Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 5050.2ed0: \SystemRoot\System32\ntdll.dll:
- 5050.2ed0: CreationTime: 2024-12-27T04:46:48.085800000Z
- 5050.2ed0: LastWriteTime: 2024-12-27T04:46:48.230755400Z
- 5050.2ed0: ChangeTime: 2024-12-27T10:39:59.823242500Z
- 5050.2ed0: FileAttributes: 0x20
- 5050.2ed0: Size: 0x216050
- 5050.2ed0: NT Headers: 0xe8
- 5050.2ed0: Timestamp: 0xe7035eba
- 5050.2ed0: Machine: 0x8664 - amd64
- 5050.2ed0: Timestamp: 0xe7035eba
- 5050.2ed0: Image Version: 10.0
- 5050.2ed0: SizeOfImage: 0x217000 (2191360)
- 5050.2ed0: Resource Dir: 0x1a0000 LB 0x759a8
- 5050.2ed0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5050.2ed0: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 5050.2ed0: ProductName: Microsoft® Windows® Operating System
- 5050.2ed0: ProductVersion: 10.0.22621.4541
- 5050.2ed0: FileVersion: 10.0.22621.4541 (WinBuild.160101.0800)
- 5050.2ed0: FileDescription: NT Layer DLL
- 5050.2ed0: \SystemRoot\System32\kernel32.dll:
- 5050.2ed0: CreationTime: 2024-12-27T04:46:46.481290000Z
- 5050.2ed0: LastWriteTime: 2024-12-27T04:46:46.553985700Z
- 5050.2ed0: ChangeTime: 2024-12-27T10:39:47.087420300Z
- 5050.2ed0: FileAttributes: 0x20
- 5050.2ed0: Size: 0xc71e0
- 5050.2ed0: NT Headers: 0xe8
- 5050.2ed0: Timestamp: 0x1ef15383
- 5050.2ed0: Machine: 0x8664 - amd64
- 5050.2ed0: Timestamp: 0x1ef15383
- 5050.2ed0: Image Version: 10.0
- 5050.2ed0: SizeOfImage: 0xc4000 (802816)
- 5050.2ed0: Resource Dir: 0xc2000 LB 0x520
- 5050.2ed0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5050.2ed0: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 5050.2ed0: ProductName: Microsoft® Windows® Operating System
- 5050.2ed0: ProductVersion: 10.0.22621.4391
- 5050.2ed0: FileVersion: 10.0.22621.4391 (WinBuild.160101.0800)
- 5050.2ed0: FileDescription: Windows NT BASE API Client DLL
- 5050.2ed0: \SystemRoot\System32\KernelBase.dll:
- 5050.2ed0: CreationTime: 2024-12-27T04:46:50.984447700Z
- 5050.2ed0: LastWriteTime: 2024-12-27T04:46:51.497833800Z
- 5050.2ed0: ChangeTime: 2024-12-27T10:39:57.596691700Z
- 5050.2ed0: FileAttributes: 0x20
- 5050.2ed0: Size: 0x3c0bb0
- 5050.2ed0: NT Headers: 0xf8
- 5050.2ed0: Timestamp: 0x8ca6fab8
- 5050.2ed0: Machine: 0x8664 - amd64
- 5050.2ed0: Timestamp: 0x8ca6fab8
- 5050.2ed0: Image Version: 10.0
- 5050.2ed0: SizeOfImage: 0x3ba000 (3907584)
- 5050.2ed0: Resource Dir: 0x389000 LB 0x548
- 5050.2ed0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5050.2ed0: [Raw version resource data: 0x3890b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 5050.2ed0: ProductName: Microsoft® Windows® Operating System
- 5050.2ed0: ProductVersion: 10.0.22621.4541
- 5050.2ed0: FileVersion: 10.0.22621.4541 (WinBuild.160101.0800)
- 5050.2ed0: FileDescription: Windows NT BASE API Client DLL
- 5050.2ed0: \SystemRoot\System32\apisetschema.dll:
- 5050.2ed0: CreationTime: 2024-12-23T14:22:41.175102100Z
- 5050.2ed0: LastWriteTime: 2024-12-23T14:22:41.175102100Z
- 5050.2ed0: ChangeTime: 2024-12-27T04:53:23.177148400Z
- 5050.2ed0: FileAttributes: 0x20
- 5050.2ed0: Size: 0x245e0
- 5050.2ed0: NT Headers: 0xc8
- 5050.2ed0: Timestamp: 0x8f476251
- 5050.2ed0: Machine: 0x8664 - amd64
- 5050.2ed0: Timestamp: 0x8f476251
- 5050.2ed0: Image Version: 10.0
- 5050.2ed0: SizeOfImage: 0x23000 (143360)
- 5050.2ed0: Resource Dir: 0x22000 LB 0x408
- 5050.2ed0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5050.2ed0: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 5050.2ed0: ProductName: Microsoft® Windows® Operating System
- 5050.2ed0: ProductVersion: 10.0.22621.3958
- 5050.2ed0: FileVersion: 10.0.22621.3958 (WinBuild.160101.0800)
- 5050.2ed0: FileDescription: ApiSet Schema DLL
- 5050.2ed0: supR3HardenedWinFindAdversaries: 0x0
- 5050.2ed0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Windows'
- 5050.2ed0: Calling main()
- 5050.2ed0: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 5050.2ed0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Windows'
- 5050.2ed0: SUPR3HardenedMain: Respawn #1
- 5050.2ed0: System32: \Device\HarddiskVolume3\Windows\System32
- 5050.2ed0: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 5050.2ed0: KnownDllPath: C:\Windows\System32
- 5050.2ed0: supR3HardenedWinInit: Performing a limited self purification...
- 5050.2ed0: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
- 5050.2ed0: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 5050.2ed0: 000000007ffe1000-000000007ffe7fff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000007ffe8000-000000007ffe8fff 0x0002/0x0002 0x0020000
- 5050.2ed0: 000000007ffe9000-000000d6715fffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000d671600000-000000d671745fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000000d671746000-000000d671748fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000000d671749000-000000d6717fffff 0x0000/0x0004 0x0020000
- 5050.2ed0: *000000d671800000-000000d6718b8fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000000d6718b9000-000000d6718bbfff 0x0104/0x0004 0x0020000
- 5050.2ed0: 000000d6718bc000-000000d6718fffff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000000d671900000-000001ed518dffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed518e0000-000001ed518effff 0x0004/0x0004 0x0040000
- 5050.2ed0: *000001ed518f0000-000001ed518f2fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed518f3000-000001ed518fffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51900000-000001ed5191efff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed5191f000-000001ed5191ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51920000-000001ed51923fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed51924000-000001ed5192ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51930000-000001ed51930fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed51931000-000001ed5193ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51940000-000001ed51941fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51942000-000001ed5194ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51950000-000001ed51952fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed51953000-000001ed5195ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51960000-000001ed51961fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51962000-000001ed519c1fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000001ed519c2000-000001ed519cffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed519d0000-000001ed519d3fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed519d4000-000001ed519dffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed519e0000-000001ed519e3fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed519e4000-000001ed519effff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed519f0000-000001ed519f1fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed519f2000-000001ed51a3ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51a40000-000001ed51a49fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51a4a000-000001ed51b3ffff 0x0000/0x0004 0x0020000
- 5050.2ed0: *000001ed51b40000-000001ed51c0dfff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001ed51c0e000-000001ed51c0ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51c10000-000001ed51c11fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51c12000-000001ed51c71fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000001ed51c72000-000001ed51d1ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51d20000-000001ed51d2efff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51d2f000-000001ed51d2ffff 0x0000/0x0004 0x0020000
- 5050.2ed0: *000001ed51d30000-000001ed51d3cfff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000001ed51d3d000-000001ed51f54fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51f55000-000001ed51f55fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000001ed51f56000-000001ed51f5ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001ed51f60000-000001ed51f89fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001ed51f8a000-000001ed5205ffff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000001ed52060000-00007df4d84fffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df4d8500000-00007df4d8504fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 00007df4d8505000-00007df4d85fffff 0x0000/0x0002 0x0040000
- 5050.2ed0: *00007df4d8600000-00007df5d861ffff 0x0000/0x0004 0x0020000
- 5050.2ed0: *00007df5d8620000-00007df5da61ffff 0x0000/0x0004 0x0020000
- 5050.2ed0: 00007df5da620000-00007df5da620fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 00007df5da621000-00007df5da62ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df5da630000-00007df5da630fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 00007df5da631000-00007df5da63ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df5da640000-00007df5dba6ffff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007df5dba70000-00007df5dba76fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007df5dba77000-00007df5dc3f7fff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007df5dc3f8000-00007df5dc431fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007df5dc432000-00007ff5b52ddfff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5b52de000-00007ff5b52e2fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5b52e3000-00007ff5ca54afff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5ca54b000-00007ff5cd0eefff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007ff5cd0ef000-00007ff5cd0fefff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5cd0ff000-00007ff5cd182fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007ff5cd183000-00007ff5cd186fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5cd187000-00007ff5cd190fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007ff5cd191000-00007ff5cd199fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5cd19a000-00007ff5da63ffff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5da640000-00007ff6b279ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ff6b27a0000-00007ff6b27a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b27a1000-00007ff6b280bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b280c000-00007ff6b280cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b280d000-00007ff6b2860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2861000-00007ff6b2863fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2864000-00007ff6b2866fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2867000-00007ff6b2869fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b286a000-00007ff6b286afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b286b000-00007ff6b286cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b286d000-00007ff6b286dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b286e000-00007ff6b28a7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b28a8000-00007ffcaabeffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ffcaabf0000-00007ffcaabf0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5050.2ed0: 00007ffcaabf1000-00007ffcaad90fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5050.2ed0: 00007ffcaad91000-00007ffcaaf57fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5050.2ed0: 00007ffcaaf58000-00007ffcaaf5cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5050.2ed0: 00007ffcaaf5d000-00007ffcaaf5dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5050.2ed0: 00007ffcaaf5e000-00007ffcaafa9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5050.2ed0: 00007ffcaafaa000-00007ffcad0bffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ffcad0c0000-00007ffcad0c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5050.2ed0: 00007ffcad0c1000-00007ffcad141fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5050.2ed0: 00007ffcad142000-00007ffcad178fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5050.2ed0: 00007ffcad179000-00007ffcad179fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5050.2ed0: 00007ffcad17a000-00007ffcad17afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5050.2ed0: 00007ffcad17b000-00007ffcad183fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5050.2ed0: 00007ffcad184000-00007ffcad44ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ffcad450000-00007ffcad450fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad451000-00007ffcad581fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad582000-00007ffcad5cffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5d0000-00007ffcad5d0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5d1000-00007ffcad5d2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5d3000-00007ffcad5dbfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5dc000-00007ffcad666fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad667000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 5050.2ed0: kernel32.dll: timestamp 0x1ef15383 (rc=VINF_SUCCESS)
- 5050.2ed0: kernelbase.dll: timestamp 0x8ca6fab8 (rc=VINF_SUCCESS)
- 5050.2ed0: VirtualBoxVM.exe: timestamp 0x670807b4 (rc=VINF_SUCCESS)
- 5050.2ed0: '\Device\HarddiskVolume3\Windows\VirtualBoxVM.exe' has no imports
- 5050.2ed0: VirtualBoxVM.exe: Differences in section #7 (.00cfg) between file and memory:
- 5050.2ed0: 00007ff6b2875000 / 0x00d5000: 10 != 30
- 5050.2ed0: 00007ff6b2875001 / 0x00d5001: e5 != f2
- 5050.2ed0: 00007ff6b2875002 / 0x00d5002: 7b != 4d
- 5050.2ed0: 00007ff6b2875003 / 0x00d5003: b2 != ad
- 5050.2ed0: 00007ff6b2875004 / 0x00d5004: f6 != fc
- 5050.2ed0: 00007ff6b2875008 / 0x00d5008: 10 != 30
- 5050.2ed0: 00007ff6b2875009 / 0x00d5009: e5 != f2
- 5050.2ed0: 00007ff6b287500a / 0x00d500a: 7b != 4d
- 5050.2ed0: 00007ff6b287500b / 0x00d500b: b2 != ad
- 5050.2ed0: 00007ff6b287500c / 0x00d500c: f6 != fc
- 5050.2ed0: 00007ff6b2875010 / 0x00d5010: 00 != 70
- 5050.2ed0: 00007ff6b2875011 / 0x00d5011: b3 != f3
- 5050.2ed0: 00007ff6b2875012 / 0x00d5012: 80 != 4d
- 5050.2ed0: 00007ff6b2875013 / 0x00d5013: b2 != ad
- 5050.2ed0: 00007ff6b2875014 / 0x00d5014: f6 != fc
- 5050.2ed0: 00007ff6b2875018 / 0x00d5018: 20 != 70
- 5050.2ed0: 00007ff6b2875019 / 0x00d5019: b3 != f3
- 5050.2ed0: 00007ff6b287501a / 0x00d501a: 80 != 4d
- 5050.2ed0: 00007ff6b287501b / 0x00d501b: b2 != ad
- 5050.2ed0: 00007ff6b287501c / 0x00d501c: f6 != fc
- 5050.2ed0: 00007ff6b2875020 / 0x00d5020: 20 != 70
- 5050.2ed0: 00007ff6b2875021 / 0x00d5021: b3 != f3
- 5050.2ed0: 00007ff6b2875022 / 0x00d5022: 80 != 4d
- 5050.2ed0: 00007ff6b2875023 / 0x00d5023: b2 != ad
- 5050.2ed0: 00007ff6b2875024 / 0x00d5024: f6 != fc
- 5050.2ed0: Restored 0x28 bytes of original file content at 00007ff6b2875000
- 5050.2ed0: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
- 5050.2ed0: 00007ff6b28a6b28 / 0x0106b28: 00 != 50
- 5050.2ed0: 00007ff6b28a6b29 / 0x0106b29: 00 != 41
- 5050.2ed0: 00007ff6b28a6b2a / 0x0106b2a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b2b / 0x0106b2b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b2c / 0x0106b2c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b2d / 0x0106b2d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b2e / 0x0106b2e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b2f / 0x0106b2f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b30 / 0x0106b30: 00 != 58
- 5050.2ed0: 00007ff6b28a6b31 / 0x0106b31: 00 != 50
- 5050.2ed0: 00007ff6b28a6b32 / 0x0106b32: 00 != 41
- 5050.2ed0: 00007ff6b28a6b33 / 0x0106b33: 00 != 44
- 5050.2ed0: 00007ff6b28a6b34 / 0x0106b34: 00 != 44
- 5050.2ed0: 00007ff6b28a6b35 / 0x0106b35: 00 != 49
- 5050.2ed0: 00007ff6b28a6b36 / 0x0106b36: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b37 / 0x0106b37: 00 != 47
- 5050.2ed0: 00007ff6b28a6b38 / 0x0106b38: 00 != 50
- 5050.2ed0: 00007ff6b28a6b39 / 0x0106b39: 00 != 41
- 5050.2ed0: 00007ff6b28a6b3a / 0x0106b3a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b3b / 0x0106b3b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b3c / 0x0106b3c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b3d / 0x0106b3d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b3e / 0x0106b3e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b3f / 0x0106b3f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b40 / 0x0106b40: 00 != 58
- 5050.2ed0: 00007ff6b28a6b41 / 0x0106b41: 00 != 50
- 5050.2ed0: 00007ff6b28a6b42 / 0x0106b42: 00 != 41
- 5050.2ed0: 00007ff6b28a6b43 / 0x0106b43: 00 != 44
- 5050.2ed0: 00007ff6b28a6b44 / 0x0106b44: 00 != 44
- 5050.2ed0: 00007ff6b28a6b45 / 0x0106b45: 00 != 49
- 5050.2ed0: 00007ff6b28a6b46 / 0x0106b46: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b47 / 0x0106b47: 00 != 47
- 5050.2ed0: 00007ff6b28a6b48 / 0x0106b48: 00 != 50
- 5050.2ed0: 00007ff6b28a6b49 / 0x0106b49: 00 != 41
- 5050.2ed0: 00007ff6b28a6b4a / 0x0106b4a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b4b / 0x0106b4b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b4c / 0x0106b4c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b4d / 0x0106b4d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b4e / 0x0106b4e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b4f / 0x0106b4f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b50 / 0x0106b50: 00 != 58
- 5050.2ed0: 00007ff6b28a6b51 / 0x0106b51: 00 != 50
- 5050.2ed0: 00007ff6b28a6b52 / 0x0106b52: 00 != 41
- 5050.2ed0: 00007ff6b28a6b53 / 0x0106b53: 00 != 44
- 5050.2ed0: 00007ff6b28a6b54 / 0x0106b54: 00 != 44
- 5050.2ed0: 00007ff6b28a6b55 / 0x0106b55: 00 != 49
- 5050.2ed0: 00007ff6b28a6b56 / 0x0106b56: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b57 / 0x0106b57: 00 != 47
- 5050.2ed0: 00007ff6b28a6b58 / 0x0106b58: 00 != 50
- 5050.2ed0: 00007ff6b28a6b59 / 0x0106b59: 00 != 41
- 5050.2ed0: 00007ff6b28a6b5a / 0x0106b5a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b5b / 0x0106b5b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b5c / 0x0106b5c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b5d / 0x0106b5d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b5e / 0x0106b5e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b5f / 0x0106b5f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b60 / 0x0106b60: 00 != 58
- 5050.2ed0: 00007ff6b28a6b61 / 0x0106b61: 00 != 50
- 5050.2ed0: 00007ff6b28a6b62 / 0x0106b62: 00 != 41
- 5050.2ed0: 00007ff6b28a6b63 / 0x0106b63: 00 != 44
- 5050.2ed0: 00007ff6b28a6b64 / 0x0106b64: 00 != 44
- 5050.2ed0: 00007ff6b28a6b65 / 0x0106b65: 00 != 49
- 5050.2ed0: 00007ff6b28a6b66 / 0x0106b66: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b67 / 0x0106b67: 00 != 47
- 5050.2ed0: 00007ff6b28a6b68 / 0x0106b68: 00 != 50
- 5050.2ed0: 00007ff6b28a6b69 / 0x0106b69: 00 != 41
- 5050.2ed0: 00007ff6b28a6b6a / 0x0106b6a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b6b / 0x0106b6b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b6c / 0x0106b6c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b6d / 0x0106b6d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b6e / 0x0106b6e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b6f / 0x0106b6f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b70 / 0x0106b70: 00 != 58
- 5050.2ed0: 00007ff6b28a6b71 / 0x0106b71: 00 != 50
- 5050.2ed0: 00007ff6b28a6b72 / 0x0106b72: 00 != 41
- 5050.2ed0: 00007ff6b28a6b73 / 0x0106b73: 00 != 44
- 5050.2ed0: 00007ff6b28a6b74 / 0x0106b74: 00 != 44
- 5050.2ed0: 00007ff6b28a6b75 / 0x0106b75: 00 != 49
- 5050.2ed0: 00007ff6b28a6b76 / 0x0106b76: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b77 / 0x0106b77: 00 != 47
- 5050.2ed0: 00007ff6b28a6b78 / 0x0106b78: 00 != 50
- 5050.2ed0: 00007ff6b28a6b79 / 0x0106b79: 00 != 41
- 5050.2ed0: 00007ff6b28a6b7a / 0x0106b7a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b7b / 0x0106b7b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b7c / 0x0106b7c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b7d / 0x0106b7d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b7e / 0x0106b7e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b7f / 0x0106b7f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b80 / 0x0106b80: 00 != 58
- 5050.2ed0: 00007ff6b28a6b81 / 0x0106b81: 00 != 50
- 5050.2ed0: 00007ff6b28a6b82 / 0x0106b82: 00 != 41
- 5050.2ed0: 00007ff6b28a6b83 / 0x0106b83: 00 != 44
- 5050.2ed0: 00007ff6b28a6b84 / 0x0106b84: 00 != 44
- 5050.2ed0: 00007ff6b28a6b85 / 0x0106b85: 00 != 49
- 5050.2ed0: 00007ff6b28a6b86 / 0x0106b86: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b87 / 0x0106b87: 00 != 47
- 5050.2ed0: 00007ff6b28a6b88 / 0x0106b88: 00 != 50
- 5050.2ed0: 00007ff6b28a6b89 / 0x0106b89: 00 != 41
- 5050.2ed0: 00007ff6b28a6b8a / 0x0106b8a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b8b / 0x0106b8b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b8c / 0x0106b8c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b8d / 0x0106b8d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b8e / 0x0106b8e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b8f / 0x0106b8f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b90 / 0x0106b90: 00 != 58
- 5050.2ed0: 00007ff6b28a6b91 / 0x0106b91: 00 != 50
- 5050.2ed0: 00007ff6b28a6b92 / 0x0106b92: 00 != 41
- 5050.2ed0: 00007ff6b28a6b93 / 0x0106b93: 00 != 44
- 5050.2ed0: 00007ff6b28a6b94 / 0x0106b94: 00 != 44
- 5050.2ed0: 00007ff6b28a6b95 / 0x0106b95: 00 != 49
- 5050.2ed0: 00007ff6b28a6b96 / 0x0106b96: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b97 / 0x0106b97: 00 != 47
- 5050.2ed0: 00007ff6b28a6b98 / 0x0106b98: 00 != 50
- 5050.2ed0: 00007ff6b28a6b99 / 0x0106b99: 00 != 41
- 5050.2ed0: 00007ff6b28a6b9a / 0x0106b9a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b9b / 0x0106b9b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b9c / 0x0106b9c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b9d / 0x0106b9d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b9e / 0x0106b9e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b9f / 0x0106b9f: 00 != 58
- 5050.2ed0: 00007ff6b28a6ba0 / 0x0106ba0: 00 != 58
- 5050.2ed0: 00007ff6b28a6ba1 / 0x0106ba1: 00 != 50
- 5050.2ed0: 00007ff6b28a6ba2 / 0x0106ba2: 00 != 41
- 5050.2ed0: 00007ff6b28a6ba3 / 0x0106ba3: 00 != 44
- 5050.2ed0: 00007ff6b28a6ba4 / 0x0106ba4: 00 != 44
- 5050.2ed0: 00007ff6b28a6ba5 / 0x0106ba5: 00 != 49
- 5050.2ed0: 00007ff6b28a6ba6 / 0x0106ba6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6ba7 / 0x0106ba7: 00 != 47
- 5050.2ed0: 00007ff6b28a6ba8 / 0x0106ba8: 00 != 50
- 5050.2ed0: 00007ff6b28a6ba9 / 0x0106ba9: 00 != 41
- 5050.2ed0: 00007ff6b28a6baa / 0x0106baa: 00 != 44
- 5050.2ed0: 00007ff6b28a6bab / 0x0106bab: 00 != 44
- 5050.2ed0: 00007ff6b28a6bac / 0x0106bac: 00 != 49
- 5050.2ed0: 00007ff6b28a6bad / 0x0106bad: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bae / 0x0106bae: 00 != 47
- 5050.2ed0: 00007ff6b28a6baf / 0x0106baf: 00 != 58
- 5050.2ed0: 00007ff6b28a6bb0 / 0x0106bb0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bb1 / 0x0106bb1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bb2 / 0x0106bb2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bb3 / 0x0106bb3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bb4 / 0x0106bb4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bb5 / 0x0106bb5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bb6 / 0x0106bb6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bb7 / 0x0106bb7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bb8 / 0x0106bb8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bb9 / 0x0106bb9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bba / 0x0106bba: 00 != 44
- 5050.2ed0: 00007ff6b28a6bbb / 0x0106bbb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bbc / 0x0106bbc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bbd / 0x0106bbd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bbe / 0x0106bbe: 00 != 47
- 5050.2ed0: 00007ff6b28a6bbf / 0x0106bbf: 00 != 58
- 5050.2ed0: 00007ff6b28a6bc0 / 0x0106bc0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bc1 / 0x0106bc1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bc2 / 0x0106bc2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bc3 / 0x0106bc3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bc4 / 0x0106bc4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bc5 / 0x0106bc5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bc6 / 0x0106bc6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bc7 / 0x0106bc7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bc8 / 0x0106bc8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bc9 / 0x0106bc9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bca / 0x0106bca: 00 != 44
- 5050.2ed0: 00007ff6b28a6bcb / 0x0106bcb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bcc / 0x0106bcc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bcd / 0x0106bcd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bce / 0x0106bce: 00 != 47
- 5050.2ed0: 00007ff6b28a6bcf / 0x0106bcf: 00 != 58
- 5050.2ed0: 00007ff6b28a6bd0 / 0x0106bd0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bd1 / 0x0106bd1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bd2 / 0x0106bd2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bd3 / 0x0106bd3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bd4 / 0x0106bd4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bd5 / 0x0106bd5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bd6 / 0x0106bd6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bd7 / 0x0106bd7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bd8 / 0x0106bd8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bd9 / 0x0106bd9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bda / 0x0106bda: 00 != 44
- 5050.2ed0: 00007ff6b28a6bdb / 0x0106bdb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bdc / 0x0106bdc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bdd / 0x0106bdd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bde / 0x0106bde: 00 != 47
- 5050.2ed0: 00007ff6b28a6bdf / 0x0106bdf: 00 != 58
- 5050.2ed0: 00007ff6b28a6be0 / 0x0106be0: 00 != 58
- 5050.2ed0: 00007ff6b28a6be1 / 0x0106be1: 00 != 50
- 5050.2ed0: 00007ff6b28a6be2 / 0x0106be2: 00 != 41
- 5050.2ed0: 00007ff6b28a6be3 / 0x0106be3: 00 != 44
- 5050.2ed0: 00007ff6b28a6be4 / 0x0106be4: 00 != 44
- 5050.2ed0: 00007ff6b28a6be5 / 0x0106be5: 00 != 49
- 5050.2ed0: 00007ff6b28a6be6 / 0x0106be6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6be7 / 0x0106be7: 00 != 47
- 5050.2ed0: 00007ff6b28a6be8 / 0x0106be8: 00 != 50
- 5050.2ed0: 00007ff6b28a6be9 / 0x0106be9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bea / 0x0106bea: 00 != 44
- 5050.2ed0: 00007ff6b28a6beb / 0x0106beb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bec / 0x0106bec: 00 != 49
- 5050.2ed0: 00007ff6b28a6bed / 0x0106bed: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bee / 0x0106bee: 00 != 47
- 5050.2ed0: 00007ff6b28a6bef / 0x0106bef: 00 != 58
- 5050.2ed0: 00007ff6b28a6bf0 / 0x0106bf0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bf1 / 0x0106bf1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bf2 / 0x0106bf2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bf3 / 0x0106bf3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bf4 / 0x0106bf4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bf5 / 0x0106bf5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bf6 / 0x0106bf6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bf7 / 0x0106bf7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bf8 / 0x0106bf8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bf9 / 0x0106bf9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bfa / 0x0106bfa: 00 != 44
- 5050.2ed0: 00007ff6b28a6bfb / 0x0106bfb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bfc / 0x0106bfc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bfd / 0x0106bfd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bfe / 0x0106bfe: 00 != 47
- 5050.2ed0: 00007ff6b28a6bff / 0x0106bff: 00 != 58
- 5050.2ed0: Restored 0x4d8 bytes of original file content at 00007ff6b28a6b28
- 5050.2ed0: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 5050.2ed0: ntdll.dll: Differences in section #9 (.00cfg) between file and memory:
- 5050.2ed0: 00007ffcad5ef000 / 0x019f000: 50 != 70
- 5050.2ed0: 00007ffcad5ef001 / 0x019f001: 40 != f3
- 5050.2ed0: 00007ffcad5ef002 / 0x019f002: 4f != 4d
- 5050.2ed0: 00007ffcad5ef008 / 0x019f008: 20 != 30
- 5050.2ed0: 00007ffcad5ef009 / 0x019f009: f1 != f2
- 5050.2ed0: 00007ffcad5ef011 / 0x019f011: 40 != f3
- 5050.2ed0: 00007ffcad5ef012 / 0x019f012: 4f != 4d
- 5050.2ed0: 00007ffcad5ef019 / 0x019f019: 40 != f3
- 5050.2ed0: 00007ffcad5ef01a / 0x019f01a: 4f != 4d
- 5050.2ed0: Restored 0x28 bytes of original file content at 00007ffcad5ef000
- 5050.2ed0: kernel32.dll: Differences in section #2 (.rdata) between file and memory:
- 5050.2ed0: 00007ffcad1466b8 / 0x00866b8: 10 != 30
- 5050.2ed0: 00007ffcad1466b9 / 0x00866b9: 01 != f2
- 5050.2ed0: 00007ffcad1466ba / 0x00866ba: 0e != 4d
- 5050.2ed0: 00007ffcad1466c0 / 0x00866c0: e0 != 70
- 5050.2ed0: 00007ffcad1466c1 / 0x00866c1: 46 != f3
- 5050.2ed0: 00007ffcad1466c2 / 0x00866c2: 0e != 4d
- 5050.2ed0: 00007ffcad1466c8 / 0x00866c8: 10 != 30
- 5050.2ed0: 00007ffcad1466c9 / 0x00866c9: 01 != f2
- 5050.2ed0: 00007ffcad1466ca / 0x00866ca: 0e != 4d
- 5050.2ed0: 00007ffcad1466d0 / 0x00866d0: 00 != 70
- 5050.2ed0: 00007ffcad1466d1 / 0x00866d1: 47 != f3
- 5050.2ed0: 00007ffcad1466d2 / 0x00866d2: 0e != 4d
- 5050.2ed0: 00007ffcad1466d8 / 0x00866d8: 00 != 70
- 5050.2ed0: 00007ffcad1466d9 / 0x00866d9: 47 != f3
- 5050.2ed0: 00007ffcad1466da / 0x00866da: 0e != 4d
- 5050.2ed0: Restored 0x2000 bytes of original file content at 00007ffcad146000
- 5050.2ed0: kernelbase.dll: Differences in section #2 (.rdata) between file and memory:
- 5050.2ed0: 00007ffcaae61e21 / 0x0271e21: db != f2
- 5050.2ed0: 00007ffcaae61e22 / 0x0271e22: cc != 4d
- 5050.2ed0: 00007ffcaae61e23 / 0x0271e23: aa != ad
- 5050.2ed0: 00007ffcaae61e28 / 0x0271e28: e0 != 70
- 5050.2ed0: 00007ffcaae61e29 / 0x0271e29: de != f3
- 5050.2ed0: 00007ffcaae61e2a / 0x0271e2a: cc != 4d
- 5050.2ed0: 00007ffcaae61e2b / 0x0271e2b: aa != ad
- 5050.2ed0: 00007ffcaae61e31 / 0x0271e31: db != f2
- 5050.2ed0: 00007ffcaae61e32 / 0x0271e32: cc != 4d
- 5050.2ed0: 00007ffcaae61e33 / 0x0271e33: aa != ad
- 5050.2ed0: 00007ffcaae61e38 / 0x0271e38: 00 != 70
- 5050.2ed0: 00007ffcaae61e39 / 0x0271e39: df != f3
- 5050.2ed0: 00007ffcaae61e3a / 0x0271e3a: cc != 4d
- 5050.2ed0: 00007ffcaae61e3b / 0x0271e3b: aa != ad
- 5050.2ed0: 00007ffcaae61e40 / 0x0271e40: 00 != 70
- 5050.2ed0: 00007ffcaae61e41 / 0x0271e41: df != f3
- 5050.2ed0: 00007ffcaae61e42 / 0x0271e42: cc != 4d
- 5050.2ed0: 00007ffcaae61e43 / 0x0271e43: aa != ad
- 5050.2ed0: Restored 0x2000 bytes of original file content at 00007ffcaae61000
- 5050.2ed0: supHardNtVpCheckHandles:
- 5050.2ed0: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=5
- 5050.2ed0: '\Device\HarddiskVolume3\Windows\VirtualBoxVM.exe' has no imports
- 5050.2ed0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\VirtualBoxVM.exe)
- 5050.2ed0: supR3HardNtEnableThreadCreationEx:
- 5050.2ed0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcad4c4400 pvNtTerminateThread=00007ffcad4f0df0
- 5050.2ed0: supR3HardenedWinDoReSpawn(1): New child 1f00.2bac [kernel32].
- 5050.2ed0: supR3HardNtChildGatherData: PebBaseAddress=000000bd60ea9000 cbPeb=0x388
- 5050.2ed0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcad450000 uNtDllChildAddr=00007ffcad450000
- 5050.2ed0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcad4c4400
- 5050.2ed0: supR3HardenedWinSetupChildInit: Initial context:
- rax=0000000000000000 rbx=0000000000000000 rcx=00007ff6b27ab790 rdx=000000bd60ea9000
- rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
- r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
- rip=00007ffcad4aaf10 rsp=000000bd610ffab8 rbp=0000000000000000 ctxflags=0010001b
- cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
- P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
- dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
- dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
- lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
- 5050.2ed0: supR3HardenedWinSetupChildInit: Start child.
- 5050.2ed0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 5050.2ed0: supR3HardNtChildPurify: Startup delay kludge #1/0: 267 ms, 18 sleeps
- 5050.2ed0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 5050.2ed0: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 5050.2ed0: 000000007ffe1000-000000007ffe7fff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000007ffe8000-000000007ffe8fff 0x0002/0x0002 0x0020000
- 5050.2ed0: 000000007ffe9000-000000bd60dfffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000bd60e00000-000000bd60ea8fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000000bd60ea9000-000000bd60eabfff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000000bd60eac000-000000bd60ffffff 0x0000/0x0004 0x0020000
- 5050.2ed0: *000000bd61000000-000000bd610fafff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000000bd610fb000-000000bd610fdfff 0x0104/0x0004 0x0020000
- 5050.2ed0: 000000bd610fe000-000000bd610fffff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000000bd61100000-000001fbfa60ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa610000-000001fbfa62ffff 0x0004/0x0004 0x0020000
- 5050.2ed0: *000001fbfa630000-000001fbfa64efff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001fbfa64f000-000001fbfa64ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa650000-000001fbfa653fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001fbfa654000-000001fbfa65ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa660000-000001fbfa660fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001fbfa661000-000001fbfa66ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa670000-000001fbfa671fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001fbfa672000-00007df5c706ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df5c7070000-00007df5c7070fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 00007df5c7071000-00007df5c707ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df5c7080000-00007df5c84affff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007df5c84b0000-00007df5c84b6fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007df5c84b7000-00007df5c8e37fff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007df5c8e38000-00007df5c8e71fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007df5c8e72000-00007ff5a1d1dfff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5a1d1e000-00007ff5a1d22fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5a1d23000-00007ff5b6f8afff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5b6f8b000-00007ff5b9bd0fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007ff5b9bd1000-00007ff5b9bd9fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5b9bda000-00007ff5c707ffff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5c7080000-00007ff6b279ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ff6b27a0000-00007ff6b27a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b27a1000-00007ff6b280bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b280c000-00007ff6b280cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b280d000-00007ff6b2860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2861000-00007ff6b2861fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2862000-00007ff6b2862fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2863000-00007ff6b2867fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2868000-00007ff6b286dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b286e000-00007ff6b28a7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b28a8000-00007ffcad44ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ffcad450000-00007ffcad450fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad451000-00007ffcad581fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad582000-00007ffcad5cffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5d0000-00007ffcad5dbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5dc000-00007ffcad5eafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5eb000-00007ffcad5ebfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5ec000-00007ffcad5eefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5ef000-00007ffcad666fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad667000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 5050.2ed0: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
- 5050.2ed0: 00007ff6b28a6b28 / 0x0106b28: 00 != 50
- 5050.2ed0: 00007ff6b28a6b29 / 0x0106b29: 00 != 41
- 5050.2ed0: 00007ff6b28a6b2a / 0x0106b2a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b2b / 0x0106b2b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b2c / 0x0106b2c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b2d / 0x0106b2d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b2e / 0x0106b2e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b2f / 0x0106b2f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b30 / 0x0106b30: 00 != 58
- 5050.2ed0: 00007ff6b28a6b31 / 0x0106b31: 00 != 50
- 5050.2ed0: 00007ff6b28a6b32 / 0x0106b32: 00 != 41
- 5050.2ed0: 00007ff6b28a6b33 / 0x0106b33: 00 != 44
- 5050.2ed0: 00007ff6b28a6b34 / 0x0106b34: 00 != 44
- 5050.2ed0: 00007ff6b28a6b35 / 0x0106b35: 00 != 49
- 5050.2ed0: 00007ff6b28a6b36 / 0x0106b36: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b37 / 0x0106b37: 00 != 47
- 5050.2ed0: 00007ff6b28a6b38 / 0x0106b38: 00 != 50
- 5050.2ed0: 00007ff6b28a6b39 / 0x0106b39: 00 != 41
- 5050.2ed0: 00007ff6b28a6b3a / 0x0106b3a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b3b / 0x0106b3b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b3c / 0x0106b3c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b3d / 0x0106b3d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b3e / 0x0106b3e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b3f / 0x0106b3f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b40 / 0x0106b40: 00 != 58
- 5050.2ed0: 00007ff6b28a6b41 / 0x0106b41: 00 != 50
- 5050.2ed0: 00007ff6b28a6b42 / 0x0106b42: 00 != 41
- 5050.2ed0: 00007ff6b28a6b43 / 0x0106b43: 00 != 44
- 5050.2ed0: 00007ff6b28a6b44 / 0x0106b44: 00 != 44
- 5050.2ed0: 00007ff6b28a6b45 / 0x0106b45: 00 != 49
- 5050.2ed0: 00007ff6b28a6b46 / 0x0106b46: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b47 / 0x0106b47: 00 != 47
- 5050.2ed0: 00007ff6b28a6b48 / 0x0106b48: 00 != 50
- 5050.2ed0: 00007ff6b28a6b49 / 0x0106b49: 00 != 41
- 5050.2ed0: 00007ff6b28a6b4a / 0x0106b4a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b4b / 0x0106b4b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b4c / 0x0106b4c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b4d / 0x0106b4d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b4e / 0x0106b4e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b4f / 0x0106b4f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b50 / 0x0106b50: 00 != 58
- 5050.2ed0: 00007ff6b28a6b51 / 0x0106b51: 00 != 50
- 5050.2ed0: 00007ff6b28a6b52 / 0x0106b52: 00 != 41
- 5050.2ed0: 00007ff6b28a6b53 / 0x0106b53: 00 != 44
- 5050.2ed0: 00007ff6b28a6b54 / 0x0106b54: 00 != 44
- 5050.2ed0: 00007ff6b28a6b55 / 0x0106b55: 00 != 49
- 5050.2ed0: 00007ff6b28a6b56 / 0x0106b56: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b57 / 0x0106b57: 00 != 47
- 5050.2ed0: 00007ff6b28a6b58 / 0x0106b58: 00 != 50
- 5050.2ed0: 00007ff6b28a6b59 / 0x0106b59: 00 != 41
- 5050.2ed0: 00007ff6b28a6b5a / 0x0106b5a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b5b / 0x0106b5b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b5c / 0x0106b5c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b5d / 0x0106b5d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b5e / 0x0106b5e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b5f / 0x0106b5f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b60 / 0x0106b60: 00 != 58
- 5050.2ed0: 00007ff6b28a6b61 / 0x0106b61: 00 != 50
- 5050.2ed0: 00007ff6b28a6b62 / 0x0106b62: 00 != 41
- 5050.2ed0: 00007ff6b28a6b63 / 0x0106b63: 00 != 44
- 5050.2ed0: 00007ff6b28a6b64 / 0x0106b64: 00 != 44
- 5050.2ed0: 00007ff6b28a6b65 / 0x0106b65: 00 != 49
- 5050.2ed0: 00007ff6b28a6b66 / 0x0106b66: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b67 / 0x0106b67: 00 != 47
- 5050.2ed0: 00007ff6b28a6b68 / 0x0106b68: 00 != 50
- 5050.2ed0: 00007ff6b28a6b69 / 0x0106b69: 00 != 41
- 5050.2ed0: 00007ff6b28a6b6a / 0x0106b6a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b6b / 0x0106b6b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b6c / 0x0106b6c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b6d / 0x0106b6d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b6e / 0x0106b6e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b6f / 0x0106b6f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b70 / 0x0106b70: 00 != 58
- 5050.2ed0: 00007ff6b28a6b71 / 0x0106b71: 00 != 50
- 5050.2ed0: 00007ff6b28a6b72 / 0x0106b72: 00 != 41
- 5050.2ed0: 00007ff6b28a6b73 / 0x0106b73: 00 != 44
- 5050.2ed0: 00007ff6b28a6b74 / 0x0106b74: 00 != 44
- 5050.2ed0: 00007ff6b28a6b75 / 0x0106b75: 00 != 49
- 5050.2ed0: 00007ff6b28a6b76 / 0x0106b76: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b77 / 0x0106b77: 00 != 47
- 5050.2ed0: 00007ff6b28a6b78 / 0x0106b78: 00 != 50
- 5050.2ed0: 00007ff6b28a6b79 / 0x0106b79: 00 != 41
- 5050.2ed0: 00007ff6b28a6b7a / 0x0106b7a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b7b / 0x0106b7b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b7c / 0x0106b7c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b7d / 0x0106b7d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b7e / 0x0106b7e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b7f / 0x0106b7f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b80 / 0x0106b80: 00 != 58
- 5050.2ed0: 00007ff6b28a6b81 / 0x0106b81: 00 != 50
- 5050.2ed0: 00007ff6b28a6b82 / 0x0106b82: 00 != 41
- 5050.2ed0: 00007ff6b28a6b83 / 0x0106b83: 00 != 44
- 5050.2ed0: 00007ff6b28a6b84 / 0x0106b84: 00 != 44
- 5050.2ed0: 00007ff6b28a6b85 / 0x0106b85: 00 != 49
- 5050.2ed0: 00007ff6b28a6b86 / 0x0106b86: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b87 / 0x0106b87: 00 != 47
- 5050.2ed0: 00007ff6b28a6b88 / 0x0106b88: 00 != 50
- 5050.2ed0: 00007ff6b28a6b89 / 0x0106b89: 00 != 41
- 5050.2ed0: 00007ff6b28a6b8a / 0x0106b8a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b8b / 0x0106b8b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b8c / 0x0106b8c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b8d / 0x0106b8d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b8e / 0x0106b8e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b8f / 0x0106b8f: 00 != 58
- 5050.2ed0: 00007ff6b28a6b90 / 0x0106b90: 00 != 58
- 5050.2ed0: 00007ff6b28a6b91 / 0x0106b91: 00 != 50
- 5050.2ed0: 00007ff6b28a6b92 / 0x0106b92: 00 != 41
- 5050.2ed0: 00007ff6b28a6b93 / 0x0106b93: 00 != 44
- 5050.2ed0: 00007ff6b28a6b94 / 0x0106b94: 00 != 44
- 5050.2ed0: 00007ff6b28a6b95 / 0x0106b95: 00 != 49
- 5050.2ed0: 00007ff6b28a6b96 / 0x0106b96: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b97 / 0x0106b97: 00 != 47
- 5050.2ed0: 00007ff6b28a6b98 / 0x0106b98: 00 != 50
- 5050.2ed0: 00007ff6b28a6b99 / 0x0106b99: 00 != 41
- 5050.2ed0: 00007ff6b28a6b9a / 0x0106b9a: 00 != 44
- 5050.2ed0: 00007ff6b28a6b9b / 0x0106b9b: 00 != 44
- 5050.2ed0: 00007ff6b28a6b9c / 0x0106b9c: 00 != 49
- 5050.2ed0: 00007ff6b28a6b9d / 0x0106b9d: 00 != 4e
- 5050.2ed0: 00007ff6b28a6b9e / 0x0106b9e: 00 != 47
- 5050.2ed0: 00007ff6b28a6b9f / 0x0106b9f: 00 != 58
- 5050.2ed0: 00007ff6b28a6ba0 / 0x0106ba0: 00 != 58
- 5050.2ed0: 00007ff6b28a6ba1 / 0x0106ba1: 00 != 50
- 5050.2ed0: 00007ff6b28a6ba2 / 0x0106ba2: 00 != 41
- 5050.2ed0: 00007ff6b28a6ba3 / 0x0106ba3: 00 != 44
- 5050.2ed0: 00007ff6b28a6ba4 / 0x0106ba4: 00 != 44
- 5050.2ed0: 00007ff6b28a6ba5 / 0x0106ba5: 00 != 49
- 5050.2ed0: 00007ff6b28a6ba6 / 0x0106ba6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6ba7 / 0x0106ba7: 00 != 47
- 5050.2ed0: 00007ff6b28a6ba8 / 0x0106ba8: 00 != 50
- 5050.2ed0: 00007ff6b28a6ba9 / 0x0106ba9: 00 != 41
- 5050.2ed0: 00007ff6b28a6baa / 0x0106baa: 00 != 44
- 5050.2ed0: 00007ff6b28a6bab / 0x0106bab: 00 != 44
- 5050.2ed0: 00007ff6b28a6bac / 0x0106bac: 00 != 49
- 5050.2ed0: 00007ff6b28a6bad / 0x0106bad: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bae / 0x0106bae: 00 != 47
- 5050.2ed0: 00007ff6b28a6baf / 0x0106baf: 00 != 58
- 5050.2ed0: 00007ff6b28a6bb0 / 0x0106bb0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bb1 / 0x0106bb1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bb2 / 0x0106bb2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bb3 / 0x0106bb3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bb4 / 0x0106bb4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bb5 / 0x0106bb5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bb6 / 0x0106bb6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bb7 / 0x0106bb7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bb8 / 0x0106bb8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bb9 / 0x0106bb9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bba / 0x0106bba: 00 != 44
- 5050.2ed0: 00007ff6b28a6bbb / 0x0106bbb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bbc / 0x0106bbc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bbd / 0x0106bbd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bbe / 0x0106bbe: 00 != 47
- 5050.2ed0: 00007ff6b28a6bbf / 0x0106bbf: 00 != 58
- 5050.2ed0: 00007ff6b28a6bc0 / 0x0106bc0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bc1 / 0x0106bc1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bc2 / 0x0106bc2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bc3 / 0x0106bc3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bc4 / 0x0106bc4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bc5 / 0x0106bc5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bc6 / 0x0106bc6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bc7 / 0x0106bc7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bc8 / 0x0106bc8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bc9 / 0x0106bc9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bca / 0x0106bca: 00 != 44
- 5050.2ed0: 00007ff6b28a6bcb / 0x0106bcb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bcc / 0x0106bcc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bcd / 0x0106bcd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bce / 0x0106bce: 00 != 47
- 5050.2ed0: 00007ff6b28a6bcf / 0x0106bcf: 00 != 58
- 5050.2ed0: 00007ff6b28a6bd0 / 0x0106bd0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bd1 / 0x0106bd1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bd2 / 0x0106bd2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bd3 / 0x0106bd3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bd4 / 0x0106bd4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bd5 / 0x0106bd5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bd6 / 0x0106bd6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bd7 / 0x0106bd7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bd8 / 0x0106bd8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bd9 / 0x0106bd9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bda / 0x0106bda: 00 != 44
- 5050.2ed0: 00007ff6b28a6bdb / 0x0106bdb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bdc / 0x0106bdc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bdd / 0x0106bdd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bde / 0x0106bde: 00 != 47
- 5050.2ed0: 00007ff6b28a6bdf / 0x0106bdf: 00 != 58
- 5050.2ed0: 00007ff6b28a6be0 / 0x0106be0: 00 != 58
- 5050.2ed0: 00007ff6b28a6be1 / 0x0106be1: 00 != 50
- 5050.2ed0: 00007ff6b28a6be2 / 0x0106be2: 00 != 41
- 5050.2ed0: 00007ff6b28a6be3 / 0x0106be3: 00 != 44
- 5050.2ed0: 00007ff6b28a6be4 / 0x0106be4: 00 != 44
- 5050.2ed0: 00007ff6b28a6be5 / 0x0106be5: 00 != 49
- 5050.2ed0: 00007ff6b28a6be6 / 0x0106be6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6be7 / 0x0106be7: 00 != 47
- 5050.2ed0: 00007ff6b28a6be8 / 0x0106be8: 00 != 50
- 5050.2ed0: 00007ff6b28a6be9 / 0x0106be9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bea / 0x0106bea: 00 != 44
- 5050.2ed0: 00007ff6b28a6beb / 0x0106beb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bec / 0x0106bec: 00 != 49
- 5050.2ed0: 00007ff6b28a6bed / 0x0106bed: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bee / 0x0106bee: 00 != 47
- 5050.2ed0: 00007ff6b28a6bef / 0x0106bef: 00 != 58
- 5050.2ed0: 00007ff6b28a6bf0 / 0x0106bf0: 00 != 58
- 5050.2ed0: 00007ff6b28a6bf1 / 0x0106bf1: 00 != 50
- 5050.2ed0: 00007ff6b28a6bf2 / 0x0106bf2: 00 != 41
- 5050.2ed0: 00007ff6b28a6bf3 / 0x0106bf3: 00 != 44
- 5050.2ed0: 00007ff6b28a6bf4 / 0x0106bf4: 00 != 44
- 5050.2ed0: 00007ff6b28a6bf5 / 0x0106bf5: 00 != 49
- 5050.2ed0: 00007ff6b28a6bf6 / 0x0106bf6: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bf7 / 0x0106bf7: 00 != 47
- 5050.2ed0: 00007ff6b28a6bf8 / 0x0106bf8: 00 != 50
- 5050.2ed0: 00007ff6b28a6bf9 / 0x0106bf9: 00 != 41
- 5050.2ed0: 00007ff6b28a6bfa / 0x0106bfa: 00 != 44
- 5050.2ed0: 00007ff6b28a6bfb / 0x0106bfb: 00 != 44
- 5050.2ed0: 00007ff6b28a6bfc / 0x0106bfc: 00 != 49
- 5050.2ed0: 00007ff6b28a6bfd / 0x0106bfd: 00 != 4e
- 5050.2ed0: 00007ff6b28a6bfe / 0x0106bfe: 00 != 47
- 5050.2ed0: 00007ff6b28a6bff / 0x0106bff: 00 != 58
- 5050.2ed0: Restored 0x4d8 bytes of original file content at 00007ff6b28a6b28
- 5050.2ed0: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x80000000
- 5050.2ed0: supR3HardNtChildPurify: Startup delay kludge #1/1: 516 ms, 36 sleeps
- 5050.2ed0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 5050.2ed0: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 5050.2ed0: 000000007ffe1000-000000007ffe7fff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000007ffe8000-000000007ffe8fff 0x0002/0x0002 0x0020000
- 5050.2ed0: 000000007ffe9000-000000bd60dfffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000000bd60e00000-000000bd60ea8fff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000000bd60ea9000-000000bd60eabfff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000000bd60eac000-000000bd60ffffff 0x0000/0x0004 0x0020000
- 5050.2ed0: *000000bd61000000-000000bd610fafff 0x0000/0x0004 0x0020000
- 5050.2ed0: 000000bd610fb000-000000bd610fdfff 0x0104/0x0004 0x0020000
- 5050.2ed0: 000000bd610fe000-000000bd610fffff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000000bd61100000-000001fbfa60ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa610000-000001fbfa62ffff 0x0004/0x0004 0x0020000
- 5050.2ed0: *000001fbfa630000-000001fbfa64efff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001fbfa64f000-000001fbfa64ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa650000-000001fbfa653fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001fbfa654000-000001fbfa65ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa660000-000001fbfa660fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 000001fbfa661000-000001fbfa66ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *000001fbfa670000-000001fbfa671fff 0x0004/0x0004 0x0020000
- 5050.2ed0: 000001fbfa672000-00007df5c706ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df5c7070000-00007df5c7070fff 0x0002/0x0002 0x0040000
- 5050.2ed0: 00007df5c7071000-00007df5c707ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007df5c7080000-00007df5c84affff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007df5c84b0000-00007df5c84b6fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007df5c84b7000-00007df5c8e37fff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007df5c8e38000-00007df5c8e71fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007df5c8e72000-00007ff5a1d1dfff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5a1d1e000-00007ff5a1d22fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5a1d23000-00007ff5b6f8afff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5b6f8b000-00007ff5b9bd0fff 0x0001/0x0001 0x0040000
- 5050.2ed0: 00007ff5b9bd1000-00007ff5b9bd9fff 0x0002/0x0001 0x0040000
- 5050.2ed0: 00007ff5b9bda000-00007ff5c707ffff 0x0000/0x0001 0x0040000
- 5050.2ed0: 00007ff5c7080000-00007ff6b279ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ff6b27a0000-00007ff6b27a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b27a1000-00007ff6b280bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b280c000-00007ff6b280cfff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b280d000-00007ff6b2860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b2861000-00007ff6b286dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b286e000-00007ff6b28a7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\VirtualBoxVM.exe
- 5050.2ed0: 00007ff6b28a8000-00007ffcad44ffff 0x0001/0x0000 0x0000000
- 5050.2ed0: *00007ffcad450000-00007ffcad450fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad451000-00007ffcad581fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad582000-00007ffcad5cffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5d0000-00007ffcad5d3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5d4000-00007ffcad5dbfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5dc000-00007ffcad5eafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5eb000-00007ffcad5ebfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5ec000-00007ffcad5eefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad5ef000-00007ffcad666fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5050.2ed0: 00007ffcad667000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 5050.2ed0: supR3HardNtChildPurify: Done after 786 ms and 1 fixes (loop #1).
- 1f00.2bac: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcad450000 g_uNtVerCombined=0xa0586700 (stack ~000000bd610fe880)
- 1f00.2bac: ntdll.dll: timestamp 0xe7035eba (rc=VINF_SUCCESS)
- 1f00.2bac: New simple heap: #1 000001fbfa780000 LB 0x800000 (for 2191360 allocation)
- 1f00.2bac: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Windows'
- 1f00.2bac: System32: \Device\HarddiskVolume3\Windows\System32
- 1f00.2bac: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 1f00.2bac: KnownDllPath: C:\Windows\System32
- 1f00.2bac: supR3HardenedVmProcessInit: Opening vboxsup stub...
- 5050.2ed0: supR3HardNtEnableThreadCreationEx:
- 1f00.2bac: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 1f00.2bac: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 1f00.2bac: Registered Dll notification callback with NTDLL.
- 1f00.2bac: supHardenedWinVerifyImageByHandle: -> -5657 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
- 1f00.2bac: Error (rc=0):
- 1f00.2bac: supR3HardenedScreenImage/LdrLoadDll: rc=-5657 fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume3\Windows\System32\kernel32.dll: Signature #1/1: Not signed with the build certificate (serial 33 00 00 04 8e 16 55 47 b1 c3 02 85 03 00 00 00 00 04 8e, expected 06 0e 2f 8f 9e 1b 8b e5 18 d5 fe 2b 69 cf cc b1): \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 1f00.2bac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 1f00.2bac: Error (rc=0):
- 1f00.2bac: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Windows\System32\KERNEL32.DLL': rcNt=0xc0000190
- 1f00.2bac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Windows\System32\KERNEL32.DLL'
- 5050.2ed0: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000190 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 89 ms, CloseEvents);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement