Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 1680.27a0: Log file opened: 5.1.2r108956 g_hStartupLog=0000000000000070 g_uNtVerCombined=0xa0456300
- 1680.27a0: \SystemRoot\System32\ntdll.dll:
- 1680.27a0: CreationTime: 2018-12-13T19:22:02.635309100Z
- 1680.27a0: LastWriteTime: 2018-12-13T19:22:02.682181600Z
- 1680.27a0: ChangeTime: 2018-12-20T14:42:55.839474100Z
- 1680.27a0: FileAttributes: 0x20
- 1680.27a0: Size: 0x1e7010
- 1680.27a0: NT Headers: 0xe0
- 1680.27a0: Timestamp: 0xe8b54827
- 1680.27a0: Machine: 0x8664 - amd64
- 1680.27a0: Timestamp: 0xe8b54827
- 1680.27a0: Image Version: 10.0
- 1680.27a0: SizeOfImage: 0x1ed000 (2019328)
- 1680.27a0: Resource Dir: 0x17d000 LB 0x6ea08
- 1680.27a0: ProductName: Microsoft® Windows® Operating System
- 1680.27a0: ProductVersion: 10.0.17763.194
- 1680.27a0: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
- 1680.27a0: FileDescription: NT Layer DLL
- 1680.27a0: \SystemRoot\System32\kernel32.dll:
- 1680.27a0: CreationTime: 2018-09-15T07:28:44.342269900Z
- 1680.27a0: LastWriteTime: 2018-09-15T07:28:44.342269900Z
- 1680.27a0: ChangeTime: 2018-11-27T23:00:42.235380500Z
- 1680.27a0: FileAttributes: 0x20
- 1680.27a0: Size: 0xb1380
- 1680.27a0: NT Headers: 0xe8
- 1680.27a0: Timestamp: 0x65614da1
- 1680.27a0: Machine: 0x8664 - amd64
- 1680.27a0: Timestamp: 0x65614da1
- 1680.27a0: Image Version: 10.0
- 1680.27a0: SizeOfImage: 0xb3000 (733184)
- 1680.27a0: Resource Dir: 0xb1000 LB 0x520
- 1680.27a0: ProductName: Microsoft® Windows® Operating System
- 1680.27a0: ProductVersion: 10.0.17763.1
- 1680.27a0: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
- 1680.27a0: FileDescription: Windows NT BASE API Client DLL
- 1680.27a0: \SystemRoot\System32\KernelBase.dll:
- 1680.27a0: CreationTime: 2018-11-28T11:09:10.498025800Z
- 1680.27a0: LastWriteTime: 2018-11-28T11:09:10.560520900Z
- 1680.27a0: ChangeTime: 2018-12-20T14:42:55.837475400Z
- 1680.27a0: FileAttributes: 0x20
- 1680.27a0: Size: 0x293cc8
- 1680.27a0: NT Headers: 0xf8
- 1680.27a0: Timestamp: 0x1659a33b
- 1680.27a0: Machine: 0x8664 - amd64
- 1680.27a0: Timestamp: 0x1659a33b
- 1680.27a0: Image Version: 10.0
- 1680.27a0: SizeOfImage: 0x293000 (2699264)
- 1680.27a0: Resource Dir: 0x26f000 LB 0x548
- 1680.27a0: ProductName: Microsoft® Windows® Operating System
- 1680.27a0: ProductVersion: 10.0.17763.134
- 1680.27a0: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
- 1680.27a0: FileDescription: Windows NT BASE API Client DLL
- 1680.27a0: \SystemRoot\System32\apisetschema.dll:
- 1680.27a0: CreationTime: 2018-09-15T07:28:25.403122600Z
- 1680.27a0: LastWriteTime: 2018-09-15T07:28:25.403122600Z
- 1680.27a0: ChangeTime: 2018-11-27T22:49:35.488419400Z
- 1680.27a0: FileAttributes: 0x20
- 1680.27a0: Size: 0x1c738
- 1680.27a0: NT Headers: 0xd0
- 1680.27a0: Timestamp: 0x33775897
- 1680.27a0: Machine: 0x8664 - amd64
- 1680.27a0: Timestamp: 0x33775897
- 1680.27a0: Image Version: 10.0
- 1680.27a0: SizeOfImage: 0x1d000 (118784)
- 1680.27a0: Resource Dir: 0x1c000 LB 0x408
- 1680.27a0: ProductName: Microsoft® Windows® Operating System
- 1680.27a0: ProductVersion: 10.0.17763.1
- 1680.27a0: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
- 1680.27a0: FileDescription: ApiSet Schema DLL
- 1680.27a0: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 1680.27a0: supR3HardenedWinFindAdversaries: 0x0
- 1680.27a0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 1680.27a0: Calling main()
- 1680.27a0: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 1680.27a0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 1680.27a0: SUPR3HardenedMain: Respawn #1
- 1680.27a0: System32: \Device\HarddiskVolume2\Windows\System32
- 1680.27a0: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
- 1680.27a0: KnownDllPath: C:\WINDOWS\System32
- 1680.27a0: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 1680.27a0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 1680.27a0: supR3HardNtEnableThreadCreation:
- 1680.27a0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb82ea5640 pvNtTerminateThread=00007ffb82ed00b0
- 1680.27a0: supR3HardenedWinDoReSpawn(1): New child 24a0.2c14 [kernel32].
- 1680.27a0: supR3HardNtChildGatherData: PebBaseAddress=00000000011c0000 cbPeb=0x388
- 1680.27a0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb82e30000 uNtDllChildAddr=00007ffb82e30000
- 1680.27a0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb82ea5640
- 1680.27a0: supR3HardenedWinSetupChildInit: Start child.
- 1680.27a0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 2 ms.
- 1680.27a0: supR3HardNtChildPurify: Startup delay kludge #1/0: 259 ms, 30 sleeps
- 1680.27a0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 1680.27a0: *0000000000000000-ffffffffff09ffff 0x0001/0x0000 0x0000000
- 1680.27a0: *0000000000f60000-0000000000f3ffff 0x0004/0x0004 0x0020000
- 1680.27a0: *0000000000f80000-0000000000f65fff 0x0002/0x0002 0x0040000
- 1680.27a0: 0000000000f9a000-0000000000f93fff 0x0001/0x0000 0x0000000
- 1680.27a0: *0000000000fa0000-0000000000f9bfff 0x0002/0x0002 0x0040000
- 1680.27a0: 0000000000fa4000-0000000000f97fff 0x0001/0x0000 0x0000000
- 1680.27a0: *0000000000fb0000-0000000000fadfff 0x0004/0x0004 0x0020000
- 1680.27a0: 0000000000fb2000-0000000000f63fff 0x0001/0x0000 0x0000000
- 1680.27a0: *0000000001000000-0000000000e3ffff 0x0000/0x0004 0x0020000
- 1680.27a0: 00000000011c0000-00000000011bcfff 0x0004/0x0004 0x0020000
- 1680.27a0: 00000000011c3000-0000000001185fff 0x0000/0x0004 0x0020000
- 1680.27a0: *0000000001200000-0000000001104fff 0x0000/0x0004 0x0020000
- 1680.27a0: 00000000012fb000-00000000012f7fff 0x0104/0x0004 0x0020000
- 1680.27a0: 00000000012fe000-00000000012fbfff 0x0004/0x0004 0x0020000
- 1680.27a0: 0000000001300000-ffffffff8261ffff 0x0001/0x0000 0x0000000
- 1680.27a0: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 1680.27a0: 000000007ffe1000-000000007ffdefff 0x0001/0x0000 0x0000000
- 1680.27a0: *000000007ffe3000-000000007ffe1fff 0x0002/0x0002 0x0020000
- 1680.27a0: 000000007ffe4000-ffff800b5c6d7fff 0x0001/0x0000 0x0000000
- 1680.27a0: *00007ff5a38f0000-00007ff5a38eefff 0x0002/0x0002 0x0040000
- 1680.27a0: 00007ff5a38f1000-00007ff5a38e1fff 0x0001/0x0000 0x0000000
- 1680.27a0: *00007ff5a3900000-00007ff5a38dcfff 0x0002/0x0002 0x0040000
- 1680.27a0: 00007ff5a3923000-00007ff49de65fff 0x0001/0x0000 0x0000000
- 1680.27a0: *00007ff6a93e0000-00007ff6a93e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a93e1000-00007ff6a944ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a9450000-00007ff6a9450fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a9451000-00007ff6a9494fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a9495000-00007ff6a9495fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a9496000-00007ff6a9496fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a9497000-00007ff6a949bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a949c000-00007ff6a949cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a949d000-00007ff6a949dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a949e000-00007ff6a94a1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a94a2000-00007ff6a94e9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 1680.27a0: 00007ff6a94ea000-00007ff1cfba3fff 0x0001/0x0000 0x0000000
- 1680.27a0: *00007ffb82e30000-00007ffb82e30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82e31000-00007ffb82f47fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82f48000-00007ffb82f8efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82f8f000-00007ffb82f99fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82f9a000-00007ffb82fa7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82fa8000-00007ffb82fa8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82fa9000-00007ffb82fabfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb82fac000-00007ffb8301cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1680.27a0: 00007ffb8301d000-00007ff706049fff 0x0001/0x0000 0x0000000
- 1680.27a0: VirtualBox.exe: timestamp 0x5790f053 (rc=VINF_SUCCESS)
- 1680.27a0: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 1680.27a0: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
- 1680.27a0: supR3HardNtChildPurify: Done after 291 ms and 0 fixes (loop #0).
- 24a0.2c14: Log file opened: 5.1.2r108956 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
- 24a0.2c14: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb82e30000 g_uNtVerCombined=0xa0456300
- 1680.27a0: supR3HardNtEnableThreadCreation:
- 24a0.2c14: ntdll.dll: timestamp 0xe8b54827 (rc=VINF_SUCCESS)
- 24a0.2c14: New simple heap: #1 0000000001400000 LB 0x400000 (for 2019328 allocation)
- 24a0.2c14: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 24a0.2c14: System32: \Device\HarddiskVolume2\Windows\System32
- 24a0.2c14: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
- 24a0.2c14: KnownDllPath: C:\WINDOWS\System32
- 24a0.2c14: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- 24a0.2c14: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 24a0.2c14: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 24a0.2c14: Registered Dll notification callback with NTDLL.
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
- 24a0.2c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
- 24a0.2c14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
- 24a0.2c14: supR3HardenedDllNotificationCallback: load 00007ffb7fdd0000 LB 0x00293000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
- 24a0.2c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
- 24a0.2c14: supR3HardenedDllNotificationCallback: load 00007ffb81a70000 LB 0x000b3000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
- 24a0.2c14: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 24a0.2c14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb81a70000 'C:\WINDOWS\System32\KERNEL32.DLL'
- 24a0.2c14: supR3HardenedDllNotificationCallback: load 00007ff6a93e0000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
- 24a0.2c14: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 24a0.2c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb82ea5640 pvNtTerminateThread=00007ffb82ed00b0
- 1680.27a0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 84 ms.
- 24a0.2c14: \SystemRoot\System32\ntdll.dll:
- 24a0.2c14: CreationTime: 2018-12-13T19:22:02.635309100Z
- 24a0.2c14: LastWriteTime: 2018-12-13T19:22:02.682181600Z
- 24a0.2c14: ChangeTime: 2018-12-20T14:42:55.839474100Z
- 24a0.2c14: FileAttributes: 0x20
- 24a0.2c14: Size: 0x1e7010
- 24a0.2c14: NT Headers: 0xe0
- 24a0.2c14: Timestamp: 0xe8b54827
- 24a0.2c14: Machine: 0x8664 - amd64
- 24a0.2c14: Timestamp: 0xe8b54827
- 24a0.2c14: Image Version: 10.0
- 24a0.2c14: SizeOfImage: 0x1ed000 (2019328)
- 24a0.2c14: Resource Dir: 0x17d000 LB 0x6ea08
- 24a0.2c14: ProductName: Microsoft® Windows® Operating System
- 24a0.2c14: ProductVersion: 10.0.17763.194
- 24a0.2c14: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
- 24a0.2c14: FileDescription: NT Layer DLL
- 24a0.2c14: \SystemRoot\System32\kernel32.dll:
- 24a0.2c14: CreationTime: 2018-09-15T07:28:44.342269900Z
- 24a0.2c14: LastWriteTime: 2018-09-15T07:28:44.342269900Z
- 24a0.2c14: ChangeTime: 2018-11-27T23:00:42.235380500Z
- 24a0.2c14: FileAttributes: 0x20
- 24a0.2c14: Size: 0xb1380
- 24a0.2c14: NT Headers: 0xe8
- 24a0.2c14: Timestamp: 0x65614da1
- 24a0.2c14: Machine: 0x8664 - amd64
- 24a0.2c14: Timestamp: 0x65614da1
- 24a0.2c14: Image Version: 10.0
- 24a0.2c14: SizeOfImage: 0xb3000 (733184)
- 24a0.2c14: Resource Dir: 0xb1000 LB 0x520
- 24a0.2c14: ProductName: Microsoft® Windows® Operating System
- 24a0.2c14: ProductVersion: 10.0.17763.1
- 24a0.2c14: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
- 24a0.2c14: FileDescription: Windows NT BASE API Client DLL
- 24a0.2c14: \SystemRoot\System32\KernelBase.dll:
- 24a0.2c14: CreationTime: 2018-11-28T11:09:10.498025800Z
- 24a0.2c14: LastWriteTime: 2018-11-28T11:09:10.560520900Z
- 24a0.2c14: ChangeTime: 2018-12-20T14:42:55.837475400Z
- 24a0.2c14: FileAttributes: 0x20
- 24a0.2c14: Size: 0x293cc8
- 24a0.2c14: NT Headers: 0xf8
- 24a0.2c14: Timestamp: 0x1659a33b
- 24a0.2c14: Machine: 0x8664 - amd64
- 24a0.2c14: Timestamp: 0x1659a33b
- 24a0.2c14: Image Version: 10.0
- 24a0.2c14: SizeOfImage: 0x293000 (2699264)
- 24a0.2c14: Resource Dir: 0x26f000 LB 0x548
- 24a0.2c14: ProductName: Microsoft® Windows® Operating System
- 24a0.2c14: ProductVersion: 10.0.17763.134
- 24a0.2c14: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
- 24a0.2c14: FileDescription: Windows NT BASE API Client DLL
- 24a0.2c14: \SystemRoot\System32\apisetschema.dll:
- 24a0.2c14: CreationTime: 2018-09-15T07:28:25.403122600Z
- 24a0.2c14: LastWriteTime: 2018-09-15T07:28:25.403122600Z
- 24a0.2c14: ChangeTime: 2018-11-27T22:49:35.488419400Z
- 24a0.2c14: FileAttributes: 0x20
- 24a0.2c14: Size: 0x1c738
- 24a0.2c14: NT Headers: 0xd0
- 24a0.2c14: Timestamp: 0x33775897
- 24a0.2c14: Machine: 0x8664 - amd64
- 24a0.2c14: Timestamp: 0x33775897
- 24a0.2c14: Image Version: 10.0
- 24a0.2c14: SizeOfImage: 0x1d000 (118784)
- 24a0.2c14: Resource Dir: 0x1c000 LB 0x408
- 24a0.2c14: ProductName: Microsoft® Windows® Operating System
- 24a0.2c14: ProductVersion: 10.0.17763.1
- 24a0.2c14: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
- 24a0.2c14: FileDescription: ApiSet Schema DLL
- 24a0.2c14: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 24a0.2c14: supR3HardenedWinFindAdversaries: 0x0
- 24a0.2c14: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 24a0.2c14: Calling main()
- 24a0.2c14: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 24a0.2c14: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 24a0.2c14: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 24a0.2c14: SUPR3HardenedMain: Respawn #2
- 24a0.2c14: supR3HardNtEnableThreadCreation:
- 24a0.2c14: supR3HardenedDllNotificationCallback: load 00007ffb82a40000 LB 0x00122000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
- 24a0.2c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 24a0.2c14: supR3HardenedDllNotificationCallback: load 00007ffb819d0000 LB 0x0009e000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
- 24a0.2c14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
- 24a0.2c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
- 24a0.2c14: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
- 24a0.2c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
- 24a0.2c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 24a0.2c14: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 24a0.2c14: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 24a0.2c14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 24a0.2c14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb82e30000 'C:\WINDOWS\System32\ntdll.dll'
- 24a0.2c14: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb82ea5640 pvNtTerminateThread=00007ffb82ed00b0
- 24a0.2c14: supR3HardenedWinDoReSpawn(2): New child 2e38.c8 [kernel32].
- 24a0.2c14: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
- 24a0.2c14: supR3HardNtChildGatherData: PebBaseAddress=00000000009de000 cbPeb=0x388
- 24a0.2c14: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb82e30000 uNtDllChildAddr=00007ffb82e30000
- 24a0.2c14: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb82ea5640
- 24a0.2c14: supR3HardenedWinSetupChildInit: Start child.
- 24a0.2c14: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
- 24a0.2c14: supR3HardNtChildPurify: Startup delay kludge #1/0: 260 ms, 24 sleeps
- 24a0.2c14: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 24a0.2c14: *0000000000000000-ffffffffff84ffff 0x0001/0x0000 0x0000000
- 24a0.2c14: *00000000007b0000-000000000078ffff 0x0004/0x0004 0x0020000
- 24a0.2c14: *00000000007d0000-00000000007b5fff 0x0002/0x0002 0x0040000
- 24a0.2c14: 00000000007ea000-00000000007e3fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *00000000007f0000-00000000007ebfff 0x0002/0x0002 0x0040000
- 24a0.2c14: 00000000007f4000-00000000007e7fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *0000000000800000-0000000000621fff 0x0000/0x0004 0x0020000
- 24a0.2c14: 00000000009de000-00000000009dafff 0x0004/0x0004 0x0020000
- 24a0.2c14: 00000000009e1000-00000000009c1fff 0x0000/0x0004 0x0020000
- 24a0.2c14: *0000000000a00000-0000000000904fff 0x0000/0x0004 0x0020000
- 24a0.2c14: 0000000000afb000-0000000000af7fff 0x0104/0x0004 0x0020000
- 24a0.2c14: 0000000000afe000-0000000000afbfff 0x0004/0x0004 0x0020000
- 24a0.2c14: *0000000000b00000-0000000000afdfff 0x0004/0x0004 0x0020000
- 24a0.2c14: 0000000000b02000-ffffffff81623fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 24a0.2c14: 000000007ffe1000-000000007ffdefff 0x0001/0x0000 0x0000000
- 24a0.2c14: *000000007ffe3000-000000007ffe1fff 0x0002/0x0002 0x0020000
- 24a0.2c14: 000000007ffe4000-ffff800b4eac7fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *00007ff5b1500000-00007ff5b14fefff 0x0002/0x0002 0x0040000
- 24a0.2c14: 00007ff5b1501000-00007ff5b14f1fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *00007ff5b1510000-00007ff5b14ecfff 0x0002/0x0002 0x0040000
- 24a0.2c14: 00007ff5b1533000-00007ff4b9685fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *00007ff6a93e0000-00007ff6a93e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a93e1000-00007ff6a944ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a9450000-00007ff6a9450fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a9451000-00007ff6a9494fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a9495000-00007ff6a9495fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a9496000-00007ff6a9496fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a9497000-00007ff6a949bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a949c000-00007ff6a949cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a949d000-00007ff6a949dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a949e000-00007ff6a94a1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a94a2000-00007ff6a94e9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 24a0.2c14: 00007ff6a94ea000-00007ff1cfba3fff 0x0001/0x0000 0x0000000
- 24a0.2c14: *00007ffb82e30000-00007ffb82e30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82e31000-00007ffb82f47fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82f48000-00007ffb82f8efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82f8f000-00007ffb82f99fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82f9a000-00007ffb82fa7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82fa8000-00007ffb82fa8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82fa9000-00007ffb82fabfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb82fac000-00007ffb8301cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 24a0.2c14: 00007ffb8301d000-00007ff706049fff 0x0001/0x0000 0x0000000
- 24a0.2c14: VirtualBox.exe: timestamp 0x5790f053 (rc=VINF_SUCCESS)
- 24a0.2c14: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 24a0.2c14: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
- 24a0.2c14: supR3HardNtChildPurify: Done after 292 ms and 0 fixes (loop #0).
- 2e38.c8: Log file opened: 5.1.2r108956 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
- 2e38.c8: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb82e30000 g_uNtVerCombined=0xa0456300
- 2e38.c8: ntdll.dll: timestamp 0xe8b54827 (rc=VINF_SUCCESS)
- 2e38.c8: New simple heap: #1 0000000000c10000 LB 0x400000 (for 2019328 allocation)
- 24a0.2c14: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001400000 LB 0x400000)
- 24a0.2c14: supR3HardNtEnableThreadCreation:
- 2e38.c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 2e38.c8: System32: \Device\HarddiskVolume2\Windows\System32
- 2e38.c8: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
- 2e38.c8: KnownDllPath: C:\WINDOWS\System32
- 2e38.c8: supR3HardenedVmProcessInit: Opening vboxdrv...
- 2e38.c8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 2e38.c8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 2e38.c8: Registered Dll notification callback with NTDLL.
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7fdd0000 LB 0x00293000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb81a70000 LB 0x000b3000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb81a70000 'C:\WINDOWS\System32\KERNEL32.DLL'
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ff6a93e0000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
- 2e38.c8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 2e38.c8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb82ea5640 pvNtTerminateThread=00007ffb82ed00b0
- 24a0.2c14: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 106 ms.
- 2e38.c8: \SystemRoot\System32\ntdll.dll:
- 2e38.c8: CreationTime: 2018-12-13T19:22:02.635309100Z
- 2e38.c8: LastWriteTime: 2018-12-13T19:22:02.682181600Z
- 2e38.c8: ChangeTime: 2018-12-20T14:42:55.839474100Z
- 2e38.c8: FileAttributes: 0x20
- 2e38.c8: Size: 0x1e7010
- 2e38.c8: NT Headers: 0xe0
- 2e38.c8: Timestamp: 0xe8b54827
- 2e38.c8: Machine: 0x8664 - amd64
- 2e38.c8: Timestamp: 0xe8b54827
- 2e38.c8: Image Version: 10.0
- 2e38.c8: SizeOfImage: 0x1ed000 (2019328)
- 2e38.c8: Resource Dir: 0x17d000 LB 0x6ea08
- 2e38.c8: ProductName: Microsoft® Windows® Operating System
- 2e38.c8: ProductVersion: 10.0.17763.194
- 2e38.c8: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
- 2e38.c8: FileDescription: NT Layer DLL
- 2e38.c8: \SystemRoot\System32\kernel32.dll:
- 2e38.c8: CreationTime: 2018-09-15T07:28:44.342269900Z
- 2e38.c8: LastWriteTime: 2018-09-15T07:28:44.342269900Z
- 2e38.c8: ChangeTime: 2018-11-27T23:00:42.235380500Z
- 2e38.c8: FileAttributes: 0x20
- 2e38.c8: Size: 0xb1380
- 2e38.c8: NT Headers: 0xe8
- 2e38.c8: Timestamp: 0x65614da1
- 2e38.c8: Machine: 0x8664 - amd64
- 2e38.c8: Timestamp: 0x65614da1
- 2e38.c8: Image Version: 10.0
- 2e38.c8: SizeOfImage: 0xb3000 (733184)
- 2e38.c8: Resource Dir: 0xb1000 LB 0x520
- 2e38.c8: ProductName: Microsoft® Windows® Operating System
- 2e38.c8: ProductVersion: 10.0.17763.1
- 2e38.c8: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
- 2e38.c8: FileDescription: Windows NT BASE API Client DLL
- 2e38.c8: \SystemRoot\System32\KernelBase.dll:
- 2e38.c8: CreationTime: 2018-11-28T11:09:10.498025800Z
- 2e38.c8: LastWriteTime: 2018-11-28T11:09:10.560520900Z
- 2e38.c8: ChangeTime: 2018-12-20T14:42:55.837475400Z
- 2e38.c8: FileAttributes: 0x20
- 2e38.c8: Size: 0x293cc8
- 2e38.c8: NT Headers: 0xf8
- 2e38.c8: Timestamp: 0x1659a33b
- 2e38.c8: Machine: 0x8664 - amd64
- 2e38.c8: Timestamp: 0x1659a33b
- 2e38.c8: Image Version: 10.0
- 2e38.c8: SizeOfImage: 0x293000 (2699264)
- 2e38.c8: Resource Dir: 0x26f000 LB 0x548
- 2e38.c8: ProductName: Microsoft® Windows® Operating System
- 2e38.c8: ProductVersion: 10.0.17763.134
- 2e38.c8: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
- 2e38.c8: FileDescription: Windows NT BASE API Client DLL
- 2e38.c8: \SystemRoot\System32\apisetschema.dll:
- 2e38.c8: CreationTime: 2018-09-15T07:28:25.403122600Z
- 2e38.c8: LastWriteTime: 2018-09-15T07:28:25.403122600Z
- 2e38.c8: ChangeTime: 2018-11-27T22:49:35.488419400Z
- 2e38.c8: FileAttributes: 0x20
- 2e38.c8: Size: 0x1c738
- 2e38.c8: NT Headers: 0xd0
- 2e38.c8: Timestamp: 0x33775897
- 2e38.c8: Machine: 0x8664 - amd64
- 2e38.c8: Timestamp: 0x33775897
- 2e38.c8: Image Version: 10.0
- 2e38.c8: SizeOfImage: 0x1d000 (118784)
- 2e38.c8: Resource Dir: 0x1c000 LB 0x408
- 2e38.c8: ProductName: Microsoft® Windows® Operating System
- 2e38.c8: ProductVersion: 10.0.17763.1
- 2e38.c8: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
- 2e38.c8: FileDescription: ApiSet Schema DLL
- 2e38.c8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 2e38.c8: supR3HardenedWinFindAdversaries: 0x0
- 2e38.c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 2e38.c8: Calling main()
- 2e38.c8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 2e38.c8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 2e38.c8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 2e38.c8: SUPR3HardenedMain: Final process, opening VBoxDrv...
- 2e38.c8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000c10000 LB 0x400000)
- 2e38.c8: supR3HardNtEnableThreadCreation:
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7c8f0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7c8f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7c8f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7c8f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 2e38.c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 2e38.c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
- 2e38.c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
- 2e38.c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 2e38.c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 2e38.c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb82d60000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7ef40000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7f120000 LB 0x000fc000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7fbf0000 LB 0x001db000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb82a40000 LB 0x00122000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7f220000 LB 0x00058000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7fdd0000 'api-ms-win-core-synch-l1-2-0'
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7fdd0000 'api-ms-win-core-fibers-l1-1-1'
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7fdd0000 'api-ms-win-core-fibers-l1-1-1'
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7fdd0000 'api-ms-win-core-synch-l1-2-0'
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7fdd0000 'api-ms-win-core-localization-l1-2-1'
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb7f220000 'C:\WINDOWS\system32\Wintrust.dll'
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> -626 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
- 2e38.c8: Error (rc=0):
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume2\Windows\System32\bcrypt.dll: Grown load config (192 to 264 bytes) includes non-zero bytes: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 ba 01 80 01 00 00 00 00 00 00 00 00 00 00 00
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
- 2e38.c8: Error (rc=0):
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\WINDOWS\system32\bcrypt.dll' (C:\WINDOWS\system32\bcrypt.dll): rcNt=0xc0000190
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\WINDOWS\system32\bcrypt.dll'
- 2e38.c8: Warning! Failed to load bcrypt.dll
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7f280000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
- 2e38.c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
- 2e38.c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
- 2e38.c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 2e38.c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 2e38.c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status -626 (0xfffffd8e)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 2e38.c8: Error (rc=0):
- 2e38.c8: supR3HardenedScreenImage/Imports: cached rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
- 2e38.c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 2e38.c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 2e38.c8: supR3HardenedDllNotificationCallback: load 00007ffb7fbc0000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -626 (0xfffffd8e)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 2e38.c8: Error (rc=0):
- 2e38.c8: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
- 2e38.c8: Fatal error:
- 2e38.c8: supR3HardenedDllNotificationCallback: supR3HardenedScreenImage failed on 'C:\WINDOWS\System32\bcrypt.dll' / '\??\C:\WINDOWS\System32\bcrypt.dll': 0xc0000190
- 24a0.2c14: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 102 ms, the end);
- 1680.27a0: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 584 ms, the end);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement