1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bc2000-00bc2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bc3000-00bc3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bc4000-00bc4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bc5000-00bc5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bc6000-00bc7fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bc8000-00bcafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00bcb000-00c0efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: 00c0f000-00c0dfff 0x0001/0x0000 0x0000000
- 2580.1f44: *00c10000-00b12fff 0x0000/0x0004 0x0020000
- 2580.1f44: 00d0d000-00d0afff 0x0104/0x0004 0x0020000
- 2580.1f44: 00d0f000-00d0dfff 0x0004/0x0004 0x0020000
- 2580.1f44: 00d10000-89caffff 0x0001/0x0000 0x0000000
- 2580.1f44: *77d70000-77d70fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 2580.1f44: 77d71000-77e75fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 2580.1f44: 77e76000-77e7afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 2580.1f44: 77e7b000-77e7bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 2580.1f44: 77e7c000-77e7dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 2580.1f44: 77e7e000-77ee8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 2580.1f44: 77ee9000-706d1fff 0x0001/0x0000 0x0000000
- 2580.1f44: *7f700000-7f6ccfff 0x0002/0x0002 0x0040000
- 2580.1f44: 7f733000-7f729fff 0x0001/0x0000 0x0000000
- 2580.1f44: *7f73c000-7f73afff 0x0004/0x0004 0x0020000
- 2580.1f44: 7f73d000-7f73afff 0x0001/0x0000 0x0000000
- 2580.1f44: *7f73f000-7f73dfff 0x0004/0x0004 0x0020000
- 2580.1f44: 7f740000-7ee9ffff 0x0001/0x0000 0x0000000
- 2580.1f44: *7ffe0000-7ffdefff 0x0002/0x0002 0x0020000
- 2580.1f44: 7ffe1000-7ffd1fff 0x0001/0x0002 0x0020000
- 2580.1f44: VirtualBox.exe: timestamp 0x55c302e9 (rc=VINF_SUCCESS)
- 2580.1f44: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2580.1f44: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 2580.1f44: supR3HardNtChildPurify: Done after 317 ms and 0 fixes (loop #0).
- 1b68.1ae4: Log file opened: 5.0.1r101957 g_hStartupLog=00000004 g_uNtVerCombined=0xa0280000
- 1b68.1ae4: supR3HardenedVmProcessInit: uNtDllAddr=77d70000
- 2580.1f44: supR3HardenedEarlyCompact: Removed heap 1 (0xe70000 LB 0x400000)
- 1b68.1ae4: ntdll.dll: timestamp 0x55a85cc1 (rc=VINF_SUCCESS)
- 1b68.1ae4: New simple heap: #1 00e10000 LB 0x400000 (for 1544192 allocation)
- 2580.1f44: supR3HardNtEnableThreadCreation:
- 1b68.1ae4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 1b68.1ae4: System32: \Device\HarddiskVolume3\Windows\System32
- 1b68.1ae4: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 1b68.1ae4: KnownDllPath: C:\WINDOWS\system32
- 1b68.1ae4: supR3HardenedVmProcessInit: Opening vboxdrv...
- 1b68.1ae4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 1b68.1ae4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 1b68.1ae4: Registered Dll notification callback with NTDLL.
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000801:<flags> [calling]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 74f20000 LB 0x00177000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 77be0000 LB 0x00095000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77be0000 'C:\WINDOWS\system32\KERNEL32.DLL'
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 00b10000 LB 0x000ff000 H:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
- 1b68.1ae4: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2580.1f44: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 138 ms.
- 1b68.1ae4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77de2e70 pvNtTerminateThread=77df0f10
- 1b68.1ae4: \SystemRoot\System32\ntdll.dll:
- 1b68.1ae4: CreationTime: 2015-08-06T06:28:10.077441700Z
- 1b68.1ae4: LastWriteTime: 2015-08-06T06:28:10.077441700Z
- 1b68.1ae4: ChangeTime: 2015-08-06T06:28:52.546189200Z
- 1b68.1ae4: FileAttributes: 0x20
- 1b68.1ae4: Size: 0x176c38
- 1b68.1ae4: NT Headers: 0xf0
- 1b68.1ae4: Timestamp: 0x55a85cc1
- 1b68.1ae4: Machine: 0x14c - i386
- 1b68.1ae4: Timestamp: 0x55a85cc1
- 1b68.1ae4: Image Version: 10.0
- 1b68.1ae4: SizeOfImage: 0x179000 (1544192)
- 1b68.1ae4: Resource Dir: 0x10e000 LB 0x65720
- 1b68.1ae4: ProductName: Microsoft® Windows® Operating System
- 1b68.1ae4: ProductVersion: 10.0.10240.16392
- 1b68.1ae4: FileVersion: 10.0.10240.16392 (th1_st1.150716-1608)
- 1b68.1ae4: FileDescription: NT Layer DLL
- 1b68.1ae4: \SystemRoot\System32\kernel32.dll:
- 1b68.1ae4: CreationTime: 2015-07-10T08:24:38.139724700Z
- 1b68.1ae4: LastWriteTime: 2015-07-10T08:24:38.139724700Z
- 1b68.1ae4: ChangeTime: 2015-08-06T06:15:08.921190400Z
- 1b68.1ae4: FileAttributes: 0x20
- 1b68.1ae4: Size: 0x986b8
- 1b68.1ae4: NT Headers: 0xf8
- 1b68.1ae4: Timestamp: 0x559f3b86
- 1b68.1ae4: Machine: 0x14c - i386
- 1b68.1ae4: Timestamp: 0x559f3b86
- 1b68.1ae4: Image Version: 10.0
- 1b68.1ae4: SizeOfImage: 0x95000 (610304)
- 1b68.1ae4: Resource Dir: 0x8f000 LB 0x518
- 1b68.1ae4: ProductName: Microsoft® Windows® Operating System
- 1b68.1ae4: ProductVersion: 10.0.10240.16384
- 1b68.1ae4: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 1b68.1ae4: FileDescription: Windows NT BASE API Client DLL
- 1b68.1ae4: \SystemRoot\System32\KernelBase.dll:
- 1b68.1ae4: CreationTime: 2015-07-10T08:24:56.031660300Z
- 1b68.1ae4: LastWriteTime: 2015-07-10T08:24:56.047288800Z
- 1b68.1ae4: ChangeTime: 2015-08-06T06:15:09.030566300Z
- 1b68.1ae4: FileAttributes: 0x20
- 1b68.1ae4: Size: 0x175610
- 1b68.1ae4: NT Headers: 0xf0
- 1b68.1ae4: Timestamp: 0x559f3b4c
- 1b68.1ae4: Machine: 0x14c - i386
- 1b68.1ae4: Timestamp: 0x559f3b4c
- 1b68.1ae4: Image Version: 10.0
- 1b68.1ae4: SizeOfImage: 0x177000 (1536000)
- 1b68.1ae4: Resource Dir: 0x15b000 LB 0x530
- 1b68.1ae4: ProductName: Microsoft® Windows® Operating System
- 1b68.1ae4: ProductVersion: 10.0.10240.16384
- 1b68.1ae4: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 1b68.1ae4: FileDescription: Windows NT BASE API Client DLL
- 1b68.1ae4: \SystemRoot\System32\apisetschema.dll:
- 1b68.1ae4: CreationTime: 2015-07-10T08:24:49.281165400Z
- 1b68.1ae4: LastWriteTime: 2015-07-10T08:24:49.281165400Z
- 1b68.1ae4: ChangeTime: 2015-08-06T06:15:07.639941700Z
- 1b68.1ae4: FileAttributes: 0x20
- 1b68.1ae4: Size: 0x16560
- 1b68.1ae4: NT Headers: 0xc8
- 1b68.1ae4: Timestamp: 0x559f4063
- 1b68.1ae4: Machine: 0x14c - i386
- 1b68.1ae4: Timestamp: 0x559f4063
- 1b68.1ae4: Image Version: 10.0
- 1b68.1ae4: SizeOfImage: 0x17000 (94208)
- 1b68.1ae4: Resource Dir: 0x16000 LB 0x3f0
- 1b68.1ae4: ProductName: Microsoft® Windows® Operating System
- 1b68.1ae4: ProductVersion: 10.0.10240.16384
- 1b68.1ae4: FileVersion: 10.0.10240.16384 (th1.150709-1700)
- 1b68.1ae4: FileDescription: ApiSet Schema DLL
- 1b68.1ae4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 1b68.1ae4: supR3HardenedWinFindAdversaries: 0x0
- 1b68.1ae4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 1b68.1ae4: Calling main()
- 1b68.1ae4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 1b68.1ae4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
- 1b68.1ae4: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 1b68.1ae4: SUPR3HardenedMain: Final process, opening VBoxDrv...
- 1b68.1ae4: supR3HardenedEarlyCompact: Removed heap 1 (0xe10000 LB 0x400000)
- 1b68.1ae4: supR3HardNtEnableThreadCreation:
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000801:<flags> [calling]
- 1b68.1ae4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 6fb30000 LB 0x00005000 H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6fb30000 'H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6fb30000 'H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6fb30000 'H:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msasn1.dll'.
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000801:<flags> [calling]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 77310000 LB 0x000be000 C:\WINDOWS\system32\msvcrt.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 74f00000 LB 0x0000e000 C:\WINDOWS\system32\MSASN1.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 756b0000 LB 0x00175000 C:\WINDOWS\system32\CRYPT32.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 77a70000 LB 0x000c2000 C:\WINDOWS\system32\RPCRT4.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 75140000 LB 0x00042000 C:\WINDOWS\system32\Wintrust.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\WINDOWS\system32\Wintrust.dll'
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000801:<flags> [calling]
- 1b68.1ae4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 74e00000 LB 0x0001d000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74e00000 'C:\WINDOWS\system32\bcrypt.dll'
- 1b68.1ae4: bcrypt.dll loaded at 74e00000, BCryptOpenAlgorithmProvider at 74e05cc0, preloading providers:
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 74d20000 LB 0x00059000 C:\WINDOWS\system32\bcryptprimitives.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74d20000 'C:\WINDOWS\system32\bcryptprimitives.dll'
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=013e9648)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=013e9b88)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=013e9e40)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=013ea0f8)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=013ea3b0)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=013ea668)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=013ea920)
- 1b68.1ae4: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=013eb360)
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'.
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 74870000 LB 0x00013000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'bcrypt.dll'.
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 74550000 LB 0x0002f000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74550000 'C:\WINDOWS\system32\rsaenh.dll'
- 1b68.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 749a0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
- 1b68.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
- 1b68.1ae4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77be0000 'C:\WINDOWS\system32\kernel32.dll'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\System32\WINTRUST.DLL'
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000001:<flags> [calling]
- 1b68.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=756b0000 'C:\WINDOWS\system32\CRYPT32.dll'
- 1b68.1ae4: supR3HardenedDllNotificationCallback: load 77b40000 LB 0x00019000 C:\WINDOWS\system32\imagehlp.dll [fFlags=0x0]
- 1b68.1ae4: supHardenedWinVerifyImageByHandle: -> -626 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
- 1b68.1ae4: Error (rc=0):
- 1b68.1ae4: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume3\Windows\System32\imagehlp.dll:
- 1b68.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
- 1b68.1ae4: Fatal error:
- 1b68.1ae4: supR3HardenedDllNotificationCallback: supR3HardenedScreenImage failed on 'C:\WINDOWS\system32\imagehlp.dll' / '\??\C:\WINDOWS\system32\imagehlp.dll': 0xc0000190
- 2580.1f44: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 174 ms, the end);
- 12ec.d24: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 668 ms, the end);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement