| 1 | 1e00.2090: Log file opened: 5.0.8r103449 g_hStartupLog=0000000000000058 g_uNtVerCombined=0xa0280000
|
|---|
| 2 | 1e00.2090: \SystemRoot\System32\ntdll.dll:
|
|---|
| 3 | 1e00.2090: CreationTime: 2015-08-20T23:20:59.070821600Z
|
|---|
| 4 | 1e00.2090: LastWriteTime: 2015-08-08T07:29:58.168349600Z
|
|---|
| 5 | 1e00.2090: ChangeTime: 2015-08-21T10:30:50.420447700Z
|
|---|
| 6 | 1e00.2090: FileAttributes: 0x20
|
|---|
| 7 | 1e00.2090: Size: 0x1bce48
|
|---|
| 8 | 1e00.2090: NT Headers: 0xd8
|
|---|
| 9 | 1e00.2090: Timestamp: 0x55c59f92
|
|---|
| 10 | 1e00.2090: Machine: 0x8664 - amd64
|
|---|
| 11 | 1e00.2090: Timestamp: 0x55c59f92
|
|---|
| 12 | 1e00.2090: Image Version: 10.0
|
|---|
| 13 | 1e00.2090: SizeOfImage: 0x1c1000 (1839104)
|
|---|
| 14 | 1e00.2090: Resource Dir: 0x15a000 LB 0x65718
|
|---|
| 15 | 1e00.2090: ProductName: Microsoft® Windows® Operating System
|
|---|
| 16 | 1e00.2090: ProductVersion: 10.0.10240.16430
|
|---|
| 17 | 1e00.2090: FileVersion: 10.0.10240.16430 (th1.150807-2049)
|
|---|
| 18 | 1e00.2090: FileDescription: NT Layer DLL
|
|---|
| 19 | 1e00.2090: \SystemRoot\System32\kernel32.dll:
|
|---|
| 20 | 1e00.2090: CreationTime: 2015-07-10T10:59:59.699781600Z
|
|---|
| 21 | 1e00.2090: LastWriteTime: 2015-07-10T10:59:59.699781600Z
|
|---|
| 22 | 1e00.2090: ChangeTime: 2015-10-13T23:39:05.537198800Z
|
|---|
| 23 | 1e00.2090: FileAttributes: 0x20
|
|---|
| 24 | 1e00.2090: Size: 0xab830
|
|---|
| 25 | 1e00.2090: NT Headers: 0xf0
|
|---|
| 26 | 1e00.2090: Timestamp: 0x559f38ad
|
|---|
| 27 | 1e00.2090: Machine: 0x8664 - amd64
|
|---|
| 28 | 1e00.2090: Timestamp: 0x559f38ad
|
|---|
| 29 | 1e00.2090: Image Version: 10.0
|
|---|
| 30 | 1e00.2090: SizeOfImage: 0xad000 (708608)
|
|---|
| 31 | 1e00.2090: Resource Dir: 0xab000 LB 0x518
|
|---|
| 32 | 1e00.2090: ProductName: Microsoft® Windows® Operating System
|
|---|
| 33 | 1e00.2090: ProductVersion: 10.0.10240.16384
|
|---|
| 34 | 1e00.2090: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 35 | 1e00.2090: FileDescription: Windows NT BASE API Client DLL
|
|---|
| 36 | 1e00.2090: \SystemRoot\System32\KernelBase.dll:
|
|---|
| 37 | 1e00.2090: CreationTime: 2015-07-10T11:00:10.325689700Z
|
|---|
| 38 | 1e00.2090: LastWriteTime: 2015-07-10T11:00:10.325689700Z
|
|---|
| 39 | 1e00.2090: ChangeTime: 2015-10-13T23:39:05.865323100Z
|
|---|
| 40 | 1e00.2090: FileAttributes: 0x20
|
|---|
| 41 | 1e00.2090: Size: 0x1dc680
|
|---|
| 42 | 1e00.2090: NT Headers: 0x100
|
|---|
| 43 | 1e00.2090: Timestamp: 0x559f38c3
|
|---|
| 44 | 1e00.2090: Machine: 0x8664 - amd64
|
|---|
| 45 | 1e00.2090: Timestamp: 0x559f38c3
|
|---|
| 46 | 1e00.2090: Image Version: 10.0
|
|---|
| 47 | 1e00.2090: SizeOfImage: 0x1dd000 (1953792)
|
|---|
| 48 | 1e00.2090: Resource Dir: 0x1c7000 LB 0x530
|
|---|
| 49 | 1e00.2090: ProductName: Microsoft® Windows® Operating System
|
|---|
| 50 | 1e00.2090: ProductVersion: 10.0.10240.16384
|
|---|
| 51 | 1e00.2090: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 52 | 1e00.2090: FileDescription: Windows NT BASE API Client DLL
|
|---|
| 53 | 1e00.2090: \SystemRoot\System32\apisetschema.dll:
|
|---|
| 54 | 1e00.2090: CreationTime: 2015-07-10T11:00:04.872098600Z
|
|---|
| 55 | 1e00.2090: LastWriteTime: 2015-07-10T11:00:04.872098600Z
|
|---|
| 56 | 1e00.2090: ChangeTime: 2015-08-21T03:35:07.893781700Z
|
|---|
| 57 | 1e00.2090: FileAttributes: 0x20
|
|---|
| 58 | 1e00.2090: Size: 0x16760
|
|---|
| 59 | 1e00.2090: NT Headers: 0xc8
|
|---|
| 60 | 1e00.2090: Timestamp: 0x559f3e3d
|
|---|
| 61 | 1e00.2090: Machine: 0x8664 - amd64
|
|---|
| 62 | 1e00.2090: Timestamp: 0x559f3e3d
|
|---|
| 63 | 1e00.2090: Image Version: 10.0
|
|---|
| 64 | 1e00.2090: SizeOfImage: 0x17000 (94208)
|
|---|
| 65 | 1e00.2090: Resource Dir: 0x16000 LB 0x3f0
|
|---|
| 66 | 1e00.2090: ProductName: Microsoft® Windows® Operating System
|
|---|
| 67 | 1e00.2090: ProductVersion: 10.0.10240.16384
|
|---|
| 68 | 1e00.2090: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 69 | 1e00.2090: FileDescription: ApiSet Schema DLL
|
|---|
| 70 | 1e00.2090: NtOpenDirectoryObject failed on \Driver: 0xc0000022
|
|---|
| 71 | 1e00.2090: supR3HardenedWinFindAdversaries: 0x0
|
|---|
| 72 | 1e00.2090: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 73 | 1e00.2090: Calling main()
|
|---|
| 74 | 1e00.2090: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
|
|---|
| 75 | 1e00.2090: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 76 | 1e00.2090: SUPR3HardenedMain: Respawn #1
|
|---|
| 77 | 1e00.2090: System32: \Device\HarddiskVolume4\Windows\System32
|
|---|
| 78 | 1e00.2090: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
|
|---|
| 79 | 1e00.2090: KnownDllPath: C:\Windows\system32
|
|---|
| 80 | 1e00.2090: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 81 | 1e00.2090: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
|
|---|
| 82 | 1e00.2090: supR3HardNtEnableThreadCreation:
|
|---|
| 83 | 1e00.2090: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffad453fb70 pvNtTerminateThread=00007ffad4563a20
|
|---|
| 84 | 1e00.2090: supR3HardenedWinDoReSpawn(1): New child 17d4.18f8 [kernel32].
|
|---|
| 85 | 1e00.2090: supR3HardNtChildGatherData: PebBaseAddress=00007ff674c0a000 cbPeb=0x388
|
|---|
| 86 | 1e00.2090: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffad44d0000 uNtDllChildAddr=00007ffad44d0000
|
|---|
| 87 | 1e00.2090: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffad453fb70
|
|---|
| 88 | 1e00.2090: supR3HardenedWinSetupChildInit: Start child.
|
|---|
| 89 | 1e00.2090: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
|
|---|
| 90 | 1e00.2090: supR3HardNtChildPurify: Startup delay kludge #1/0: 266 ms, 21 sleeps
|
|---|
| 91 | 1e00.2090: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
|
|---|
| 92 | 1e00.2090: *0000000000000000-ffffffffff00ffff 0x0001/0x0000 0x0000000
|
|---|
| 93 | 1e00.2090: *0000000000ff0000-0000000000fcffff 0x0004/0x0004 0x0020000
|
|---|
| 94 | 1e00.2090: *0000000001010000-0000000000ffbfff 0x0002/0x0002 0x0040000
|
|---|
| 95 | 1e00.2090: 0000000001024000-0000000001017fff 0x0001/0x0000 0x0000000
|
|---|
| 96 | 1e00.2090: *0000000001030000-0000000000f33fff 0x0000/0x0004 0x0020000
|
|---|
| 97 | 1e00.2090: 000000000112c000-0000000001128fff 0x0104/0x0004 0x0020000
|
|---|
| 98 | 1e00.2090: 000000000112f000-000000000112dfff 0x0004/0x0004 0x0020000
|
|---|
| 99 | 1e00.2090: *0000000001130000-000000000112bfff 0x0002/0x0002 0x0040000
|
|---|
| 100 | 1e00.2090: 0000000001134000-0000000001127fff 0x0001/0x0000 0x0000000
|
|---|
| 101 | 1e00.2090: *0000000001140000-000000000113dfff 0x0004/0x0004 0x0020000
|
|---|
| 102 | 1e00.2090: 0000000001142000-ffffffff822a3fff 0x0001/0x0000 0x0000000
|
|---|
| 103 | 1e00.2090: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
|
|---|
| 104 | 1e00.2090: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
|
|---|
| 105 | 1e00.2090: 000000007fff0000-ffff800a8b3fffff 0x0001/0x0000 0x0000000
|
|---|
| 106 | 1e00.2090: *00007ff674be0000-00007ff674bbcfff 0x0002/0x0002 0x0040000
|
|---|
| 107 | 1e00.2090: 00007ff674c03000-00007ff674bfbfff 0x0001/0x0000 0x0000000
|
|---|
| 108 | 1e00.2090: *00007ff674c0a000-00007ff674c08fff 0x0004/0x0004 0x0020000
|
|---|
| 109 | 1e00.2090: 00007ff674c0b000-00007ff674c07fff 0x0001/0x0000 0x0000000
|
|---|
| 110 | 1e00.2090: *00007ff674c0e000-00007ff674c0bfff 0x0004/0x0004 0x0020000
|
|---|
| 111 | 1e00.2090: 00007ff674c10000-00007ff67423ffff 0x0001/0x0000 0x0000000
|
|---|
| 112 | 1e00.2090: *00007ff6755e0000-00007ff6755e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 113 | 1e00.2090: 00007ff6755e1000-00007ff675667fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 114 | 1e00.2090: 00007ff675668000-00007ff675668fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 115 | 1e00.2090: 00007ff675669000-00007ff6756b3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 116 | 1e00.2090: 00007ff6756b4000-00007ff6756b4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 117 | 1e00.2090: 00007ff6756b5000-00007ff6756b5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 118 | 1e00.2090: 00007ff6756b6000-00007ff6756bafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 119 | 1e00.2090: 00007ff6756bb000-00007ff6756bbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 120 | 1e00.2090: 00007ff6756bc000-00007ff6756bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 121 | 1e00.2090: 00007ff6756bd000-00007ff6756c0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 122 | 1e00.2090: 00007ff6756c1000-00007ff67570bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 123 | 1e00.2090: 00007ff67570c000-00007ff216947fff 0x0001/0x0000 0x0000000
|
|---|
| 124 | 1e00.2090: *00007ffad44d0000-00007ffad44d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 125 | 1e00.2090: 00007ffad44d1000-00007ffad45ccfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 126 | 1e00.2090: 00007ffad45cd000-00007ffad460efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 127 | 1e00.2090: 00007ffad460f000-00007ffad4617fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 128 | 1e00.2090: 00007ffad4618000-00007ffad4625fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 129 | 1e00.2090: 00007ffad4626000-00007ffad4626fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 130 | 1e00.2090: 00007ffad4627000-00007ffad4629fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 131 | 1e00.2090: 00007ffad462a000-00007ffad4690fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 132 | 1e00.2090: 00007ffad4691000-00007ff5a8d41fff 0x0001/0x0000 0x0000000
|
|---|
| 133 | 1e00.2090: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
|
|---|
| 134 | 1e00.2090: VirtualBox.exe: timestamp 0x561faefe (rc=VINF_SUCCESS)
|
|---|
| 135 | 1e00.2090: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 136 | 1e00.2090: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
|
|---|
| 137 | 1e00.2090: supR3HardNtChildPurify: Done after 281 ms and 0 fixes (loop #0).
|
|---|
| 138 | 17d4.18f8: Log file opened: 5.0.8r103449 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0280000
|
|---|
| 139 | 17d4.18f8: supR3HardenedVmProcessInit: uNtDllAddr=00007ffad44d0000
|
|---|
| 140 | 1e00.2090: supR3HardNtEnableThreadCreation:
|
|---|
| 141 | 17d4.18f8: ntdll.dll: timestamp 0x55c59f92 (rc=VINF_SUCCESS)
|
|---|
| 142 | 17d4.18f8: New simple heap: #1 0000000001250000 LB 0x400000 (for 1839104 allocation)
|
|---|
| 143 | 17d4.18f8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 144 | 17d4.18f8: System32: \Device\HarddiskVolume4\Windows\System32
|
|---|
| 145 | 17d4.18f8: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
|
|---|
| 146 | 17d4.18f8: KnownDllPath: C:\Windows\system32
|
|---|
| 147 | 17d4.18f8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
|
|---|
| 148 | 17d4.18f8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
|
|---|
| 149 | 17d4.18f8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
|
|---|
| 150 | 17d4.18f8: Registered Dll notification callback with NTDLL.
|
|---|
| 151 | 17d4.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
|
|---|
| 152 | 17d4.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
|
|---|
| 153 | 17d4.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
|
|---|
| 154 | 17d4.18f8: supR3HardenedDllNotificationCallback: load 00007ffad1900000 LB 0x001dd000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
|
|---|
| 155 | 17d4.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
|
|---|
| 156 | 17d4.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
|
|---|
| 157 | 17d4.18f8: supR3HardenedDllNotificationCallback: load 00007ffad4420000 LB 0x000ad000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]
|
|---|
| 158 | 17d4.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
|
|---|
| 159 | 17d4.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4420000 'C:\Windows\system32\KERNEL32.DLL'
|
|---|
| 160 | 17d4.18f8: supR3HardenedDllNotificationCallback: load 00007ff6755e0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
|
|---|
| 161 | 17d4.18f8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 162 | 17d4.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
|
|---|
| 163 | 17d4.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 164 | 17d4.18f8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffad453fb70 pvNtTerminateThread=00007ffad4563a20
|
|---|
| 165 | 1e00.2090: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 63 ms.
|
|---|
| 166 | 17d4.18f8: \SystemRoot\System32\ntdll.dll:
|
|---|
| 167 | 17d4.18f8: CreationTime: 2015-08-20T23:20:59.070821600Z
|
|---|
| 168 | 17d4.18f8: LastWriteTime: 2015-08-08T07:29:58.168349600Z
|
|---|
| 169 | 17d4.18f8: ChangeTime: 2015-08-21T10:30:50.420447700Z
|
|---|
| 170 | 17d4.18f8: FileAttributes: 0x20
|
|---|
| 171 | 17d4.18f8: Size: 0x1bce48
|
|---|
| 172 | 17d4.18f8: NT Headers: 0xd8
|
|---|
| 173 | 17d4.18f8: Timestamp: 0x55c59f92
|
|---|
| 174 | 17d4.18f8: Machine: 0x8664 - amd64
|
|---|
| 175 | 17d4.18f8: Timestamp: 0x55c59f92
|
|---|
| 176 | 17d4.18f8: Image Version: 10.0
|
|---|
| 177 | 17d4.18f8: SizeOfImage: 0x1c1000 (1839104)
|
|---|
| 178 | 17d4.18f8: Resource Dir: 0x15a000 LB 0x65718
|
|---|
| 179 | 17d4.18f8: ProductName: Microsoft® Windows® Operating System
|
|---|
| 180 | 17d4.18f8: ProductVersion: 10.0.10240.16430
|
|---|
| 181 | 17d4.18f8: FileVersion: 10.0.10240.16430 (th1.150807-2049)
|
|---|
| 182 | 17d4.18f8: FileDescription: NT Layer DLL
|
|---|
| 183 | 17d4.18f8: \SystemRoot\System32\kernel32.dll:
|
|---|
| 184 | 17d4.18f8: CreationTime: 2015-07-10T10:59:59.699781600Z
|
|---|
| 185 | 17d4.18f8: LastWriteTime: 2015-07-10T10:59:59.699781600Z
|
|---|
| 186 | 17d4.18f8: ChangeTime: 2015-10-13T23:39:05.537198800Z
|
|---|
| 187 | 17d4.18f8: FileAttributes: 0x20
|
|---|
| 188 | 17d4.18f8: Size: 0xab830
|
|---|
| 189 | 17d4.18f8: NT Headers: 0xf0
|
|---|
| 190 | 17d4.18f8: Timestamp: 0x559f38ad
|
|---|
| 191 | 17d4.18f8: Machine: 0x8664 - amd64
|
|---|
| 192 | 17d4.18f8: Timestamp: 0x559f38ad
|
|---|
| 193 | 17d4.18f8: Image Version: 10.0
|
|---|
| 194 | 17d4.18f8: SizeOfImage: 0xad000 (708608)
|
|---|
| 195 | 17d4.18f8: Resource Dir: 0xab000 LB 0x518
|
|---|
| 196 | 17d4.18f8: ProductName: Microsoft® Windows® Operating System
|
|---|
| 197 | 17d4.18f8: ProductVersion: 10.0.10240.16384
|
|---|
| 198 | 17d4.18f8: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 199 | 17d4.18f8: FileDescription: Windows NT BASE API Client DLL
|
|---|
| 200 | 17d4.18f8: \SystemRoot\System32\KernelBase.dll:
|
|---|
| 201 | 17d4.18f8: CreationTime: 2015-07-10T11:00:10.325689700Z
|
|---|
| 202 | 17d4.18f8: LastWriteTime: 2015-07-10T11:00:10.325689700Z
|
|---|
| 203 | 17d4.18f8: ChangeTime: 2015-10-13T23:39:05.865323100Z
|
|---|
| 204 | 17d4.18f8: FileAttributes: 0x20
|
|---|
| 205 | 17d4.18f8: Size: 0x1dc680
|
|---|
| 206 | 17d4.18f8: NT Headers: 0x100
|
|---|
| 207 | 17d4.18f8: Timestamp: 0x559f38c3
|
|---|
| 208 | 17d4.18f8: Machine: 0x8664 - amd64
|
|---|
| 209 | 17d4.18f8: Timestamp: 0x559f38c3
|
|---|
| 210 | 17d4.18f8: Image Version: 10.0
|
|---|
| 211 | 17d4.18f8: SizeOfImage: 0x1dd000 (1953792)
|
|---|
| 212 | 17d4.18f8: Resource Dir: 0x1c7000 LB 0x530
|
|---|
| 213 | 17d4.18f8: ProductName: Microsoft® Windows® Operating System
|
|---|
| 214 | 17d4.18f8: ProductVersion: 10.0.10240.16384
|
|---|
| 215 | 17d4.18f8: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 216 | 17d4.18f8: FileDescription: Windows NT BASE API Client DLL
|
|---|
| 217 | 17d4.18f8: \SystemRoot\System32\apisetschema.dll:
|
|---|
| 218 | 17d4.18f8: CreationTime: 2015-07-10T11:00:04.872098600Z
|
|---|
| 219 | 17d4.18f8: LastWriteTime: 2015-07-10T11:00:04.872098600Z
|
|---|
| 220 | 17d4.18f8: ChangeTime: 2015-08-21T03:35:07.893781700Z
|
|---|
| 221 | 17d4.18f8: FileAttributes: 0x20
|
|---|
| 222 | 17d4.18f8: Size: 0x16760
|
|---|
| 223 | 17d4.18f8: NT Headers: 0xc8
|
|---|
| 224 | 17d4.18f8: Timestamp: 0x559f3e3d
|
|---|
| 225 | 17d4.18f8: Machine: 0x8664 - amd64
|
|---|
| 226 | 17d4.18f8: Timestamp: 0x559f3e3d
|
|---|
| 227 | 17d4.18f8: Image Version: 10.0
|
|---|
| 228 | 17d4.18f8: SizeOfImage: 0x17000 (94208)
|
|---|
| 229 | 17d4.18f8: Resource Dir: 0x16000 LB 0x3f0
|
|---|
| 230 | 17d4.18f8: ProductName: Microsoft® Windows® Operating System
|
|---|
| 231 | 17d4.18f8: ProductVersion: 10.0.10240.16384
|
|---|
| 232 | 17d4.18f8: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 233 | 17d4.18f8: FileDescription: ApiSet Schema DLL
|
|---|
| 234 | 17d4.18f8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
|
|---|
| 235 | 17d4.18f8: supR3HardenedWinFindAdversaries: 0x0
|
|---|
| 236 | 17d4.18f8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 237 | 17d4.18f8: Calling main()
|
|---|
| 238 | 17d4.18f8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
|
|---|
| 239 | 17d4.18f8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 240 | 17d4.18f8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 241 | 17d4.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
|
|---|
| 242 | 17d4.18f8: SUPR3HardenedMain: Respawn #2
|
|---|
| 243 | 17d4.18f8: supR3HardNtEnableThreadCreation:
|
|---|
| 244 | 17d4.18f8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffad453fb70 pvNtTerminateThread=00007ffad4563a20
|
|---|
| 245 | 17d4.18f8: supR3HardenedWinDoReSpawn(2): New child 130c.1f0c [kernel32].
|
|---|
| 246 | 17d4.18f8: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
|
|---|
| 247 | 17d4.18f8: supR3HardNtChildGatherData: PebBaseAddress=00007ff674633000 cbPeb=0x388
|
|---|
| 248 | 17d4.18f8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffad44d0000 uNtDllChildAddr=00007ffad44d0000
|
|---|
| 249 | 17d4.18f8: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffad453fb70
|
|---|
| 250 | 17d4.18f8: supR3HardenedWinSetupChildInit: Start child.
|
|---|
| 251 | 17d4.18f8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
|
|---|
| 252 | 17d4.18f8: supR3HardNtChildPurify: Startup delay kludge #1/0: 263 ms, 22 sleeps
|
|---|
| 253 | 17d4.18f8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
|
|---|
| 254 | 17d4.18f8: *0000000000000000-ffffffffff7dffff 0x0001/0x0000 0x0000000
|
|---|
| 255 | 17d4.18f8: *0000000000820000-00000000007fffff 0x0004/0x0004 0x0020000
|
|---|
| 256 | 17d4.18f8: *0000000000840000-000000000082bfff 0x0002/0x0002 0x0040000
|
|---|
| 257 | 17d4.18f8: 0000000000854000-0000000000847fff 0x0001/0x0000 0x0000000
|
|---|
| 258 | 17d4.18f8: *0000000000860000-0000000000763fff 0x0000/0x0004 0x0020000
|
|---|
| 259 | 17d4.18f8: 000000000095c000-0000000000958fff 0x0104/0x0004 0x0020000
|
|---|
| 260 | 17d4.18f8: 000000000095f000-000000000095dfff 0x0004/0x0004 0x0020000
|
|---|
| 261 | 17d4.18f8: *0000000000960000-000000000095bfff 0x0002/0x0002 0x0040000
|
|---|
| 262 | 17d4.18f8: 0000000000964000-0000000000957fff 0x0001/0x0000 0x0000000
|
|---|
| 263 | 17d4.18f8: *0000000000970000-000000000096dfff 0x0004/0x0004 0x0020000
|
|---|
| 264 | 17d4.18f8: 0000000000972000-ffffffff81303fff 0x0001/0x0000 0x0000000
|
|---|
| 265 | 17d4.18f8: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
|
|---|
| 266 | 17d4.18f8: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
|
|---|
| 267 | 17d4.18f8: 000000007fff0000-ffff800a8b9cffff 0x0001/0x0000 0x0000000
|
|---|
| 268 | 17d4.18f8: *00007ff674610000-00007ff6745ecfff 0x0002/0x0002 0x0040000
|
|---|
| 269 | 17d4.18f8: *00007ff674633000-00007ff674631fff 0x0004/0x0004 0x0020000
|
|---|
| 270 | 17d4.18f8: 00007ff674634000-00007ff674629fff 0x0001/0x0000 0x0000000
|
|---|
| 271 | 17d4.18f8: *00007ff67463e000-00007ff67463bfff 0x0004/0x0004 0x0020000
|
|---|
| 272 | 17d4.18f8: 00007ff674640000-00007ff67369ffff 0x0001/0x0000 0x0000000
|
|---|
| 273 | 17d4.18f8: *00007ff6755e0000-00007ff6755e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 274 | 17d4.18f8: 00007ff6755e1000-00007ff675667fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 275 | 17d4.18f8: 00007ff675668000-00007ff675668fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 276 | 17d4.18f8: 00007ff675669000-00007ff6756b3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 277 | 17d4.18f8: 00007ff6756b4000-00007ff6756b4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 278 | 17d4.18f8: 00007ff6756b5000-00007ff6756b5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 279 | 17d4.18f8: 00007ff6756b6000-00007ff6756bafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 280 | 17d4.18f8: 00007ff6756bb000-00007ff6756bbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 281 | 17d4.18f8: 00007ff6756bc000-00007ff6756bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 282 | 17d4.18f8: 00007ff6756bd000-00007ff6756c0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 283 | 17d4.18f8: 00007ff6756c1000-00007ff67570bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 284 | 17d4.18f8: 00007ff67570c000-00007ff216947fff 0x0001/0x0000 0x0000000
|
|---|
| 285 | 17d4.18f8: *00007ffad44d0000-00007ffad44d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 286 | 17d4.18f8: 00007ffad44d1000-00007ffad45ccfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 287 | 17d4.18f8: 00007ffad45cd000-00007ffad460efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 288 | 17d4.18f8: 00007ffad460f000-00007ffad4617fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 289 | 17d4.18f8: 00007ffad4618000-00007ffad4625fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 290 | 17d4.18f8: 00007ffad4626000-00007ffad4626fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 291 | 17d4.18f8: 00007ffad4627000-00007ffad4629fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 292 | 17d4.18f8: 00007ffad462a000-00007ffad4690fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
|
|---|
| 293 | 17d4.18f8: 00007ffad4691000-00007ff5a8d41fff 0x0001/0x0000 0x0000000
|
|---|
| 294 | 17d4.18f8: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
|
|---|
| 295 | 17d4.18f8: VirtualBox.exe: timestamp 0x561faefe (rc=VINF_SUCCESS)
|
|---|
| 296 | 17d4.18f8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 297 | 17d4.18f8: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
|
|---|
| 298 | 17d4.18f8: supR3HardNtChildPurify: Done after 295 ms and 0 fixes (loop #0).
|
|---|
| 299 | 130c.1f0c: Log file opened: 5.0.8r103449 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0280000
|
|---|
| 300 | 130c.1f0c: supR3HardenedVmProcessInit: uNtDllAddr=00007ffad44d0000
|
|---|
| 301 | 17d4.18f8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001250000 LB 0x400000)
|
|---|
| 302 | 130c.1f0c: ntdll.dll: timestamp 0x55c59f92 (rc=VINF_SUCCESS)
|
|---|
| 303 | 130c.1f0c: New simple heap: #1 0000000000a80000 LB 0x400000 (for 1839104 allocation)
|
|---|
| 304 | 17d4.18f8: supR3HardNtEnableThreadCreation:
|
|---|
| 305 | 130c.1f0c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 306 | 130c.1f0c: System32: \Device\HarddiskVolume4\Windows\System32
|
|---|
| 307 | 130c.1f0c: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
|
|---|
| 308 | 130c.1f0c: KnownDllPath: C:\Windows\system32
|
|---|
| 309 | 130c.1f0c: supR3HardenedVmProcessInit: Opening vboxdrv...
|
|---|
| 310 | 130c.1f0c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
|
|---|
| 311 | 130c.1f0c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
|
|---|
| 312 | 130c.1f0c: Registered Dll notification callback with NTDLL.
|
|---|
| 313 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
|
|---|
| 314 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
|
|---|
| 315 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
|
|---|
| 316 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1900000 LB 0x001dd000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
|
|---|
| 317 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
|
|---|
| 318 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
|
|---|
| 319 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad4420000 LB 0x000ad000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]
|
|---|
| 320 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
|
|---|
| 321 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4420000 'C:\Windows\system32\KERNEL32.DLL'
|
|---|
| 322 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ff6755e0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
|
|---|
| 323 | 130c.1f0c: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 324 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
|
|---|
| 325 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 326 | 130c.1f0c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffad453fb70 pvNtTerminateThread=00007ffad4563a20
|
|---|
| 327 | 17d4.18f8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 80 ms.
|
|---|
| 328 | 130c.1f0c: \SystemRoot\System32\ntdll.dll:
|
|---|
| 329 | 130c.1f0c: CreationTime: 2015-08-20T23:20:59.070821600Z
|
|---|
| 330 | 130c.1f0c: LastWriteTime: 2015-08-08T07:29:58.168349600Z
|
|---|
| 331 | 130c.1f0c: ChangeTime: 2015-08-21T10:30:50.420447700Z
|
|---|
| 332 | 130c.1f0c: FileAttributes: 0x20
|
|---|
| 333 | 130c.1f0c: Size: 0x1bce48
|
|---|
| 334 | 130c.1f0c: NT Headers: 0xd8
|
|---|
| 335 | 130c.1f0c: Timestamp: 0x55c59f92
|
|---|
| 336 | 130c.1f0c: Machine: 0x8664 - amd64
|
|---|
| 337 | 130c.1f0c: Timestamp: 0x55c59f92
|
|---|
| 338 | 130c.1f0c: Image Version: 10.0
|
|---|
| 339 | 130c.1f0c: SizeOfImage: 0x1c1000 (1839104)
|
|---|
| 340 | 130c.1f0c: Resource Dir: 0x15a000 LB 0x65718
|
|---|
| 341 | 130c.1f0c: ProductName: Microsoft® Windows® Operating System
|
|---|
| 342 | 130c.1f0c: ProductVersion: 10.0.10240.16430
|
|---|
| 343 | 130c.1f0c: FileVersion: 10.0.10240.16430 (th1.150807-2049)
|
|---|
| 344 | 130c.1f0c: FileDescription: NT Layer DLL
|
|---|
| 345 | 130c.1f0c: \SystemRoot\System32\kernel32.dll:
|
|---|
| 346 | 130c.1f0c: CreationTime: 2015-07-10T10:59:59.699781600Z
|
|---|
| 347 | 130c.1f0c: LastWriteTime: 2015-07-10T10:59:59.699781600Z
|
|---|
| 348 | 130c.1f0c: ChangeTime: 2015-10-13T23:39:05.537198800Z
|
|---|
| 349 | 130c.1f0c: FileAttributes: 0x20
|
|---|
| 350 | 130c.1f0c: Size: 0xab830
|
|---|
| 351 | 130c.1f0c: NT Headers: 0xf0
|
|---|
| 352 | 130c.1f0c: Timestamp: 0x559f38ad
|
|---|
| 353 | 130c.1f0c: Machine: 0x8664 - amd64
|
|---|
| 354 | 130c.1f0c: Timestamp: 0x559f38ad
|
|---|
| 355 | 130c.1f0c: Image Version: 10.0
|
|---|
| 356 | 130c.1f0c: SizeOfImage: 0xad000 (708608)
|
|---|
| 357 | 130c.1f0c: Resource Dir: 0xab000 LB 0x518
|
|---|
| 358 | 130c.1f0c: ProductName: Microsoft® Windows® Operating System
|
|---|
| 359 | 130c.1f0c: ProductVersion: 10.0.10240.16384
|
|---|
| 360 | 130c.1f0c: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 361 | 130c.1f0c: FileDescription: Windows NT BASE API Client DLL
|
|---|
| 362 | 130c.1f0c: \SystemRoot\System32\KernelBase.dll:
|
|---|
| 363 | 130c.1f0c: CreationTime: 2015-07-10T11:00:10.325689700Z
|
|---|
| 364 | 130c.1f0c: LastWriteTime: 2015-07-10T11:00:10.325689700Z
|
|---|
| 365 | 130c.1f0c: ChangeTime: 2015-10-13T23:39:05.865323100Z
|
|---|
| 366 | 130c.1f0c: FileAttributes: 0x20
|
|---|
| 367 | 130c.1f0c: Size: 0x1dc680
|
|---|
| 368 | 130c.1f0c: NT Headers: 0x100
|
|---|
| 369 | 130c.1f0c: Timestamp: 0x559f38c3
|
|---|
| 370 | 130c.1f0c: Machine: 0x8664 - amd64
|
|---|
| 371 | 130c.1f0c: Timestamp: 0x559f38c3
|
|---|
| 372 | 130c.1f0c: Image Version: 10.0
|
|---|
| 373 | 130c.1f0c: SizeOfImage: 0x1dd000 (1953792)
|
|---|
| 374 | 130c.1f0c: Resource Dir: 0x1c7000 LB 0x530
|
|---|
| 375 | 130c.1f0c: ProductName: Microsoft® Windows® Operating System
|
|---|
| 376 | 130c.1f0c: ProductVersion: 10.0.10240.16384
|
|---|
| 377 | 130c.1f0c: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 378 | 130c.1f0c: FileDescription: Windows NT BASE API Client DLL
|
|---|
| 379 | 130c.1f0c: \SystemRoot\System32\apisetschema.dll:
|
|---|
| 380 | 130c.1f0c: CreationTime: 2015-07-10T11:00:04.872098600Z
|
|---|
| 381 | 130c.1f0c: LastWriteTime: 2015-07-10T11:00:04.872098600Z
|
|---|
| 382 | 130c.1f0c: ChangeTime: 2015-08-21T03:35:07.893781700Z
|
|---|
| 383 | 130c.1f0c: FileAttributes: 0x20
|
|---|
| 384 | 130c.1f0c: Size: 0x16760
|
|---|
| 385 | 130c.1f0c: NT Headers: 0xc8
|
|---|
| 386 | 130c.1f0c: Timestamp: 0x559f3e3d
|
|---|
| 387 | 130c.1f0c: Machine: 0x8664 - amd64
|
|---|
| 388 | 130c.1f0c: Timestamp: 0x559f3e3d
|
|---|
| 389 | 130c.1f0c: Image Version: 10.0
|
|---|
| 390 | 130c.1f0c: SizeOfImage: 0x17000 (94208)
|
|---|
| 391 | 130c.1f0c: Resource Dir: 0x16000 LB 0x3f0
|
|---|
| 392 | 130c.1f0c: ProductName: Microsoft® Windows® Operating System
|
|---|
| 393 | 130c.1f0c: ProductVersion: 10.0.10240.16384
|
|---|
| 394 | 130c.1f0c: FileVersion: 10.0.10240.16384 (th1.150709-1700)
|
|---|
| 395 | 130c.1f0c: FileDescription: ApiSet Schema DLL
|
|---|
| 396 | 130c.1f0c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
|
|---|
| 397 | 130c.1f0c: supR3HardenedWinFindAdversaries: 0x0
|
|---|
| 398 | 130c.1f0c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 399 | 130c.1f0c: Calling main()
|
|---|
| 400 | 130c.1f0c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
|
|---|
| 401 | 130c.1f0c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
|
|---|
| 402 | 130c.1f0c: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
|
|---|
| 403 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
|
|---|
| 404 | 130c.1f0c: SUPR3HardenedMain: Final process, opening VBoxDrv...
|
|---|
| 405 | 130c.1f0c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000a80000 LB 0x400000)
|
|---|
| 406 | 130c.1f0c: supR3HardNtEnableThreadCreation:
|
|---|
| 407 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
|
|---|
| 408 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
|
|---|
| 409 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
|
|---|
| 410 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
|
|---|
| 411 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac91f0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
|
|---|
| 412 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
|
|---|
| 413 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
|
|---|
| 414 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 415 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac91f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
|
|---|
| 416 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
|
|---|
| 417 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 418 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac91f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
|
|---|
| 419 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac91f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
|
|---|
| 420 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 421 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
|
|---|
| 422 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
|
|---|
| 423 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
|
|---|
| 424 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
|
|---|
| 425 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
|
|---|
| 426 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 427 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 428 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
|
|---|
| 429 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
|
|---|
| 430 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
|
|---|
| 431 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 432 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 433 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msasn1.dll'.
|
|---|
| 434 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
|
|---|
| 435 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
|
|---|
| 436 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
|
|---|
| 437 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
|
|---|
| 438 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
|
|---|
| 439 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
|
|---|
| 440 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 441 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 442 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
|
|---|
| 443 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
|
|---|
| 444 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
|
|---|
| 445 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
|
|---|
| 446 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
|
|---|
| 447 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 448 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 449 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 450 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
|
|---|
| 451 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3cb0000 LB 0x0009d000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
|
|---|
| 452 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 453 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0f50000 LB 0x00011000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
|
|---|
| 454 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
|
|---|
| 455 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1000000 LB 0x001c1000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
|
|---|
| 456 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
|
|---|
| 457 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad4000000 LB 0x00126000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
|
|---|
| 458 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
|
|---|
| 459 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0fa0000 LB 0x00054000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
|
|---|
| 460 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 461 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\system32\Wintrust.dll'
|
|---|
| 462 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
|
|---|
| 463 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
|
|---|
| 464 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
|
|---|
| 465 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
|
|---|
| 466 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0e30000 LB 0x00028000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
|
|---|
| 467 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
|
|---|
| 468 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0e30000 'C:\Windows\system32\bcrypt.dll'
|
|---|
| 469 | 130c.1f0c: bcrypt.dll loaded at 00007ffad0e30000, BCryptOpenAlgorithmProvider at 00007ffad0e34a00, preloading providers:
|
|---|
| 470 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
|
|---|
| 471 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
|
|---|
| 472 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 473 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
|
|---|
| 474 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0cc0000 LB 0x0006b000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
|
|---|
| 475 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
|
|---|
| 476 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0cc0000 'C:\Windows\system32\bcryptprimitives.dll'
|
|---|
| 477 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000000e8a730)
|
|---|
| 478 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000000e8adf0)
|
|---|
| 479 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000000e8b0c0)
|
|---|
| 480 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000000e8b420)
|
|---|
| 481 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000000e8bf40)
|
|---|
| 482 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000000e8c250)
|
|---|
| 483 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000000e8c560)
|
|---|
| 484 | 130c.1f0c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000e8c830)
|
|---|
| 485 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 486 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 487 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 488 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 489 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 490 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 491 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 492 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 493 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 494 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 495 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 496 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 497 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 498 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 499 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 500 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 501 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 502 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 503 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 504 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 505 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 506 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'.
|
|---|
| 507 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
|
|---|
| 508 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
|
|---|
| 509 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0460000 LB 0x00017000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
|
|---|
| 510 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
|
|---|
| 511 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'bcrypt.dll'.
|
|---|
| 512 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
|
|---|
| 513 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
|
|---|
| 514 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
|
|---|
| 515 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 516 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
|
|---|
| 517 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
|
|---|
| 518 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 519 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
|
|---|
| 520 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 521 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 522 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad00b0000 LB 0x00033000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
|
|---|
| 523 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 524 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 525 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
|
|---|
| 526 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
|
|---|
| 527 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
|
|---|
| 528 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad05d0000 LB 0x0000b000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
|
|---|
| 529 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
|
|---|
| 530 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
|
|---|
| 531 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
|
|---|
| 532 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
|
|---|
| 533 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
|
|---|
| 534 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 535 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4420000 'C:\Windows\system32\kernel32.dll'
|
|---|
| 536 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 537 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 538 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
|
|---|
| 539 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 540 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\CRYPT32.dll'
|
|---|
| 541 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3400000 LB 0x0001c000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
|
|---|
| 542 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 543 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
|
|---|
| 544 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
|
|---|
| 545 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 546 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 547 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 548 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 549 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 550 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 551 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad31f0000 LB 0x0005b000 C:\Windows\system32\sechost.dll [fFlags=0x0]
|
|---|
| 552 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
|
|---|
| 553 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
|
|---|
| 554 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
|
|---|
| 555 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 556 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
|
|---|
| 557 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
|
|---|
| 558 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
|
|---|
| 559 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacf520000 LB 0x00023000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
|
|---|
| 560 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
|
|---|
| 561 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0f80000 LB 0x00013000 C:\Windows\system32\profapi.dll [fFlags=0x0]
|
|---|
| 562 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
|
|---|
| 563 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
|
|---|
| 564 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 565 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
|
|---|
| 566 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'wldap32.dll'.
|
|---|
| 567 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
|
|---|
| 568 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
|
|---|
| 569 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
|
|---|
| 570 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume4\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 571 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 572 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\Wldap32.dll)
|
|---|
| 573 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\Wldap32.dll
|
|---|
| 574 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
|
|---|
| 575 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 576 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
|
|---|
| 577 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 578 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 579 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 580 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 581 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 582 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
|
|---|
| 583 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 584 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 585 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 586 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 587 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 588 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
|
|---|
| 589 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 590 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 591 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 592 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 593 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 594 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1bb0000 LB 0x0005b000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
|
|---|
| 595 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
|
|---|
| 596 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac2630000 LB 0x0002f000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
|
|---|
| 597 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 598 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 599 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 600 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 601 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 602 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 603 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 604 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 605 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 606 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 607 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 608 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 609 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 610 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 611 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 612 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 613 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 614 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 615 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 616 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 617 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 618 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 619 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 620 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 621 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 622 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 623 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 624 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 625 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 626 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\system32\cryptnet.dll'
|
|---|
| 627 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
|
|---|
| 628 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2630000 'C:\Windows\System32\cryptnet.dll'
|
|---|
| 629 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad37d0000 LB 0x000a6000 C:\Windows\system32\advapi32.dll [fFlags=0x0]
|
|---|
| 630 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 631 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'.
|
|---|
| 632 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'rpcrt4.dll'.
|
|---|
| 633 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
|
|---|
| 634 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 635 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 636 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 637 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 638 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
|
|---|
| 639 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
|
|---|
| 640 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
|
|---|
| 641 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
|
|---|
| 642 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 643 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 644 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
|
|---|
| 645 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 646 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 647 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
|
|---|
| 648 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 649 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 650 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
|
|---|
| 651 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000ec0cc0
|
|---|
| 652 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 653 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=311B4CDD9B998ED36E8EA94DCB004D809301CC36
|
|---|
| 654 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
|
|---|
| 655 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 656 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4000000 'C:\Windows\system32\rpcrt4.dll'
|
|---|
| 657 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 658 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 659 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 660 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 661 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 662 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 663 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 664 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 665 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 666 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 667 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 668 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 669 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
|
|---|
| 670 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 671 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\System32\WINTRUST.DLL'
|
|---|
| 672 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 673 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 674 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 675 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
|
|---|
| 676 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 677 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 678 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_555_for_KB3081455~31bf3856ad364e35~amd64~~10.0.1.3.cat'; file='\SystemRoot\System32\ntdll.dll'
|
|---|
| 679 | 130c.1f0c: g_pfnWinVerifyTrust=00007ffad0fa8890
|
|---|
| 680 | 130c.1f0c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
|
|---|
| 681 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 682 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 683 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 684 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
|
|---|
| 685 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 686 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 687 | 130c.1f0c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
|
|---|
| 688 | 130c.1f0c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
|
|---|
| 689 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 690 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 691 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 692 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
|
|---|
| 693 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 694 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 695 | 130c.1f0c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
|
|---|
| 696 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 697 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 698 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 699 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 700 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
|
|---|
| 701 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000374 pwszName=\Device\HarddiskVolume4\Windows\System32\Wldap32.dll
|
|---|
| 702 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 703 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 704 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3E30C00BB3189B639214835B4F4C320DEC5BFA77
|
|---|
| 705 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 706 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 707 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 708 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
|
|---|
| 709 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 710 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
|
|---|
| 711 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000370 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
|
|---|
| 712 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 713 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 714 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5997BB270A09A76A71A9EE8A7ADB154F3D75EEF3
|
|---|
| 715 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 716 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 717 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 718 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
|
|---|
| 719 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 720 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
|
|---|
| 721 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 722 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 723 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 724 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
|
|---|
| 725 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 726 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 727 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 728 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
|
|---|
| 729 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 730 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 731 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 732 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
|
|---|
| 733 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 734 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 735 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 736 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
|
|---|
| 737 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 738 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 739 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
|
|---|
| 740 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 741 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 742 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
|
|---|
| 743 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
|
|---|
| 744 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 745 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 746 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 747 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
|
|---|
| 748 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 749 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 750 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
|
|---|
| 751 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 752 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 753 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
|
|---|
| 754 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 755 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 756 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
|
|---|
| 757 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 758 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 759 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
|
|---|
| 760 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 761 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 762 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
|
|---|
| 763 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 764 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 765 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
|
|---|
| 766 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 767 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
|
|---|
| 768 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 769 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe'
|
|---|
| 770 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 771 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 772 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
|
|---|
| 773 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 774 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 775 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
|
|---|
| 776 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 777 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
|
|---|
| 778 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
|
|---|
| 779 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
|
|---|
| 780 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
|
|---|
| 781 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
|
|---|
| 782 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
|
|---|
| 783 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x6fae3debd474d000 CN=ZackWorkWin10
|
|---|
| 784 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
|
|---|
| 785 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: skipping - not-self-signed: C=US, ST=Washington, L=Renton, O=Parallels, Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, CN=Parallels, Inc.
|
|---|
| 786 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xcd5e8f6875d9ad00 CN=DESKTOP-C0JAJ7K
|
|---|
| 787 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
|
|---|
| 788 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
|
|---|
| 789 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
|
|---|
| 790 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
|
|---|
| 791 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
|
|---|
| 792 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
|
|---|
| 793 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
|
|---|
| 794 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
|
|---|
| 795 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
|
|---|
| 796 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
|
|---|
| 797 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
|
|---|
| 798 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
|
|---|
| 799 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
|
|---|
| 800 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
|
|---|
| 801 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
|
|---|
| 802 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
|
|---|
| 803 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
|
|---|
| 804 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
|
|---|
| 805 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
|
|---|
| 806 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
|
|---|
| 807 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
|
|---|
| 808 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
|
|---|
| 809 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
|
|---|
| 810 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
|
|---|
| 811 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
|
|---|
| 812 | 130c.1f0c: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
|
|---|
| 813 | 130c.1f0c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=35
|
|---|
| 814 | 130c.1f0c: SUPR3HardenedMain: Load Runtime...
|
|---|
| 815 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 816 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 817 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
|
|---|
| 818 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
|
|---|
| 819 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
|
|---|
| 820 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
|
|---|
| 821 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 822 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 823 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 824 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
|
|---|
| 825 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 826 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 827 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 828 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 829 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'nsi.dll'.
|
|---|
| 830 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
|
|---|
| 831 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ws2_32.dll) WinVerifyTrust
|
|---|
| 832 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 833 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 834 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 835 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 836 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 837 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
|
|---|
| 838 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
|
|---|
| 839 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 840 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
|
|---|
| 841 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\nsi.dll)
|
|---|
| 842 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\nsi.dll
|
|---|
| 843 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 844 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 845 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
|
|---|
| 846 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 847 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 848 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 849 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 850 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 851 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
|
|---|
| 852 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)
|
|---|
| 853 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
|
|---|
| 854 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 855 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
|
|---|
| 856 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
|
|---|
| 857 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 858 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
|
|---|
| 859 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 860 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 0000000069750000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
|
|---|
| 861 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
|
|---|
| 862 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00000000696b0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
|
|---|
| 863 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 864 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1ba0000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
|
|---|
| 865 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
|
|---|
| 866 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad4130000 LB 0x00069000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
|
|---|
| 867 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 868 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffaa5090000 LB 0x0055f000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
|
|---|
| 869 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 870 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
|
|---|
| 871 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
|
|---|
| 872 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
|
|---|
| 873 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rescheduled]
|
|---|
| 874 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 875 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 876 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 877 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 878 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 879 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 880 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 881 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 882 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 883 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 884 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 885 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 886 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 887 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 888 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 889 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 890 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 891 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 892 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 893 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 894 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 895 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 896 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 897 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 898 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 899 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 900 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 901 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 902 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 903 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 904 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 905 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 906 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 907 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 908 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 909 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 910 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 911 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 912 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 913 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 914 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 915 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 916 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 917 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 918 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 919 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 920 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 921 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 922 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5090000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
|
|---|
| 923 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad0fa0000 'C:\Windows\system32\Wintrust.dll'
|
|---|
| 924 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 925 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 926 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
|
|---|
| 927 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 928 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 929 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 930 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 931 | 130c.1f0c: SUPR3HardenedMain: Load TrustedMain...
|
|---|
| 932 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 933 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
|
|---|
| 934 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
|
|---|
| 935 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
|
|---|
| 936 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
|
|---|
| 937 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
|
|---|
| 938 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
|
|---|
| 939 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
|
|---|
| 940 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
|
|---|
| 941 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
|
|---|
| 942 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
|
|---|
| 943 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
|
|---|
| 944 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
|
|---|
| 945 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
|
|---|
| 946 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
|
|---|
| 947 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
|
|---|
| 948 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
|
|---|
| 949 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
|
|---|
| 950 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
|
|---|
| 951 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
|
|---|
| 952 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 953 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 954 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 955 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
|
|---|
| 956 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
|
|---|
| 957 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'user32.dll'.
|
|---|
| 958 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmm.dll) WinVerifyTrust
|
|---|
| 959 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 960 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
|
|---|
| 961 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 962 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000484 pwszName=\Device\HarddiskVolume4\Windows\System32\comdlg32.dll
|
|---|
| 963 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 964 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 965 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=857477BEC0F0F69A9C4898B3680E207E94733C3F
|
|---|
| 966 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 967 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 968 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
|
|---|
| 969 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'gdi32.dll'.
|
|---|
| 970 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll)
|
|---|
| 971 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\user32.dll
|
|---|
| 972 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 973 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 974 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
|
|---|
| 975 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
|
|---|
| 976 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 977 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
|
|---|
| 978 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
|
|---|
| 979 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'devobj.dll'.
|
|---|
| 980 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmmbase.dll)
|
|---|
| 981 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmmbase.dll
|
|---|
| 982 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
|
|---|
| 983 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
|
|---|
| 984 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
|
|---|
| 985 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 986 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'cfgmgr32.dll'.
|
|---|
| 987 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\devobj.dll)
|
|---|
| 988 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devobj.dll
|
|---|
| 989 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 990 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 991 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 992 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 993 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
|
|---|
| 994 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
|
|---|
| 995 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32.dll)
|
|---|
| 996 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32.dll
|
|---|
| 997 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 998 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 999 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
|
|---|
| 1000 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
|
|---|
| 1001 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1002 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
|
|---|
| 1003 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll)
|
|---|
| 1004 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll
|
|---|
| 1005 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1006 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1007 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1008 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
|
|---|
| 1009 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1010 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1011 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_329_for_KB3081444~31bf3856ad364e35~amd64~~10.0.1.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\comdlg32.dll'
|
|---|
| 1012 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 1013 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1014 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'user32.dll'.
|
|---|
| 1015 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'shlwapi.dll'.
|
|---|
| 1016 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'gdi32.dll'.
|
|---|
| 1017 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'comctl32.dll'.
|
|---|
| 1018 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'shell32.dll'.
|
|---|
| 1019 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\comdlg32.dll) WinVerifyTrust
|
|---|
| 1020 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
|
|---|
| 1021 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 1022 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1023 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
|
|---|
| 1024 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1025 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
|
|---|
| 1026 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1027 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #64 'user32.dll'.
|
|---|
| 1028 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #66 'gdi32.dll'.
|
|---|
| 1029 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shell32.dll)
|
|---|
| 1030 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1031 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
|
|---|
| 1032 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
|
|---|
| 1033 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
|
|---|
| 1034 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
|
|---|
| 1035 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
|
|---|
| 1036 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
|
|---|
| 1037 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\comctl32.dll)
|
|---|
| 1038 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comctl32.dll
|
|---|
| 1039 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1040 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1041 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
|
|---|
| 1042 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
|
|---|
| 1043 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1044 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
|
|---|
| 1045 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
|
|---|
| 1046 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'gdi32.dll'.
|
|---|
| 1047 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'user32.dll'.
|
|---|
| 1048 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shlwapi.dll)
|
|---|
| 1049 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
|
|---|
| 1050 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1051 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1052 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
|
|---|
| 1053 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1054 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1055 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1056 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1057 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
|
|---|
| 1058 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1059 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1060 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
|
|---|
| 1061 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1062 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1063 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1064 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1065 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
|
|---|
| 1066 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1067 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1068 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
|
|---|
| 1069 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1070 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1071 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1072 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1073 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1074 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
|
|---|
| 1075 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1076 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1077 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
|
|---|
| 1078 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1079 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1080 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1081 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1082 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1083 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
|
|---|
| 1084 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
|
|---|
| 1085 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleaut32.dll) WinVerifyTrust
|
|---|
| 1086 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1087 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 1088 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1089 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1090 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1091 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
|
|---|
| 1092 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 1093 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1094 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
|
|---|
| 1095 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1096 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
|
|---|
| 1097 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\combase.dll)
|
|---|
| 1098 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\combase.dll
|
|---|
| 1099 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1100 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1101 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1102 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1103 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1104 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1105 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1106 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1107 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
|
|---|
| 1108 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
|
|---|
| 1109 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'gdi32.dll'.
|
|---|
| 1110 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'user32.dll'.
|
|---|
| 1111 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'combase.dll'.
|
|---|
| 1112 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ole32.dll) WinVerifyTrust
|
|---|
| 1113 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 1114 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
|
|---|
| 1115 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1116 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [redoing WinVerifyTrust]
|
|---|
| 1117 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 1118 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1119 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
|
|---|
| 1120 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1121 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1122 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
|
|---|
| 1123 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1124 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1125 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
|
|---|
| 1126 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1127 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1128 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1129 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1130 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
|
|---|
| 1131 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1132 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1133 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll'
|
|---|
| 1134 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1135 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1136 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1137 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1138 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1139 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
|
|---|
| 1140 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1141 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1142 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'
|
|---|
| 1143 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1144 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1145 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
|
|---|
| 1146 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1147 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1148 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\user32.dll'
|
|---|
| 1149 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
|
|---|
| 1150 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1151 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1152 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
|
|---|
| 1153 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
|
|---|
| 1154 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
|
|---|
| 1155 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
|
|---|
| 1156 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
|
|---|
| 1157 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
|
|---|
| 1158 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
|
|---|
| 1159 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
|
|---|
| 1160 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
|
|---|
| 1161 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1162 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 1163 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1164 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
|
|---|
| 1165 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
|
|---|
| 1166 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1167 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'.
|
|---|
| 1168 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
|
|---|
| 1169 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
|
|---|
| 1170 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
|
|---|
| 1171 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
|
|---|
| 1172 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
|
|---|
| 1173 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
|
|---|
| 1174 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)
|
|---|
| 1175 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
|
|---|
| 1176 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
|
|---|
| 1177 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1178 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'.
|
|---|
| 1179 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
|
|---|
| 1180 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
|
|---|
| 1181 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
|
|---|
| 1182 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
|
|---|
| 1183 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
|
|---|
| 1184 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
|
|---|
| 1185 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
|
|---|
| 1186 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
|
|---|
| 1187 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
|
|---|
| 1188 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
|
|---|
| 1189 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
|
|---|
| 1190 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
|
|---|
| 1191 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
|
|---|
| 1192 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)
|
|---|
| 1193 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
|
|---|
| 1194 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1195 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1196 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
|
|---|
| 1197 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1198 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1199 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
|
|---|
| 1200 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
|
|---|
| 1201 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1202 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'.
|
|---|
| 1203 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1204 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
|
|---|
| 1205 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
|
|---|
| 1206 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
|
|---|
| 1207 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
|
|---|
| 1208 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
|
|---|
| 1209 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\opengl32.dll)
|
|---|
| 1210 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\opengl32.dll
|
|---|
| 1211 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1212 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1213 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
|
|---|
| 1214 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1215 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
|
|---|
| 1216 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1217 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'user32.dll'.
|
|---|
| 1218 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'gdi32.dll'.
|
|---|
| 1219 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'dciman32.dll'.
|
|---|
| 1220 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\ddraw.dll)
|
|---|
| 1221 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ddraw.dll
|
|---|
| 1222 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
|
|---|
| 1223 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1224 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
|
|---|
| 1225 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1226 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
|
|---|
| 1227 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
|
|---|
| 1228 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\glu32.dll)
|
|---|
| 1229 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\glu32.dll
|
|---|
| 1230 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1231 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1232 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
|
|---|
| 1233 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1234 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1235 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1236 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1237 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1238 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 1239 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1240 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
|
|---|
| 1241 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 1242 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1243 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 1244 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
|
|---|
| 1245 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1246 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
|
|---|
| 1247 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
|
|---|
| 1248 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1249 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1250 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1251 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1252 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1253 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1254 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1255 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 1256 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1257 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 1258 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
|
|---|
| 1259 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
|
|---|
| 1260 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
|
|---|
| 1261 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1262 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'bcrypt.dll'.
|
|---|
| 1263 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\winspool.drv)
|
|---|
| 1264 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winspool.drv
|
|---|
| 1265 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
|
|---|
| 1266 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1267 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 1268 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
|
|---|
| 1269 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1270 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
|
|---|
| 1271 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
|
|---|
| 1272 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'msctf.dll'.
|
|---|
| 1273 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imm32.dll)
|
|---|
| 1274 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imm32.dll
|
|---|
| 1275 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 1276 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1277 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1278 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
|
|---|
| 1279 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1280 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
|
|---|
| 1281 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1282 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1283 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 1284 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1285 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
|
|---|
| 1286 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 1287 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1288 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 1289 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 1290 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1291 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 1292 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1293 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1294 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1295 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 1296 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1297 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 1298 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1299 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1300 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
|
|---|
| 1301 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1302 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
|
|---|
| 1303 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1304 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
|
|---|
| 1305 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
|
|---|
| 1306 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'imm32.dll'.
|
|---|
| 1307 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msctf.dll)
|
|---|
| 1308 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msctf.dll
|
|---|
| 1309 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1310 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1311 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
|
|---|
| 1312 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1313 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
|
|---|
| 1314 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1315 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1316 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1317 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1318 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
|
|---|
| 1319 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1320 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
|
|---|
| 1321 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1322 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1323 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
|
|---|
| 1324 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1325 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
|
|---|
| 1326 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1327 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
|
|---|
| 1328 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
|
|---|
| 1329 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dciman32.dll)
|
|---|
| 1330 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dciman32.dll
|
|---|
| 1331 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1332 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1333 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1334 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1335 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1336 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1337 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1338 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1339 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1340 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1341 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1342 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1343 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
|
|---|
| 1344 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1345 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [lacks WinVerifyTrust]
|
|---|
| 1346 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1347 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1348 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1349 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1350 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
|
|---|
| 1351 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1352 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1353 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1354 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
|
|---|
| 1355 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
|
|---|
| 1356 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
|
|---|
| 1357 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll) WinVerifyTrust
|
|---|
| 1358 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
|
|---|
| 1359 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
|
|---|
| 1360 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1361 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [redoing WinVerifyTrust]
|
|---|
| 1362 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 1363 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1364 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
|
|---|
| 1365 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
|
|---|
| 1366 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1367 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
|
|---|
| 1368 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 1369 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1370 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 1371 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1372 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'
|
|---|
| 1373 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
|
|---|
| 1374 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1375 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [redoing WinVerifyTrust]
|
|---|
| 1376 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1377 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'
|
|---|
| 1378 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 1379 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1380 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
|
|---|
| 1381 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1382 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'
|
|---|
| 1383 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 1384 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1385 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 1386 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 1387 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1388 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
|
|---|
| 1389 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1390 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
|
|---|
| 1391 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e4 pwszName=\Device\HarddiskVolume4\Windows\System32\opengl32.dll
|
|---|
| 1392 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 1393 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 1394 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5F0CC8DA0E67C8C01864C0783FA867C4BDCE0AAA
|
|---|
| 1395 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1396 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1397 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-windows~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
|
|---|
| 1398 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 1399 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
|
|---|
| 1400 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
|
|---|
| 1401 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
|
|---|
| 1402 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
|
|---|
| 1403 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
|
|---|
| 1404 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
|
|---|
| 1405 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
|
|---|
| 1406 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
|
|---|
| 1407 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
|
|---|
| 1408 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
|
|---|
| 1409 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
|
|---|
| 1410 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll)
|
|---|
| 1411 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll
|
|---|
| 1412 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 1413 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
|
|---|
| 1414 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
|
|---|
| 1415 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
|
|---|
| 1416 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
|
|---|
| 1417 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
|
|---|
| 1418 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
|
|---|
| 1419 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3480000 LB 0x0014e000 C:\Windows\system32\USER32.dll [fFlags=0x0]
|
|---|
| 1420 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3640000 LB 0x00186000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
|
|---|
| 1421 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab8bc0000 LB 0x00008000 C:\Windows\SYSTEM32\DCIMAN32.dll [fFlags=0x0]
|
|---|
| 1422 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
|
|---|
| 1423 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab7ca0000 LB 0x000f6000 C:\Windows\SYSTEM32\DDRAW.dll [fFlags=0x0]
|
|---|
| 1424 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
|
|---|
| 1425 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab7da0000 LB 0x0002e000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
|
|---|
| 1426 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
|
|---|
| 1427 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab8160000 LB 0x00128000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
|
|---|
| 1428 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
|
|---|
| 1429 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad41a0000 LB 0x0027c000 C:\Windows\system32\combase.dll [fFlags=0x0]
|
|---|
| 1430 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
|
|---|
| 1431 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3df0000 LB 0x00141000 C:\Windows\system32\ole32.dll [fFlags=0x0]
|
|---|
| 1432 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 1433 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00000000693d0000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
|
|---|
| 1434 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
|
|---|
| 1435 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1ae0000 LB 0x000b3000 C:\Windows\system32\shcore.dll [fFlags=0x0]
|
|---|
| 1436 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1437 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'combase.dll'.
|
|---|
| 1438 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\SHCore.dll)
|
|---|
| 1439 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\SHCore.dll
|
|---|
| 1440 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3d90000 LB 0x00051000 C:\Windows\system32\shlwapi.dll [fFlags=0x0]
|
|---|
| 1441 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
|
|---|
| 1442 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac4560000 LB 0x000aa000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\COMCTL32.dll [fFlags=0x0]
|
|---|
| 1443 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll [avoiding WinVerifyTrust]
|
|---|
| 1444 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0f70000 LB 0x0000f000 C:\Windows\system32\kernel.appcore.dll [fFlags=0x0]
|
|---|
| 1445 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcrt.dll'.
|
|---|
| 1446 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
|
|---|
| 1447 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll)
|
|---|
| 1448 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll
|
|---|
| 1449 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0f00000 LB 0x0004a000 C:\Windows\system32\powrprof.dll [fFlags=0x0]
|
|---|
| 1450 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1451 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
|
|---|
| 1452 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\powrprof.dll)
|
|---|
| 1453 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\powrprof.dll
|
|---|
| 1454 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad11d0000 LB 0x00628000 C:\Windows\system32\windows.storage.dll [fFlags=0x0]
|
|---|
| 1455 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1456 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
|
|---|
| 1457 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'combase.dll'.
|
|---|
| 1458 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #64 'profapi.dll'.
|
|---|
| 1459 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\windows.storage.dll)
|
|---|
| 1460 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\windows.storage.dll
|
|---|
| 1461 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1cc0000 LB 0x01522000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
|
|---|
| 1462 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1463 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3a70000 LB 0x000d7000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
|
|---|
| 1464 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
|
|---|
| 1465 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3f40000 LB 0x000be000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
|
|---|
| 1466 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1467 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3b50000 LB 0x0015c000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
|
|---|
| 1468 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll [avoiding WinVerifyTrust]
|
|---|
| 1469 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3d50000 LB 0x00036000 C:\Windows\system32\IMM32.dll [fFlags=0x0]
|
|---|
| 1470 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
|
|---|
| 1471 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1800000 LB 0x00044000 C:\Windows\system32\cfgmgr32.dll [fFlags=0x0]
|
|---|
| 1472 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
|
|---|
| 1473 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad0ba0000 LB 0x00027000 C:\Windows\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
|
|---|
| 1474 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
|
|---|
| 1475 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacec30000 LB 0x0002c000 C:\Windows\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
|
|---|
| 1476 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
|
|---|
| 1477 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacec90000 LB 0x00023000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
|
|---|
| 1478 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 1479 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacae00000 LB 0x00084000 C:\Windows\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
|
|---|
| 1480 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
|
|---|
| 1481 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 0000000068950000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
|
|---|
| 1482 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
|
|---|
| 1483 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00000000692c0000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
|
|---|
| 1484 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
|
|---|
| 1485 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 0000000068870000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
|
|---|
| 1486 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
|
|---|
| 1487 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffaa45d0000 LB 0x00ab9000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
|
|---|
| 1488 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
|
|---|
| 1489 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll'.
|
|---|
| 1490 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll' [rescheduled]
|
|---|
| 1491 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\powrprof.dll'.
|
|---|
| 1492 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\powrprof.dll' [rescheduled]
|
|---|
| 1493 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll'.
|
|---|
| 1494 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll' [rescheduled]
|
|---|
| 1495 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'.
|
|---|
| 1496 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll' [rescheduled]
|
|---|
| 1497 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll'.
|
|---|
| 1498 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll' [rescheduled]
|
|---|
| 1499 | 130c.1f0c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
|
|---|
| 1500 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rescheduled]
|
|---|
| 1501 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
|
|---|
| 1502 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rescheduled]
|
|---|
| 1503 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
|
|---|
| 1504 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rescheduled]
|
|---|
| 1505 | 130c.1f0c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
|
|---|
| 1506 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rescheduled]
|
|---|
| 1507 | 130c.1f0c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
|
|---|
| 1508 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rescheduled]
|
|---|
| 1509 | 130c.1f0c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
|
|---|
| 1510 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rescheduled]
|
|---|
| 1511 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
|
|---|
| 1512 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rescheduled]
|
|---|
| 1513 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
|
|---|
| 1514 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rescheduled]
|
|---|
| 1515 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
|
|---|
| 1516 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rescheduled]
|
|---|
| 1517 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
|
|---|
| 1518 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rescheduled]
|
|---|
| 1519 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
|
|---|
| 1520 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rescheduled]
|
|---|
| 1521 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
|
|---|
| 1522 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rescheduled]
|
|---|
| 1523 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [redoing WinVerifyTrust]
|
|---|
| 1524 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
|
|---|
| 1525 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\imm32.dll
|
|---|
| 1526 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
|
|---|
| 1527 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1528 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
|
|---|
| 1529 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 1530 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1531 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
|
|---|
| 1532 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
|
|---|
| 1533 | 130c.1f0c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
|
|---|
| 1534 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1535 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1536 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1537 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1538 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1539 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1540 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1541 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1542 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1543 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1544 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1545 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1546 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 1547 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1548 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
|
|---|
| 1549 | 130c.1f0c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
|
|---|
| 1550 | 130c.1f0c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
|
|---|
| 1551 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1552 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1553 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1554 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1555 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1556 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1557 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1558 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1559 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1560 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1561 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3d50000 'C:\Windows\system32\imm32.dll'
|
|---|
| 1562 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa45d0000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
|
|---|
| 1563 | 130c.1f0c: SUPR3HardenedMain: Calling TrustedMain (00007ffaa45d10d0)...
|
|---|
| 1564 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 1565 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1566 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 1567 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006a4 pwszName=\Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1568 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 1569 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 1570 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3717D376EF95470D8C03AD02F97C4DCBCE269CF8
|
|---|
| 1571 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1572 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1573 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB3097617~31bf3856ad364e35~amd64~~10.0.1.5.cat'; file='\Device\HarddiskVolume4\Windows\System32\uxtheme.dll'
|
|---|
| 1574 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 1575 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1576 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'gdi32.dll'.
|
|---|
| 1577 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'user32.dll'.
|
|---|
| 1578 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\uxtheme.dll) WinVerifyTrust
|
|---|
| 1579 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1580 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1581 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1582 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1583 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1584 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1585 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1586 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1587 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1588 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffaceee0000 LB 0x00096000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
|
|---|
| 1589 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1590 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaceee0000 'C:\Windows\system32\uxtheme.dll'
|
|---|
| 1591 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1592 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'user32.dll'.
|
|---|
| 1593 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'gdi32.dll'.
|
|---|
| 1594 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dwmapi.dll)
|
|---|
| 1595 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dwmapi.dll
|
|---|
| 1596 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007fface0a0000 LB 0x00022000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
|
|---|
| 1597 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
|
|---|
| 1598 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000458 pwszName=\Device\HarddiskVolume4\Windows\System32\dwmapi.dll
|
|---|
| 1599 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 1600 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 1601 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=71451274041047D99462EA805D3FAD1A9E10F86D
|
|---|
| 1602 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1603 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1604 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
|
|---|
| 1605 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1606 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1607 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1608 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1609 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1610 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1611 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_138_for_KB3097617~31bf3856ad364e35~amd64~~10.0.1.5.cat'; file='\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
|
|---|
| 1612 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 1613 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
|
|---|
| 1614 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1615 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1616 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1617 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
|
|---|
| 1618 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1619 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4420000 'C:\Windows\system32\kernel32.dll'
|
|---|
| 1620 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1621 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1622 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaceee0000 'C:\Windows\system32\uxtheme.dll'
|
|---|
| 1623 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1624 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1625 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaceee0000 'C:\Windows\system32\uxtheme.dll'
|
|---|
| 1626 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
|
|---|
| 1627 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1628 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
|
|---|
| 1629 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3480000 'C:\Windows\system32\user32.dll'
|
|---|
| 1630 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1631 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1632 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaceee0000 'C:\Windows\system32\uxtheme.dll'
|
|---|
| 1633 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3480000 'C:\Windows\system32\user32.dll'
|
|---|
| 1634 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1635 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1636 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad37d0000 'C:\Windows\system32\advapi32.dll'
|
|---|
| 1637 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1638 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1639 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1640 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
|
|---|
| 1641 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'profapi.dll'.
|
|---|
| 1642 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\userenv.dll) WinVerifyTrust
|
|---|
| 1643 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\userenv.dll
|
|---|
| 1644 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
|
|---|
| 1645 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1646 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
|
|---|
| 1647 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1648 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1649 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1650 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1651 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1652 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
|
|---|
| 1653 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad01a0000 LB 0x0001f000 C:\Windows\system32\userenv.dll [fFlags=0x0]
|
|---|
| 1654 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
|
|---|
| 1655 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad01a0000 'C:\Windows\system32\userenv.dll'
|
|---|
| 1656 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
|
|---|
| 1657 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1658 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4420000 'C:\Windows\system32\kernel32.dll'
|
|---|
| 1659 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad1c10000 LB 0x000a5000 C:\Windows\system32\clbcatq.dll [fFlags=0x0]
|
|---|
| 1660 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1661 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
|
|---|
| 1662 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\clbcatq.dll)
|
|---|
| 1663 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\clbcatq.dll
|
|---|
| 1664 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1665 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1666 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1667 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1668 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1669 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1670 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\clbcatq.dll'
|
|---|
| 1671 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1672 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1673 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 1674 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
|
|---|
| 1675 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
|
|---|
| 1676 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
|
|---|
| 1677 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
|
|---|
| 1678 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
|
|---|
| 1679 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
|
|---|
| 1680 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
|
|---|
| 1681 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
|
|---|
| 1682 | 130c.2260: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
|
|---|
| 1683 | 130c.2260: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
|
|---|
| 1684 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 1685 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1686 | 130c.2260: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1687 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 1688 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1689 | 130c.2260: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 1690 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 1691 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1692 | 130c.2260: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 1693 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
|
|---|
| 1694 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume4\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1695 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1696 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1697 | 130c.2260: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1698 | 130c.2260: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\version.dll) WinVerifyTrust
|
|---|
| 1699 | 130c.2260: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\version.dll
|
|---|
| 1700 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 1701 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1702 | 130c.2260: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
|
|---|
| 1703 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 1704 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1705 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
|
|---|
| 1706 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1707 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1708 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1709 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1710 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1711 | 130c.2260: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\psapi.dll) WinVerifyTrust
|
|---|
| 1712 | 130c.2260: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\psapi.dll
|
|---|
| 1713 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 1714 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1715 | 130c.2260: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 1716 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 1717 | 130c.2260: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1718 | 130c.2260: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
|
|---|
| 1719 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1720 | 130c.2260: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
|
|---|
| 1721 | 130c.2260: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\version.dll
|
|---|
| 1722 | 130c.2260: supR3HardenedDllNotificationCallback: load 00007ffad3a60000 LB 0x00008000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
|
|---|
| 1723 | 130c.2260: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\psapi.dll
|
|---|
| 1724 | 130c.2260: supR3HardenedDllNotificationCallback: load 00007ffacf500000 LB 0x0000a000 C:\Windows\SYSTEM32\VERSION.dll [fFlags=0x0]
|
|---|
| 1725 | 130c.2260: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\version.dll
|
|---|
| 1726 | 130c.2260: supR3HardenedDllNotificationCallback: load 00007ffaa3ff0000 LB 0x005d6000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
|
|---|
| 1727 | 130c.2260: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
|
|---|
| 1728 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3ff0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
|
|---|
| 1729 | 130c.2260: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1730 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1731 | 130c.2260: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3f40000 'C:\Windows\System32\oleaut32.dll'
|
|---|
| 1732 | 130c.2260: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sxs.dll)
|
|---|
| 1733 | 130c.2260: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sxs.dll
|
|---|
| 1734 | 130c.2260: supR3HardenedDllNotificationCallback: load 00007ffad0d30000 LB 0x00098000 C:\Windows\SYSTEM32\sxs.dll [fFlags=0x0]
|
|---|
| 1735 | 130c.2260: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sxs.dll [avoiding WinVerifyTrust]
|
|---|
| 1736 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1737 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1738 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sxs.dll'
|
|---|
| 1739 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1740 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1741 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3f40000 'C:\Windows\system32\OLEAUT32.dll'
|
|---|
| 1742 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
|
|---|
| 1743 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1744 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
|
|---|
| 1745 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3640000 'C:\Windows\system32\gdi32.dll'
|
|---|
| 1746 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3480000 'C:\Windows\system32\user32.dll'
|
|---|
| 1747 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1748 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1749 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1750 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b68 pwszName=\Device\HarddiskVolume4\Windows\System32\DataExchange.dll
|
|---|
| 1751 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 1752 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 1753 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=030BB80F5AC7982FF01AB351589D64E6D4167B3E
|
|---|
| 1754 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1755 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1756 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-AppRuntime-shell-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\DataExchange.dll'
|
|---|
| 1757 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 1758 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1759 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
|
|---|
| 1760 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'combase.dll'.
|
|---|
| 1761 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'd2d1.dll'.
|
|---|
| 1762 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'd3d11.dll'.
|
|---|
| 1763 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'dcomp.dll'.
|
|---|
| 1764 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\DataExchange.dll) WinVerifyTrust
|
|---|
| 1765 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
|
|---|
| 1766 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
|
|---|
| 1767 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume4\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1768 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1769 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1770 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1771 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dcomp.dll) WinVerifyTrust
|
|---|
| 1772 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dcomp.dll
|
|---|
| 1773 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
|
|---|
| 1774 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume4\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1775 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1776 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1777 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
|
|---|
| 1778 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1779 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1780 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1781 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'dxgi.dll'.
|
|---|
| 1782 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\d3d11.dll) WinVerifyTrust
|
|---|
| 1783 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\d3d11.dll
|
|---|
| 1784 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd2d1.dll'...
|
|---|
| 1785 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'd2d1.dll' -> '\Device\HarddiskVolume4\Windows\System32\d2d1.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1786 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bb0 pwszName=\Device\HarddiskVolume4\Windows\System32\d2d1.dll
|
|---|
| 1787 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 1788 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 1789 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CA1A7323788F698339FF353F1BA100EF7C556D74
|
|---|
| 1790 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
|
|---|
| 1791 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1792 | 130c.1f0c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\dxgi.dll'.
|
|---|
| 1793 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1794 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
|
|---|
| 1795 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dxgi.dll)
|
|---|
| 1796 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dxgi.dll
|
|---|
| 1797 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1798 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1799 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1800 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1801 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1802 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1803 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1804 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1805 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\d2d1.dll'
|
|---|
| 1806 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 1807 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1808 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\d2d1.dll) WinVerifyTrust
|
|---|
| 1809 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\d2d1.dll
|
|---|
| 1810 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 1811 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1812 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
|
|---|
| 1813 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1814 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1815 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1816 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1817 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\combase.dll'
|
|---|
| 1818 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
|
|---|
| 1819 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume4\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1820 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
|
|---|
| 1821 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1822 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1823 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'
|
|---|
| 1824 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1825 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1826 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1827 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
|
|---|
| 1828 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d2d1.dll
|
|---|
| 1829 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d3d11.dll
|
|---|
| 1830 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll
|
|---|
| 1831 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
|
|---|
| 1832 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac5e50000 LB 0x00545000 C:\Windows\system32\d2d1.dll [fFlags=0x0]
|
|---|
| 1833 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d2d1.dll
|
|---|
| 1834 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacdd50000 LB 0x0009c000 C:\Windows\system32\dxgi.dll [fFlags=0x0]
|
|---|
| 1835 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
|
|---|
| 1836 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacddf0000 LB 0x002a3000 C:\Windows\system32\d3d11.dll [fFlags=0x0]
|
|---|
| 1837 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d3d11.dll
|
|---|
| 1838 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007fface760000 LB 0x000d1000 C:\Windows\system32\dcomp.dll [fFlags=0x0]
|
|---|
| 1839 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll
|
|---|
| 1840 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffabc800000 LB 0x00046000 C:\Windows\system32\dataexchange.dll [fFlags=0x0]
|
|---|
| 1841 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
|
|---|
| 1842 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffabc800000 'C:\Windows\system32\dataexchange.dll'
|
|---|
| 1843 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1844 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1845 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dxgi.dll'
|
|---|
| 1846 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1847 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'userenv.dll'.
|
|---|
| 1848 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'bcrypt.dll'.
|
|---|
| 1849 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
|
|---|
| 1850 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'combase.dll'.
|
|---|
| 1851 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll)
|
|---|
| 1852 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll
|
|---|
| 1853 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacefa0000 LB 0x000ee000 C:\Windows\system32\twinapi.appcore.dll [fFlags=0x0]
|
|---|
| 1854 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
|
|---|
| 1855 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 1856 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1857 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll
|
|---|
| 1858 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1859 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1860 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
|
|---|
| 1861 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
|
|---|
| 1862 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1863 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
|
|---|
| 1864 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
|
|---|
| 1865 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume4\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1866 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
|
|---|
| 1867 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1868 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1869 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1870 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1871 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll'
|
|---|
| 1872 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll [redoing WinVerifyTrust]
|
|---|
| 1873 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
|
|---|
| 1874 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1875 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1876 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1877 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll'
|
|---|
| 1878 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1879 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3b50000 'C:\Windows\system32\MSCTF.dll'
|
|---|
| 1880 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1881 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1882 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1883 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1884 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1885 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1886 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1887 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1888 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1889 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1890 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1891 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1892 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll' [redir]
|
|---|
| 1893 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll [redoing WinVerifyTrust]
|
|---|
| 1894 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1895 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1896 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll'
|
|---|
| 1897 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1898 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac4560000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll'
|
|---|
| 1899 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 1900 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\SYSTEM32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1901 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\SYSTEM32\WINMM.dll'
|
|---|
| 1902 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1903 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1904 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1905 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1906 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1907 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1908 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1909 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1910 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1911 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1912 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1913 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1914 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1915 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1916 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 1917 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1918 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaceee0000 'C:\Windows\system32/uxtheme.dll'
|
|---|
| 1919 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1920 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1921 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1922 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1923 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1924 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1925 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1926 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1927 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
|
|---|
| 1928 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1929 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 1930 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1931 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1932 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1933 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
|
|---|
| 1934 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
|
|---|
| 1935 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\propsys.dll) WinVerifyTrust
|
|---|
| 1936 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\propsys.dll
|
|---|
| 1937 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1938 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1939 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 1940 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1941 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 1942 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1943 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1944 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\propsys.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1945 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
|
|---|
| 1946 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007fface160000 LB 0x00183000 C:\Windows\system32\propsys.dll [fFlags=0x0]
|
|---|
| 1947 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
|
|---|
| 1948 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fface160000 'C:\Windows\system32\propsys.dll'
|
|---|
| 1949 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\windows.storage.dll [redoing WinVerifyTrust]
|
|---|
| 1950 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1951 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1952 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll'
|
|---|
| 1953 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Windows.Storage.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1954 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad11d0000 'C:\Windows\system32\Windows.Storage.dll'
|
|---|
| 1955 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\windows.storage.dll
|
|---|
| 1956 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\windows.storage.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 1957 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad11d0000 'C:\Windows\system32\windows.storage.dll'
|
|---|
| 1958 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1959 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1960 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1961 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'gdi32.dll'.
|
|---|
| 1962 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
|
|---|
| 1963 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll) WinVerifyTrust
|
|---|
| 1964 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
|
|---|
| 1965 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 1966 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1967 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 1968 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1969 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1970 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1971 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll (Input=comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1972 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
|
|---|
| 1973 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac02e0000 LB 0x00274000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll [fFlags=0x0]
|
|---|
| 1974 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
|
|---|
| 1975 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac02e0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll'
|
|---|
| 1976 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
|
|---|
| 1977 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll (Input=comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 1978 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac02e0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll'
|
|---|
| 1979 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 1980 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
|
|---|
| 1981 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
|
|---|
| 1982 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WindowsCodecs.dll)
|
|---|
| 1983 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WindowsCodecs.dll
|
|---|
| 1984 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacac00000 LB 0x001b2000 C:\Windows\SYSTEM32\WindowsCodecs.dll [fFlags=0x0]
|
|---|
| 1985 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WindowsCodecs.dll [avoiding WinVerifyTrust]
|
|---|
| 1986 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
|
|---|
| 1987 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1988 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
|
|---|
| 1989 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 1990 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1991 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 1992 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 1993 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 1994 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 1995 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\WindowsCodecs.dll'
|
|---|
| 1996 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\System32\shell32.dll'
|
|---|
| 1997 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\System32\shell32.dll'
|
|---|
| 1998 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\apphelp.dll)
|
|---|
| 1999 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\apphelp.dll
|
|---|
| 2000 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffaced60000 LB 0x00078000 C:\Windows\SYSTEM32\apphelp.dll [fFlags=0x0]
|
|---|
| 2001 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\apphelp.dll [avoiding WinVerifyTrust]
|
|---|
| 2002 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e1c pwszName=\Device\HarddiskVolume4\Windows\System32\apphelp.dll
|
|---|
| 2003 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2004 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2005 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=54A8D49732D327F780234E47407FD91AB77B632A
|
|---|
| 2006 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2007 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2008 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-base~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\apphelp.dll'
|
|---|
| 2009 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2010 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\apphelp.dll'
|
|---|
| 2011 | 130c.1f0c: \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll: Owner is not trusted installer (01 05 00 00 00 00 00 05 15 00 00 00 0b f4 b7 b3 5e f7 a4 6b ab 0b 7c 99 e9 03 00 00)
|
|---|
| 2012 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> -5667 (\Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll)
|
|---|
| 2013 | 130c.1f0c: Error (rc=0):
|
|---|
| 2014 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -5667 (0xffffe9dd) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll: supHardenedWinVerifyImageByHandle: TrustedInstaller is not the owner of '\Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll'.
|
|---|
| 2015 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll
|
|---|
| 2016 | 130c.1f0c: Error (rc=0):
|
|---|
| 2017 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll' (C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll): rcNt=0xc0000190
|
|---|
| 2018 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll'
|
|---|
| 2019 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -5667 (0xffffe9dd)) on \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll [lacks WinVerifyTrust]
|
|---|
| 2020 | 130c.1f0c: Error (rc=0):
|
|---|
| 2021 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -5667 (0xffffe9dd) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll
|
|---|
| 2022 | 130c.1f0c: Error (rc=0):
|
|---|
| 2023 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll' (C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll): rcNt=0xc0000190
|
|---|
| 2024 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll'
|
|---|
| 2025 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -5667 (0xffffe9dd)) on \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll [lacks WinVerifyTrust]
|
|---|
| 2026 | 130c.1f0c: Error (rc=0):
|
|---|
| 2027 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -5667 (0xffffe9dd) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll
|
|---|
| 2028 | 130c.1f0c: Error (rc=0):
|
|---|
| 2029 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll' (C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll): rcNt=0xc0000190
|
|---|
| 2030 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll'
|
|---|
| 2031 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -5667 (0xffffe9dd)) on \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll [lacks WinVerifyTrust]
|
|---|
| 2032 | 130c.1f0c: Error (rc=0):
|
|---|
| 2033 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -5667 (0xffffe9dd) fImage=1 fProtect=0x0 fAccess=0x0 cHits=3 \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll
|
|---|
| 2034 | 130c.1f0c: Error (rc=0):
|
|---|
| 2035 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll' (C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll): rcNt=0xc0000190
|
|---|
| 2036 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll'
|
|---|
| 2037 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -5667 (0xffffe9dd)) on \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll [lacks WinVerifyTrust]
|
|---|
| 2038 | 130c.1f0c: Error (rc=0):
|
|---|
| 2039 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -5667 (0xffffe9dd) fImage=1 fProtect=0x0 fAccess=0x0 cHits=4 \Device\HarddiskVolume4\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll
|
|---|
| 2040 | 130c.1f0c: Error (rc=0):
|
|---|
| 2041 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll' (C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll): rcNt=0xc0000190
|
|---|
| 2042 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Users\Zachary Burns\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll'
|
|---|
| 2043 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d20 pwszName=\Device\HarddiskVolume4\Windows\System32\EhStorShell.dll
|
|---|
| 2044 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2045 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2046 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=71E11A131CDF3E69651FC99A41A71D0B0DE9672D
|
|---|
| 2047 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2048 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2049 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-drivers~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\EhStorShell.dll'
|
|---|
| 2050 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2051 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2052 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
|
|---|
| 2053 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
|
|---|
| 2054 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
|
|---|
| 2055 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
|
|---|
| 2056 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
|
|---|
| 2057 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
|
|---|
| 2058 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shlwapi.dll'.
|
|---|
| 2059 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'comctl32.dll'.
|
|---|
| 2060 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'setupapi.dll'.
|
|---|
| 2061 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\EhStorShell.dll) WinVerifyTrust
|
|---|
| 2062 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\EhStorShell.dll
|
|---|
| 2063 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
|
|---|
| 2064 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2065 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2066 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2067 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'cfgmgr32.dll'.
|
|---|
| 2068 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
|
|---|
| 2069 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
|
|---|
| 2070 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\setupapi.dll) WinVerifyTrust
|
|---|
| 2071 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\setupapi.dll
|
|---|
| 2072 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
|
|---|
| 2073 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
|
|---|
| 2074 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comctl32.dll [redoing WinVerifyTrust]
|
|---|
| 2075 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2076 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2077 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2078 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2079 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
|
|---|
| 2080 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2081 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
|
|---|
| 2082 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2083 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2084 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'
|
|---|
| 2085 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
|
|---|
| 2086 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2087 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
|
|---|
| 2088 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2089 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
|
|---|
| 2090 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2091 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2092 | 130c.1f0c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'
|
|---|
| 2093 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
|
|---|
| 2094 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume4\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2095 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
|
|---|
| 2096 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
|
|---|
| 2097 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2098 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 2099 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2100 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 2101 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2102 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 2103 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 2104 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2105 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 2106 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2107 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2108 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2109 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2110 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\EhStorShell.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2111 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\EhStorShell.dll
|
|---|
| 2112 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffad3890000 LB 0x001c5000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
|
|---|
| 2113 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
|
|---|
| 2114 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab8be0000 LB 0x00037000 C:\Windows\System32\EhStorShell.dll [fFlags=0x0]
|
|---|
| 2115 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\EhStorShell.dll
|
|---|
| 2116 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8be0000 'C:\Windows\System32\EhStorShell.dll'
|
|---|
| 2117 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\EhStorShell.dll
|
|---|
| 2118 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\EhStorShell.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2119 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8be0000 'C:\Windows\System32\EhStorShell.dll'
|
|---|
| 2120 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e04 pwszName=\Device\HarddiskVolume4\Windows\System32\cscui.dll
|
|---|
| 2121 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2122 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2123 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E64571B9529C5C26824687EDDD20704860318470
|
|---|
| 2124 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2125 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2126 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OfflineFiles-UI-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\cscui.dll'
|
|---|
| 2127 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2128 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2129 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'propsys.dll'.
|
|---|
| 2130 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
|
|---|
| 2131 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
|
|---|
| 2132 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
|
|---|
| 2133 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'cscdll.dll'.
|
|---|
| 2134 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
|
|---|
| 2135 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cscui.dll) WinVerifyTrust
|
|---|
| 2136 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cscui.dll
|
|---|
| 2137 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2138 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2139 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cscdll.dll'...
|
|---|
| 2140 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cscdll.dll' -> '\Device\HarddiskVolume4\Windows\System32\cscdll.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2141 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e08 pwszName=\Device\HarddiskVolume4\Windows\System32\cscdll.dll
|
|---|
| 2142 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2143 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2144 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CF8F6BC6D7190460FA0E3467AE0519E1B041C365
|
|---|
| 2145 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2146 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2147 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-base~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\cscdll.dll'
|
|---|
| 2148 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2149 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2150 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cscdll.dll) WinVerifyTrust
|
|---|
| 2151 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cscdll.dll
|
|---|
| 2152 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2153 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2154 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
|
|---|
| 2155 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2156 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
|
|---|
| 2157 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
|
|---|
| 2158 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2159 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
|
|---|
| 2160 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume4\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2161 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
|
|---|
| 2162 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2163 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2164 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2165 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2166 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cscui.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2167 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cscui.dll
|
|---|
| 2168 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cscdll.dll
|
|---|
| 2169 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab8bd0000 LB 0x0000d000 C:\Windows\System32\CSCDLL.dll [fFlags=0x0]
|
|---|
| 2170 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cscdll.dll
|
|---|
| 2171 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab8030000 LB 0x000c4000 C:\Windows\System32\cscui.dll [fFlags=0x0]
|
|---|
| 2172 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cscui.dll
|
|---|
| 2173 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
|
|---|
| 2174 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll (Input=comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2175 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac02e0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll'
|
|---|
| 2176 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8030000 'C:\Windows\System32\cscui.dll'
|
|---|
| 2177 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cscui.dll
|
|---|
| 2178 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cscui.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2179 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8030000 'C:\Windows\System32\cscui.dll'
|
|---|
| 2180 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2181 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shell32.dll'.
|
|---|
| 2182 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
|
|---|
| 2183 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
|
|---|
| 2184 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
|
|---|
| 2185 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
|
|---|
| 2186 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shlwapi.dll'.
|
|---|
| 2187 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'mpr.dll'.
|
|---|
| 2188 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcrt.dll'.
|
|---|
| 2189 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll) WinVerifyTrust
|
|---|
| 2190 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll
|
|---|
| 2191 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2192 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2193 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
|
|---|
| 2194 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume4\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2195 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2196 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2197 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mpr.dll) WinVerifyTrust
|
|---|
| 2198 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mpr.dll
|
|---|
| 2199 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
|
|---|
| 2200 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2201 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
|
|---|
| 2202 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 2203 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2204 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 2205 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 2206 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2207 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2208 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2209 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 2210 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2211 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
|
|---|
| 2212 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2213 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2214 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll
|
|---|
| 2215 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mpr.dll
|
|---|
| 2216 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffacfe20000 LB 0x0001c000 C:\Windows\SYSTEM32\MPR.dll [fFlags=0x0]
|
|---|
| 2217 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mpr.dll
|
|---|
| 2218 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab7fd0000 LB 0x00052000 C:\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll [fFlags=0x0]
|
|---|
| 2219 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll
|
|---|
| 2220 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7fd0000 'C:\Program Files (x86)\Parallels\Parallels Tools\ShellExtentions\PrlToolsShellExt.dll'
|
|---|
| 2221 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d14 pwszName=\Device\HarddiskVolume4\Windows\System32\mssprxy.dll
|
|---|
| 2222 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2223 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2224 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=246789B7D75DFAD08D941EC92596C38786199961
|
|---|
| 2225 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2226 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2227 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_218_for_KB3081444~31bf3856ad364e35~amd64~~10.0.1.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\mssprxy.dll'
|
|---|
| 2228 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2229 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2230 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
|
|---|
| 2231 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
|
|---|
| 2232 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mssprxy.dll) WinVerifyTrust
|
|---|
| 2233 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mssprxy.dll
|
|---|
| 2234 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 2235 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2236 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
|
|---|
| 2237 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2238 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2239 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2240 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2241 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mssprxy.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2242 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mssprxy.dll
|
|---|
| 2243 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab83d0000 LB 0x00023000 C:\Windows\system32\mssprxy.dll [fFlags=0x0]
|
|---|
| 2244 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mssprxy.dll
|
|---|
| 2245 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab83d0000 'C:\Windows\system32\mssprxy.dll'
|
|---|
| 2246 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\System32\shell32.dll'
|
|---|
| 2247 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d2c pwszName=\Device\HarddiskVolume4\Windows\System32\thumbcache.dll
|
|---|
| 2248 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2249 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2250 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1DBC107C40D287802EBE6D2F04AED2B6BC21C52
|
|---|
| 2251 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2252 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2253 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-AppRuntime-shell-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\thumbcache.dll'
|
|---|
| 2254 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2255 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2256 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shcore.dll'.
|
|---|
| 2257 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
|
|---|
| 2258 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\thumbcache.dll) WinVerifyTrust
|
|---|
| 2259 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\thumbcache.dll
|
|---|
| 2260 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2261 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2262 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
|
|---|
| 2263 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume4\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2264 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
|
|---|
| 2265 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2266 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2267 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\thumbcache.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2268 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\thumbcache.dll
|
|---|
| 2269 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffab8f80000 LB 0x0004b000 C:\Windows\System32\thumbcache.dll [fFlags=0x0]
|
|---|
| 2270 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\thumbcache.dll
|
|---|
| 2271 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll
|
|---|
| 2272 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll (Input=comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2273 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac02e0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\comctl32.dll'
|
|---|
| 2274 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8f80000 'C:\Windows\System32\thumbcache.dll'
|
|---|
| 2275 | 130c.1f0c: '\Device\HarddiskVolume4\Windows\System32\imageres.dll' has no imports
|
|---|
| 2276 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\imageres.dll)
|
|---|
| 2277 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imageres.dll
|
|---|
| 2278 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\imageres.dll [avoiding WinVerifyTrust]
|
|---|
| 2279 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ebc pwszName=\Device\HarddiskVolume4\Windows\System32\imageres.dll
|
|---|
| 2280 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2281 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2282 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4623A580B03375E478409EF57299A63413828324
|
|---|
| 2283 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2284 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2285 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-shell~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\imageres.dll'
|
|---|
| 2286 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2287 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imageres.dll'
|
|---|
| 2288 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 2289 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 2290 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 2291 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2292 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3df0000 'C:\Windows\system32\ole32.dll'
|
|---|
| 2293 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3f40000 'C:\Windows\system32\OLEAUT32.dll'
|
|---|
| 2294 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cb8 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
|
|---|
| 2295 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2296 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2297 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AA7BAB6C49E4A06208A6E0EE146D0A4385100231
|
|---|
| 2298 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2299 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2300 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll'
|
|---|
| 2301 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2302 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2303 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
|
|---|
| 2304 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
|
|---|
| 2305 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
|
|---|
| 2306 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
|
|---|
| 2307 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
|
|---|
| 2308 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2309 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c58 pwszName=\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
|
|---|
| 2310 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2311 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2312 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8589CB867869E61D2D0DD902D9F24828D41B3FB4
|
|---|
| 2313 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2314 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2315 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll'
|
|---|
| 2316 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2317 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2318 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'bcrypt.dll'.
|
|---|
| 2319 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'ws2_32.dll'.
|
|---|
| 2320 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll) WinVerifyTrust
|
|---|
| 2321 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
|
|---|
| 2322 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 2323 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2324 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 2325 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2326 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2327 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 2328 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2329 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 2330 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
|
|---|
| 2331 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2332 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
|
|---|
| 2333 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2334 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2335 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2336 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
|
|---|
| 2337 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
|
|---|
| 2338 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffaca3c0000 LB 0x0007f000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
|
|---|
| 2339 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
|
|---|
| 2340 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffaca450000 LB 0x00011000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
|
|---|
| 2341 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
|
|---|
| 2342 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2343 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1900000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
|
|---|
| 2344 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaca450000 'C:\Windows\system32\wbem\wbemprox.dll'
|
|---|
| 2345 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f04 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
|
|---|
| 2346 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2347 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2348 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F55A40FEDA5AB0854F7A2A7AE88B827B3F76303B
|
|---|
| 2349 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2350 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2351 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll'
|
|---|
| 2352 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2353 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2354 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
|
|---|
| 2355 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
|
|---|
| 2356 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
|
|---|
| 2357 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2358 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2359 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2360 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2361 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2362 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
|
|---|
| 2363 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac9980000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
|
|---|
| 2364 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
|
|---|
| 2365 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac9980000 'C:\Windows\system32\wbem\wbemsvc.dll'
|
|---|
| 2366 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2367 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1900000 'api-ms-win-core-localization-l1-2-0.dll'
|
|---|
| 2368 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2369 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1900000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
|
|---|
| 2370 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f08 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
|
|---|
| 2371 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2372 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2373 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E360AD530F1A62ACF9003C6FE3BA6BBD7638D488
|
|---|
| 2374 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2375 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2376 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll'
|
|---|
| 2377 | 130c.1f0c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2378 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2379 | 130c.1f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
|
|---|
| 2380 | 130c.1f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
|
|---|
| 2381 | 130c.1f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
|
|---|
| 2382 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
|
|---|
| 2383 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2384 | 130c.1f0c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
|
|---|
| 2385 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2386 | 130c.1f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2387 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2388 | 130c.1f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
|
|---|
| 2389 | 130c.1f0c: supR3HardenedDllNotificationCallback: load 00007ffac9e20000 LB 0x000f8000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
|
|---|
| 2390 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
|
|---|
| 2391 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac9e20000 'C:\Windows\system32\wbem\fastprox.dll'
|
|---|
| 2392 | 130c.2150: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2393 | 130c.2150: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2394 | 130c.2150: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
|
|---|
| 2395 | 130c.2150: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2396 | 130c.2150: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
|
|---|
| 2397 | 130c.2150: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2398 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2399 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2400 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
|
|---|
| 2401 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2402 | 130c.2150: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2403 | 130c.2150: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
|
|---|
| 2404 | 130c.2150: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
|
|---|
| 2405 | 130c.2150: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
|
|---|
| 2406 | 130c.2150: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
|
|---|
| 2407 | 130c.2150: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
|
|---|
| 2408 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2409 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2410 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2411 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2412 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
|
|---|
| 2413 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2414 | 130c.2150: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2415 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2416 | 130c.2150: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2417 | 130c.2150: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2418 | 130c.2150: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2419 | 130c.2150: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
|
|---|
| 2420 | 130c.2150: supR3HardenedDllNotificationCallback: load 0000000068760000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
|
|---|
| 2421 | 130c.2150: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
|
|---|
| 2422 | 130c.2150: supR3HardenedDllNotificationCallback: load 00007ffaa5e70000 LB 0x00293000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
|
|---|
| 2423 | 130c.2150: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2424 | 130c.2150: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa5e70000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
|
|---|
| 2425 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2426 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2427 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys)
|
|---|
| 2428 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys
|
|---|
| 2429 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
|
|---|
| 2430 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2431 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys)
|
|---|
| 2432 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys
|
|---|
| 2433 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
|
|---|
| 2434 | 130c.1794: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys: Owner is administrators group.
|
|---|
| 2435 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ndis.sys'.
|
|---|
| 2436 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ntoskrnl.exe'.
|
|---|
| 2437 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys)
|
|---|
| 2438 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys
|
|---|
| 2439 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
|
|---|
| 2440 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2441 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
|
|---|
| 2442 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
|
|---|
| 2443 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys)
|
|---|
| 2444 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys
|
|---|
| 2445 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
|
|---|
| 2446 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
|
|---|
| 2447 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2448 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys'.
|
|---|
| 2449 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2450 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
|
|---|
| 2451 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
|
|---|
| 2452 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys)
|
|---|
| 2453 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\netio.sys
|
|---|
| 2454 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
|
|---|
| 2455 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2456 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys'.
|
|---|
| 2457 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2458 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
|
|---|
| 2459 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
|
|---|
| 2460 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'wpprecorder.sys'.
|
|---|
| 2461 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys)
|
|---|
| 2462 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys
|
|---|
| 2463 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2464 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2465 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe'.
|
|---|
| 2466 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'hal.dll'.
|
|---|
| 2467 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'pshed.dll'.
|
|---|
| 2468 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'bootvid.dll'.
|
|---|
| 2469 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'kdcom.dll'.
|
|---|
| 2470 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ci.dll'.
|
|---|
| 2471 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'msrpc.sys'.
|
|---|
| 2472 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe)
|
|---|
| 2473 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe
|
|---|
| 2474 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2475 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2476 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2477 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
|
|---|
| 2478 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2479 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys [lacks WinVerifyTrust]
|
|---|
| 2480 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2481 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2482 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2483 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2484 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2485 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2486 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
|
|---|
| 2487 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Failed to locate 'msrpc.sys'
|
|---|
| 2488 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
|
|---|
| 2489 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume4\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2490 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\ci.dll'.
|
|---|
| 2491 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2492 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
|
|---|
| 2493 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ci.dll)
|
|---|
| 2494 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ci.dll
|
|---|
| 2495 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
|
|---|
| 2496 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume4\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2497 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\kdcom.dll'.
|
|---|
| 2498 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2499 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
|
|---|
| 2500 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kdcom.dll)
|
|---|
| 2501 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kdcom.dll
|
|---|
| 2502 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bootvid.dll'...
|
|---|
| 2503 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'bootvid.dll' -> '\Device\HarddiskVolume4\Windows\System32\bootvid.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2504 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL'.
|
|---|
| 2505 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2506 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL)
|
|---|
| 2507 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL
|
|---|
| 2508 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
|
|---|
| 2509 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume4\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2510 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\PSHED.DLL'.
|
|---|
| 2511 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2512 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
|
|---|
| 2513 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\PSHED.DLL)
|
|---|
| 2514 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL
|
|---|
| 2515 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
|
|---|
| 2516 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2517 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\hal.dll'.
|
|---|
| 2518 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2519 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
|
|---|
| 2520 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
|
|---|
| 2521 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\hal.dll)
|
|---|
| 2522 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\hal.dll
|
|---|
| 2523 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wpprecorder.sys'...
|
|---|
| 2524 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'wpprecorder.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\wpprecorder.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2525 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\WppRecorder.sys'.
|
|---|
| 2526 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2527 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\WppRecorder.sys)
|
|---|
| 2528 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\WppRecorder.sys
|
|---|
| 2529 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
|
|---|
| 2530 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2531 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\netio.sys [lacks WinVerifyTrust]
|
|---|
| 2532 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
|
|---|
| 2533 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2534 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
|
|---|
| 2535 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2536 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2537 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2538 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
|
|---|
| 2539 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2540 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys'.
|
|---|
| 2541 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
|
|---|
| 2542 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys)
|
|---|
| 2543 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys
|
|---|
| 2544 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
|
|---|
| 2545 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
|
|---|
| 2546 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys [lacks WinVerifyTrust]
|
|---|
| 2547 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2548 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2549 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2550 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2551 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2552 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2553 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2554 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2555 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2556 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
|
|---|
| 2557 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume4\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2558 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\PSHED.DLL [lacks WinVerifyTrust]
|
|---|
| 2559 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
|
|---|
| 2560 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume4\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2561 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kdcom.dll [lacks WinVerifyTrust]
|
|---|
| 2562 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2563 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2564 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2565 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
|
|---|
| 2566 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2567 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
|
|---|
| 2568 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2569 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2570 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2571 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2572 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2573 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2574 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
|
|---|
| 2575 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2576 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
|
|---|
| 2577 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2578 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2579 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2580 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
|
|---|
| 2581 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2582 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
|
|---|
| 2583 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
|
|---|
| 2584 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
|
|---|
| 2585 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
|
|---|
| 2586 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2587 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys'
|
|---|
| 2588 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2589 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys'
|
|---|
| 2590 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2591 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys'
|
|---|
| 2592 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2593 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys'
|
|---|
| 2594 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2595 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2596 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys'
|
|---|
| 2597 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2598 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2599 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\WppRecorder.sys'
|
|---|
| 2600 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2601 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2602 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\hal.dll'
|
|---|
| 2603 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2604 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2605 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\PSHED.DLL'
|
|---|
| 2606 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2607 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2608 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL'
|
|---|
| 2609 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2610 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2611 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kdcom.dll'
|
|---|
| 2612 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2613 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2614 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ci.dll'
|
|---|
| 2615 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2616 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2617 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe'
|
|---|
| 2618 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2619 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2620 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys'
|
|---|
| 2621 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2622 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2623 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys'
|
|---|
| 2624 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cbc pwszName=\Device\HarddiskVolume4\Windows\System32\NetSetupShim.dll
|
|---|
| 2625 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2626 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2627 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=695CB5D234E33829E3320DD8DE835DE7D1459933
|
|---|
| 2628 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2629 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2630 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_379_for_KB3097617~31bf3856ad364e35~amd64~~10.0.1.5.cat'; file='\Device\HarddiskVolume4\Windows\System32\NetSetupShim.dll'
|
|---|
| 2631 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2632 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2633 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
|
|---|
| 2634 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'ws2_32.dll'.
|
|---|
| 2635 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'netsetupapi.dll'.
|
|---|
| 2636 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'setupapi.dll'.
|
|---|
| 2637 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\NetSetupShim.dll) WinVerifyTrust
|
|---|
| 2638 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\NetSetupShim.dll
|
|---|
| 2639 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
|
|---|
| 2640 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2641 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
|
|---|
| 2642 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
|
|---|
| 2643 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2644 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2645 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2646 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2647 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
|
|---|
| 2648 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\NetSetupApi.dll) WinVerifyTrust
|
|---|
| 2649 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\NetSetupApi.dll
|
|---|
| 2650 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 2651 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2652 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 2653 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2654 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2655 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2656 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2657 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2658 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2659 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2660 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2661 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2662 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\NetSetupShim.dll
|
|---|
| 2663 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\NetSetupApi.dll
|
|---|
| 2664 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffac8750000 LB 0x0001d000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
|
|---|
| 2665 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\NetSetupApi.dll
|
|---|
| 2666 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffac8770000 LB 0x00063000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
|
|---|
| 2667 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\NetSetupShim.dll
|
|---|
| 2668 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8770000 'C:\Windows\System32\NetSetupShim.dll'
|
|---|
| 2669 | 130c.1e90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2670 | 130c.1e90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2671 | 130c.1e90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
|
|---|
| 2672 | 130c.1e90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2673 | 130c.1e90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
|
|---|
| 2674 | 130c.1e90: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
|
|---|
| 2675 | 130c.1e90: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
|
|---|
| 2676 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2677 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2678 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2679 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2680 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
|
|---|
| 2681 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2682 | 130c.1e90: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2683 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2684 | 130c.1e90: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2685 | 130c.1e90: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2686 | 130c.1e90: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
|
|---|
| 2687 | 130c.1e90: supR3HardenedDllNotificationCallback: load 00007ffad09d0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
|
|---|
| 2688 | 130c.1e90: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
|
|---|
| 2689 | 130c.1e90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad09d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
|
|---|
| 2690 | 130c.13e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2691 | 130c.13e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2692 | 130c.13e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
|
|---|
| 2693 | 130c.13e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2694 | 130c.13e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
|
|---|
| 2695 | 130c.13e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
|
|---|
| 2696 | 130c.13e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2697 | 130c.13e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2698 | 130c.13e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 2699 | 130c.13e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2700 | 130c.13e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 2701 | 130c.13e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2702 | 130c.13e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2703 | 130c.13e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2704 | 130c.13e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
|
|---|
| 2705 | 130c.13e0: supR3HardenedDllNotificationCallback: load 00007ffac91e0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
|
|---|
| 2706 | 130c.13e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
|
|---|
| 2707 | 130c.13e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac91e0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
|
|---|
| 2708 | 130c.acc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2709 | 130c.acc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2710 | 130c.acc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
|
|---|
| 2711 | 130c.acc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2712 | 130c.acc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
|
|---|
| 2713 | 130c.acc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
|
|---|
| 2714 | 130c.acc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2715 | 130c.acc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2716 | 130c.acc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 2717 | 130c.acc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2718 | 130c.acc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
|
|---|
| 2719 | 130c.acc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2720 | 130c.acc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2721 | 130c.acc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2722 | 130c.acc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
|
|---|
| 2723 | 130c.acc: supR3HardenedDllNotificationCallback: load 00007ffac8c30000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
|
|---|
| 2724 | 130c.acc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
|
|---|
| 2725 | 130c.acc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8c30000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
|
|---|
| 2726 | 130c.1450: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2727 | 130c.1450: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2728 | 130c.1450: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
|
|---|
| 2729 | 130c.1450: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2730 | 130c.1450: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
|
|---|
| 2731 | 130c.1450: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
|
|---|
| 2732 | 130c.1450: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2733 | 130c.1450: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2734 | 130c.1450: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
|
|---|
| 2735 | 130c.1450: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2736 | 130c.1450: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2737 | 130c.1450: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2738 | 130c.1450: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2739 | 130c.1450: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
|
|---|
| 2740 | 130c.1450: supR3HardenedDllNotificationCallback: load 00007ffac0960000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
|
|---|
| 2741 | 130c.1450: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
|
|---|
| 2742 | 130c.1450: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac0960000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
|
|---|
| 2743 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32/Shell32.dll'
|
|---|
| 2744 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2745 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2746 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2747 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2748 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
|
|---|
| 2749 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2750 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
|
|---|
| 2751 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
|
|---|
| 2752 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
|
|---|
| 2753 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
|
|---|
| 2754 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
|
|---|
| 2755 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
|
|---|
| 2756 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
|
|---|
| 2757 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
|
|---|
| 2758 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
|
|---|
| 2759 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
|
|---|
| 2760 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2761 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2762 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2763 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
|
|---|
| 2764 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winnsi.dll'.
|
|---|
| 2765 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
|
|---|
| 2766 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
|
|---|
| 2767 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
|
|---|
| 2768 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2769 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
|
|---|
| 2770 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
|
|---|
| 2771 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2772 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
|
|---|
| 2773 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
|
|---|
| 2774 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2775 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
|
|---|
| 2776 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2777 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2778 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
|
|---|
| 2779 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2780 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
|
|---|
| 2781 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2782 | 130c.1794: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'.
|
|---|
| 2783 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
|
|---|
| 2784 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
|
|---|
| 2785 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winnsi.dll)
|
|---|
| 2786 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winnsi.dll
|
|---|
| 2787 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
|
|---|
| 2788 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2789 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
|
|---|
| 2790 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
|
|---|
| 2791 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2792 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
|
|---|
| 2793 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2794 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2795 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2796 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2797 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
|
|---|
| 2798 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2799 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
|
|---|
| 2800 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
|
|---|
| 2801 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
|
|---|
| 2802 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2803 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2804 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2805 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
|
|---|
| 2806 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2807 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2808 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2809 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2810 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2811 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2812 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
|
|---|
| 2813 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
|
|---|
| 2814 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
|
|---|
| 2815 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
|
|---|
| 2816 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
|
|---|
| 2817 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
|
|---|
| 2818 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
|
|---|
| 2819 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2820 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2821 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
|
|---|
| 2822 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2823 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2824 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2825 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2826 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 2827 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2828 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
|
|---|
| 2829 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume4\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2830 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001114 pwszName=\Device\HarddiskVolume4\Windows\System32\newdev.dll
|
|---|
| 2831 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2832 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2833 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=793D99A2656EF7BC8AE3D3DA54E1A198969B9F96
|
|---|
| 2834 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2835 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2836 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-base~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\newdev.dll'
|
|---|
| 2837 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2838 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2839 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
|
|---|
| 2840 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
|
|---|
| 2841 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'uxtheme.dll'.
|
|---|
| 2842 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'cfgmgr32.dll'.
|
|---|
| 2843 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'setupapi.dll'.
|
|---|
| 2844 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\newdev.dll) WinVerifyTrust
|
|---|
| 2845 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\newdev.dll
|
|---|
| 2846 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
|
|---|
| 2847 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2848 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
|
|---|
| 2849 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2850 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2851 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2852 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2853 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2854 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2855 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
|
|---|
| 2856 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
|
|---|
| 2857 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2858 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
|
|---|
| 2859 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
|
|---|
| 2860 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2861 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
|
|---|
| 2862 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2863 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2864 | 130c.1794: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'
|
|---|
| 2865 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
|
|---|
| 2866 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume4\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2867 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
|
|---|
| 2868 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
|
|---|
| 2869 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2870 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2871 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2872 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
|
|---|
| 2873 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2874 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2875 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2876 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
|
|---|
| 2877 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
|
|---|
| 2878 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
|
|---|
| 2879 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
|
|---|
| 2880 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\newdev.dll
|
|---|
| 2881 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
|
|---|
| 2882 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2883 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\devrtl.dll)
|
|---|
| 2884 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devrtl.dll
|
|---|
| 2885 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffac9830000 LB 0x00013000 C:\Windows\SYSTEM32\devrtl.DLL [fFlags=0x0]
|
|---|
| 2886 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
|
|---|
| 2887 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaa9d90000 LB 0x00058000 C:\Windows\SYSTEM32\newdev.dll [fFlags=0x0]
|
|---|
| 2888 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\newdev.dll
|
|---|
| 2889 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaa9cb0000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
|
|---|
| 2890 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
|
|---|
| 2891 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaa7a50000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
|
|---|
| 2892 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
|
|---|
| 2893 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffacc710000 LB 0x0000b000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
|
|---|
| 2894 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
|
|---|
| 2895 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffacc720000 LB 0x00038000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
|
|---|
| 2896 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
|
|---|
| 2897 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaa3700000 LB 0x008e2000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
|
|---|
| 2898 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
|
|---|
| 2899 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3700000 'C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL'
|
|---|
| 2900 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001164 pwszName=\Device\HarddiskVolume4\Windows\System32\devrtl.dll
|
|---|
| 2901 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2902 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2903 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4E1A7D70D0B4F04066620172BA9B8A3CADF2EF6
|
|---|
| 2904 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2905 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2906 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2907 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2908 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-base~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\devrtl.dll'
|
|---|
| 2909 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2910 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\devrtl.dll'
|
|---|
| 2911 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2912 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2913 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'
|
|---|
| 2914 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2915 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
|
|---|
| 2916 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2917 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3ff0000 'C:\Program Files\Oracle\VirtualBox/VBoxC.DLL'
|
|---|
| 2918 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2919 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
|
|---|
| 2920 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2921 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa7a50000 'C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL'
|
|---|
| 2922 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2923 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2924 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2925 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2926 | 130c.544: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2927 | 130c.544: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
|
|---|
| 2928 | 130c.544: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
|
|---|
| 2929 | 130c.544: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
|
|---|
| 2930 | 130c.544: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
|
|---|
| 2931 | 130c.544: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
|
|---|
| 2932 | 130c.544: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
|
|---|
| 2933 | 130c.544: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2934 | 130c.544: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
|
|---|
| 2935 | 130c.544: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2936 | 130c.544: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 2937 | 130c.544: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
|
|---|
| 2938 | 130c.544: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2939 | 130c.544: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2940 | 130c.544: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
|
|---|
| 2941 | 130c.544: supR3HardenedDllNotificationCallback: load 00007ffac0950000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
|
|---|
| 2942 | 130c.544: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
|
|---|
| 2943 | 130c.544: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac0950000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
|
|---|
| 2944 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000120c pwszName=\Device\HarddiskVolume4\Windows\System32\dsound.dll
|
|---|
| 2945 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 2946 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 2947 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7FF2119E435E404AD007FD65DA8D286C1635ACA6
|
|---|
| 2948 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2949 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2950 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SKU-Foundation-Package-avcore-noindeo-Group-avcore-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\dsound.dll'
|
|---|
| 2951 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 2952 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2953 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'advapi32.dll'.
|
|---|
| 2954 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
|
|---|
| 2955 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'winmm.dll'.
|
|---|
| 2956 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dsound.dll) WinVerifyTrust
|
|---|
| 2957 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dsound.dll
|
|---|
| 2958 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
|
|---|
| 2959 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2960 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 2961 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 2962 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2963 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
|
|---|
| 2964 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2965 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2966 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2967 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2968 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
|
|---|
| 2969 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaa7320000 LB 0x0009c000 C:\Windows\system32\dsound.dll [fFlags=0x0]
|
|---|
| 2970 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
|
|---|
| 2971 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
|
|---|
| 2972 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2973 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa7320000 'C:\Windows\system32\dsound.dll'
|
|---|
| 2974 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa7320000 'C:\Windows\system32/dsound.dll'
|
|---|
| 2975 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2976 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2977 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 2978 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
|
|---|
| 2979 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'devobj.dll'.
|
|---|
| 2980 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'propsys.dll'.
|
|---|
| 2981 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll) WinVerifyTrust
|
|---|
| 2982 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 2983 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
|
|---|
| 2984 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume4\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2985 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
|
|---|
| 2986 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
|
|---|
| 2987 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2988 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [redoing WinVerifyTrust]
|
|---|
| 2989 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
|
|---|
| 2990 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 2991 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 2992 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 2993 | 130c.1794: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\devobj.dll'
|
|---|
| 2994 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 2995 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2996 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 2997 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 2998 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 2999 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 3000 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaca580000 LB 0x00072000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
|
|---|
| 3001 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 3002 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaca580000 'C:\Windows\System32\MMDevApi.dll'
|
|---|
| 3003 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 3004 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3005 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaca580000 'C:\Windows\system32\MMDEVAPI.DLL'
|
|---|
| 3006 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 3007 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3008 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3009 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001278 pwszName=\Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3010 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 3011 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 3012 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83143779FC4D27950BF3BCBCD430201AA21D5678
|
|---|
| 3013 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3014 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3015 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MMECoreWdmAudio-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wdmaud.drv'
|
|---|
| 3016 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 3017 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3018 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'ksuser.dll'.
|
|---|
| 3019 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
|
|---|
| 3020 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'winmm.dll'.
|
|---|
| 3021 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'avrt.dll'.
|
|---|
| 3022 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'mmdevapi.dll'.
|
|---|
| 3023 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wdmaud.drv) WinVerifyTrust
|
|---|
| 3024 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3025 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
|
|---|
| 3026 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3027 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 3028 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
|
|---|
| 3029 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3030 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3031 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3032 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\avrt.dll) WinVerifyTrust
|
|---|
| 3033 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\avrt.dll
|
|---|
| 3034 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
|
|---|
| 3035 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3036 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 3037 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 3038 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3039 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
|
|---|
| 3040 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume4\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3041 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3042 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3043 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3044 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ksuser.dll) WinVerifyTrust
|
|---|
| 3045 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ksuser.dll
|
|---|
| 3046 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3047 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3048 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3049 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3050 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3051 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3052 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
|
|---|
| 3053 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
|
|---|
| 3054 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffac9aa0000 LB 0x00008000 C:\Windows\SYSTEM32\ksuser.dll [fFlags=0x0]
|
|---|
| 3055 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
|
|---|
| 3056 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffac9a90000 LB 0x0000b000 C:\Windows\SYSTEM32\AVRT.dll [fFlags=0x0]
|
|---|
| 3057 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
|
|---|
| 3058 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffacf6e0000 LB 0x00041000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
|
|---|
| 3059 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3060 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3061 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3062 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3063 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3064 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3065 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3066 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3067 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3068 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3069 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3070 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3071 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3072 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3073 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3074 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3075 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3076 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
|
|---|
| 3077 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
|
|---|
| 3078 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'mmdevapi.dll'.
|
|---|
| 3079 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\AudioSes.dll) WinVerifyTrust
|
|---|
| 3080 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
|
|---|
| 3081 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
|
|---|
| 3082 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3083 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 3084 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
|
|---|
| 3085 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3086 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 3087 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3088 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3089 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3090 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3091 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
|
|---|
| 3092 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3093 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'combase.dll'.
|
|---|
| 3094 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
|
|---|
| 3095 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WinTypes.dll)
|
|---|
| 3096 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WinTypes.dll
|
|---|
| 3097 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffaca600000 LB 0x00131000 C:\Windows\SYSTEM32\wintypes.dll [fFlags=0x0]
|
|---|
| 3098 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
|
|---|
| 3099 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffac2570000 LB 0x00085000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
|
|---|
| 3100 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
|
|---|
| 3101 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac2570000 'C:\Windows\system32\AUDIOSES.DLL'
|
|---|
| 3102 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
|
|---|
| 3103 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3104 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
|
|---|
| 3105 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3106 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll
|
|---|
| 3107 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3108 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3109 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3110 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3111 | 130c.1794: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\WinTypes.dll'
|
|---|
| 3112 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3113 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3114 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3115 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
|
|---|
| 3116 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3117 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3118 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3119 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3120 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3121 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3122 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3123 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3124 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf6e0000 'C:\Windows\system32\wdmaud.drv'
|
|---|
| 3125 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fe8 pwszName=\Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3126 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 3127 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 3128 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EAA362874D7E19DE11B8B4782838AD2981FC207
|
|---|
| 3129 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3130 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3131 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SKU-Foundation-Package-avcore-noindeo-Group-avcore-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\msacm32.drv'
|
|---|
| 3132 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 3133 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3134 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
|
|---|
| 3135 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msacm32.dll'.
|
|---|
| 3136 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'user32.dll'.
|
|---|
| 3137 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmm.dll'.
|
|---|
| 3138 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.drv) WinVerifyTrust
|
|---|
| 3139 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3140 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
|
|---|
| 3141 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3142 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
|
|---|
| 3143 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3144 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
|
|---|
| 3145 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3146 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3147 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3148 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3149 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.dll) WinVerifyTrust
|
|---|
| 3150 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.dll
|
|---|
| 3151 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
|
|---|
| 3152 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3153 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
|
|---|
| 3154 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3155 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3156 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3157 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3158 | 130c.1794: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
|
|---|
| 3159 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3160 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3161 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
|
|---|
| 3162 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffacf6c0000 LB 0x0001c000 C:\Windows\SYSTEM32\MSACM32.dll [fFlags=0x0]
|
|---|
| 3163 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
|
|---|
| 3164 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffacf980000 LB 0x0000c000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
|
|---|
| 3165 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3166 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3167 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3168 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3169 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3170 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3171 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3172 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3173 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3174 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3175 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3176 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3177 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3178 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3179 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3180 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3181 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3182 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
|
|---|
| 3183 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3184 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3185 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3186 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3187 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf980000 'C:\Windows\system32\msacm32.drv'
|
|---|
| 3188 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000012cc pwszName=\Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3189 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000ec0cc0
|
|---|
| 3190 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000ec0cc0
|
|---|
| 3191 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=96AFFE7289EA0FE318F97A9F3C88DF66DCB2B4F6
|
|---|
| 3192 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad00b0000 'C:\Windows\system32\rsaenh.dll'
|
|---|
| 3193 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1000000 'C:\Windows\system32\crypt32.dll'
|
|---|
| 3194 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SKU-Foundation-Package-avcore-noindeo-Group-avcore-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\midimap.dll'
|
|---|
| 3195 | 130c.1794: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
|
|---|
| 3196 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
|
|---|
| 3197 | 130c.1794: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'winmm.dll'.
|
|---|
| 3198 | 130c.1794: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\midimap.dll) WinVerifyTrust
|
|---|
| 3199 | 130c.1794: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3200 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
|
|---|
| 3201 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3202 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
|
|---|
| 3203 | 130c.1794: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
|
|---|
| 3204 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3205 | 130c.1794: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3206 | 130c.1794: supR3HardenedDllNotificationCallback: load 00007ffacf970000 LB 0x0000a000 C:\Windows\system32\midimap.dll [fFlags=0x0]
|
|---|
| 3207 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3208 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf970000 'C:\Windows\system32\midimap.dll'
|
|---|
| 3209 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3210 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3211 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf970000 'C:\Windows\system32\midimap.dll'
|
|---|
| 3212 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3213 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3214 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf970000 'C:\Windows\system32\midimap.dll'
|
|---|
| 3215 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
|
|---|
| 3216 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3217 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacf970000 'C:\Windows\system32\midimap.dll'
|
|---|
| 3218 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3219 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3220 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3221 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3222 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3223 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
|
|---|
| 3224 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3225 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3226 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
|
|---|
| 3227 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 3228 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa7320000 'C:\Windows\System32\dsound.dll'
|
|---|
| 3229 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3230 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3231 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacec90000 'C:\Windows\system32\winmm.dll'
|
|---|
| 3232 | 130c.1794: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
|
|---|
| 3233 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
|
|---|
| 3234 | 130c.1794: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4420000 'C:\Windows\system32/kernel32.dll'
|
|---|
| 3235 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3f40000 'C:\Windows\system32\OLEAUT32.DLL'
|
|---|
| 3236 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll
|
|---|
| 3237 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msctf.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 3238 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3b50000 'C:\Windows\system32\msctf.dll'
|
|---|
| 3239 | 130c.1f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll
|
|---|
| 3240 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msctf.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
|
|---|
| 3241 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad3b50000 'C:\Windows\system32\msctf.dll'
|
|---|
| 3242 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 3243 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 3244 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 3245 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 3246 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 3247 | 130c.1f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad1cc0000 'C:\Windows\system32\shell32.dll'
|
|---|
| 3248 | 130c.544: supR3HardenedDllNotificationCallback: Unload 00007ffac0950000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
|
|---|
| 3249 | 130c.1450: supR3HardenedDllNotificationCallback: Unload 00007ffac0960000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
|
|---|
| 3250 | 130c.acc: supR3HardenedDllNotificationCallback: Unload 00007ffac8c30000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
|
|---|
| 3251 | 130c.13e0: supR3HardenedDllNotificationCallback: Unload 00007ffac91e0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
|
|---|
| 3252 | 130c.1e90: supR3HardenedDllNotificationCallback: Unload 00007ffad09d0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
|
|---|
| 3253 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffaa3700000 LB 0x008e2000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
|
|---|
| 3254 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffaa9cb0000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
|
|---|
| 3255 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffaa9d90000 LB 0x00058000 C:\Windows\SYSTEM32\newdev.dll [flags=0x0]
|
|---|
| 3256 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffac9830000 LB 0x00013000 C:\Windows\SYSTEM32\devrtl.DLL [flags=0x0]
|
|---|
| 3257 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffaa7a50000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
|
|---|
| 3258 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffacc720000 LB 0x00038000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [flags=0x0]
|
|---|
| 3259 | 130c.1794: supR3HardenedDllNotificationCallback: Unload 00007ffacc710000 LB 0x0000b000 C:\Windows\SYSTEM32\WINNSI.DLL [flags=0x0]
|
|---|
| 3260 | 130c.1f0c: Terminating the normal way: rcExit=0
|
|---|
| 3261 | 17d4.18f8: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 55329 ms, the end);
|
|---|
| 3262 | 1e00.2090: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 55722 ms, the end);
|
|---|