VirtualBox

Ticket #15087: VBoxHardening.log

File VBoxHardening.log, 84.9 KB (added by zadarum, 9 years ago)
Line 
137a0.3ff8: Log file opened: 5.0.14r105127 g_hStartupLog=00000000000000ac g_uNtVerCombined=0x611db110
237a0.3ff8: \SystemRoot\System32\ntdll.dll:
337a0.3ff8: CreationTime: 2016-01-05T15:15:33.635876900Z
437a0.3ff8: LastWriteTime: 2015-10-20T01:09:05.164170200Z
537a0.3ff8: ChangeTime: 2016-01-05T23:14:24.453534400Z
637a0.3ff8: FileAttributes: 0x20
737a0.3ff8: Size: 0x1a67c0
837a0.3ff8: NT Headers: 0xe0
937a0.3ff8: Timestamp: 0x56259295
1037a0.3ff8: Machine: 0x8664 - amd64
1137a0.3ff8: Timestamp: 0x56259295
1237a0.3ff8: Image Version: 6.1
1337a0.3ff8: SizeOfImage: 0x1a9000 (1740800)
1437a0.3ff8: Resource Dir: 0x14d000 LB 0x5a028
1537a0.3ff8: ProductName: Microsoft® Windows® Operating System
1637a0.3ff8: ProductVersion: 6.1.7601.19045
1737a0.3ff8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
1837a0.3ff8: FileDescription: NT Layer DLL
1937a0.3ff8: \SystemRoot\System32\kernel32.dll:
2037a0.3ff8: CreationTime: 2016-01-05T15:15:33.089890900Z
2137a0.3ff8: LastWriteTime: 2015-10-20T01:05:40.819000000Z
2237a0.3ff8: ChangeTime: 2016-01-05T23:14:25.077514400Z
2337a0.3ff8: FileAttributes: 0x20
2437a0.3ff8: Size: 0x11c600
2537a0.3ff8: NT Headers: 0xe8
2637a0.3ff8: Timestamp: 0x56259270
2737a0.3ff8: Machine: 0x8664 - amd64
2837a0.3ff8: Timestamp: 0x56259270
2937a0.3ff8: Image Version: 6.1
3037a0.3ff8: SizeOfImage: 0x120000 (1179648)
3137a0.3ff8: Resource Dir: 0x117000 LB 0x528
3237a0.3ff8: ProductName: Microsoft® Windows® Operating System
3337a0.3ff8: ProductVersion: 6.1.7601.19045
3437a0.3ff8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
3537a0.3ff8: FileDescription: Windows NT BASE API Client DLL
3637a0.3ff8: \SystemRoot\System32\KernelBase.dll:
3737a0.3ff8: CreationTime: 2016-01-05T15:15:36.615400500Z
3837a0.3ff8: LastWriteTime: 2015-10-20T01:05:40.819000000Z
3937a0.3ff8: ChangeTime: 2016-01-05T23:14:25.093113900Z
4037a0.3ff8: FileAttributes: 0x20
4137a0.3ff8: Size: 0x67c00
4237a0.3ff8: NT Headers: 0xe8
4337a0.3ff8: Timestamp: 0x56259271
4437a0.3ff8: Machine: 0x8664 - amd64
4537a0.3ff8: Timestamp: 0x56259271
4637a0.3ff8: Image Version: 6.1
4737a0.3ff8: SizeOfImage: 0x6c000 (442368)
4837a0.3ff8: Resource Dir: 0x6a000 LB 0x530
4937a0.3ff8: ProductName: Microsoft® Windows® Operating System
5037a0.3ff8: ProductVersion: 6.1.7601.19045
5137a0.3ff8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
5237a0.3ff8: FileDescription: Windows NT BASE API Client DLL
5337a0.3ff8: \SystemRoot\System32\apisetschema.dll:
5437a0.3ff8: CreationTime: 2016-01-05T15:15:41.841266500Z
5537a0.3ff8: LastWriteTime: 2015-10-20T00:53:47.280000000Z
5637a0.3ff8: ChangeTime: 2016-01-05T23:14:24.079146400Z
5737a0.3ff8: FileAttributes: 0x20
5837a0.3ff8: Size: 0x1a00
5937a0.3ff8: NT Headers: 0xc0
6037a0.3ff8: Timestamp: 0x562590e2
6137a0.3ff8: Machine: 0x8664 - amd64
6237a0.3ff8: Timestamp: 0x562590e2
6337a0.3ff8: Image Version: 6.1
6437a0.3ff8: SizeOfImage: 0x50000 (327680)
6537a0.3ff8: Resource Dir: 0x30000 LB 0x3f8
6637a0.3ff8: ProductName: Microsoft® Windows® Operating System
6737a0.3ff8: ProductVersion: 6.1.7601.19045
6837a0.3ff8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
6937a0.3ff8: FileDescription: ApiSet Schema DLL
7037a0.3ff8: Found driver mfewfpk (0x20)
7137a0.3ff8: Found driver mfehidk (0x20)
7237a0.3ff8: Found driver mfeavfk (0x20)
7337a0.3ff8: Found driver mfefirek (0x20)
7437a0.3ff8: supR3HardenedWinFindAdversaries: 0x20
7537a0.3ff8: \SystemRoot\System32\drivers\mfeapfk.sys:
7637a0.3ff8: CreationTime: 2014-08-27T13:53:23.447070100Z
7737a0.3ff8: LastWriteTime: 2014-08-27T13:53:11.606254300Z
7837a0.3ff8: ChangeTime: 2015-08-26T11:18:34.144626700Z
7937a0.3ff8: FileAttributes: 0x20
8037a0.3ff8: Size: 0x2c030
8137a0.3ff8: NT Headers: 0xe8
8237a0.3ff8: Timestamp: 0x52ab7fef
8337a0.3ff8: Machine: 0x8664 - amd64
8437a0.3ff8: Timestamp: 0x52ab7fef
8537a0.3ff8: Image Version: 0.0
8637a0.3ff8: SizeOfImage: 0x29d00 (171264)
8737a0.3ff8: Resource Dir: 0x29500 LB 0x340
8837a0.3ff8: ProductName: SYSCORE
8937a0.3ff8: FileVersion: SYSCORE.15.1.0.656
9037a0.3ff8: PrivateBuild: SYSCORE.15.1.0.656 F16
9137a0.3ff8: FileDescription: Access Protection Filter Driver
9237a0.3ff8: \SystemRoot\System32\drivers\mfeavfk.sys:
9337a0.3ff8: CreationTime: 2014-08-27T13:53:23.326082200Z
9437a0.3ff8: LastWriteTime: 2015-10-22T18:41:49.066172200Z
9537a0.3ff8: ChangeTime: 2015-10-22T18:41:59.236070500Z
9637a0.3ff8: FileAttributes: 0x20
9737a0.3ff8: Size: 0x54e98
9837a0.3ff8: NT Headers: 0xf8
9937a0.3ff8: Timestamp: 0x558ddc3c
10037a0.3ff8: Machine: 0x8664 - amd64
10137a0.3ff8: Timestamp: 0x558ddc3c
10237a0.3ff8: Image Version: 0.0
10337a0.3ff8: SizeOfImage: 0x50580 (329088)
10437a0.3ff8: Resource Dir: 0x4f700 LB 0x758
10537a0.3ff8: ProductName: SYSCORE
10637a0.3ff8: ProductVersion: 15.4.0.674
10737a0.3ff8: FileVersion: SYSCORE.15.4.0.674
10837a0.3ff8: PrivateBuild: SYSCORE.15.4.0.674 F15,F16,F19
10937a0.3ff8: FileDescription: Anti-Virus File System Filter Driver
11037a0.3ff8: \SystemRoot\System32\drivers\mfefirek.sys:
11137a0.3ff8: CreationTime: 2015-10-26T20:59:00.916917600Z
11237a0.3ff8: LastWriteTime: 2015-10-26T20:57:28.083102900Z
11337a0.3ff8: ChangeTime: 2015-10-26T20:57:28.083102900Z
11437a0.3ff8: FileAttributes: 0x20
11537a0.3ff8: Size: 0x794f8
11637a0.3ff8: NT Headers: 0xe8
11737a0.3ff8: Timestamp: 0x558ddc7b
11837a0.3ff8: Machine: 0x8664 - amd64
11937a0.3ff8: Timestamp: 0x558ddc7b
12037a0.3ff8: Image Version: 0.0
12137a0.3ff8: SizeOfImage: 0x74880 (477312)
12237a0.3ff8: Resource Dir: 0x72000 LB 0x388
12337a0.3ff8: ProductName: SYSCORE
12437a0.3ff8: ProductVersion: 15.4.0.674
12537a0.3ff8: FileVersion: SYSCORE.15.4.0.674
12637a0.3ff8: PrivateBuild: SYSCORE.15.4.0.674 F17,F18
12737a0.3ff8: FileDescription: McAfee Core Firewall Engine Driver
12837a0.3ff8: \SystemRoot\System32\drivers\mfehidk.sys:
12937a0.3ff8: CreationTime: 2014-08-27T13:53:22.847130100Z
13037a0.3ff8: LastWriteTime: 2015-10-22T18:41:49.016172700Z
13137a0.3ff8: ChangeTime: 2015-10-22T18:41:49.016172700Z
13237a0.3ff8: FileAttributes: 0x20
13337a0.3ff8: Size: 0xd5d98
13437a0.3ff8: NT Headers: 0x108
13537a0.3ff8: Timestamp: 0x558ddbf8
13637a0.3ff8: Machine: 0x8664 - amd64
13737a0.3ff8: Timestamp: 0x558ddbf8
13837a0.3ff8: Image Version: 0.0
13937a0.3ff8: SizeOfImage: 0xd0880 (854144)
14037a0.3ff8: Resource Dir: 0xcd980 LB 0x758
14137a0.3ff8: ProductName: SYSCORE
14237a0.3ff8: ProductVersion: 15.4.0.674
14337a0.3ff8: FileVersion: SYSCORE.15.4.0.674
14437a0.3ff8: PrivateBuild: SYSCORE.15.4.0.674 F14,F15,F16,F18,F20
14537a0.3ff8: FileDescription: McAfee Link Driver
14637a0.3ff8: \SystemRoot\System32\drivers\mfewfpk.sys:
14737a0.3ff8: CreationTime: 2014-08-27T13:53:16.103804500Z
14837a0.3ff8: LastWriteTime: 2015-10-26T20:57:27.817908000Z
14937a0.3ff8: ChangeTime: 2015-10-26T20:57:27.817908000Z
15037a0.3ff8: FileAttributes: 0x20
15137a0.3ff8: Size: 0x54280
15237a0.3ff8: NT Headers: 0x100
15337a0.3ff8: Timestamp: 0x558ddc06
15437a0.3ff8: Machine: 0x8664 - amd64
15537a0.3ff8: Timestamp: 0x558ddc06
15637a0.3ff8: Image Version: 0.0
15737a0.3ff8: SizeOfImage: 0x4f980 (326016)
15837a0.3ff8: Resource Dir: 0x4ef00 LB 0x380
15937a0.3ff8: ProductName: SYSCORE
16037a0.3ff8: ProductVersion: 15.4.0.674
16137a0.3ff8: FileVersion: SYSCORE.15.4.0.674
16237a0.3ff8: PrivateBuild: SYSCORE.15.4.0.674 F17,F18
16337a0.3ff8: FileDescription: Anti-Virus Mini-Firewall Driver
16437a0.3ff8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
16537a0.3ff8: Calling main()
16637a0.3ff8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
16737a0.3ff8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
16837a0.3ff8: SUPR3HardenedMain: Respawn #1
16937a0.3ff8: System32: \Device\HarddiskVolume1\Windows\System32
17037a0.3ff8: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
17137a0.3ff8: KnownDllPath: C:\Windows\system32
17237a0.3ff8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
17337a0.3ff8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
17437a0.3ff8: supR3HardNtEnableThreadCreation:
17537a0.3ff8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076cdb630 pvNtTerminateThread=0000000076cfdee0
17637a0.3ff8: supR3HardenedWinDoReSpawn(1): New child 3304.3124 [kernel32].
17737a0.3ff8: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd7000 cbPeb=0x380
17837a0.3ff8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000076cb0000 uNtDllChildAddr=0000000076cb0000
17937a0.3ff8: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000076cdb630
18037a0.3ff8: supR3HardenedWinSetupChildInit: Start child.
18137a0.3ff8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
18237a0.3ff8: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
18337a0.3ff8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
18437a0.3ff8: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
18537a0.3ff8: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
18637a0.3ff8: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
18737a0.3ff8: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
18837a0.3ff8: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
18937a0.3ff8: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
19037a0.3ff8: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
19137a0.3ff8: 0000000000051000-ffffffffffea1fff 0x0001/0x0000 0x0000000
19237a0.3ff8: *0000000000200000-0000000000103fff 0x0000/0x0004 0x0020000
19337a0.3ff8: 00000000002fc000-00000000002f8fff 0x0104/0x0004 0x0020000
19437a0.3ff8: 00000000002ff000-00000000002fdfff 0x0004/0x0004 0x0020000
19537a0.3ff8: 0000000000300000-ffffffff8994ffff 0x0001/0x0000 0x0000000
19637a0.3ff8: *0000000076cb0000-0000000076cb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
19737a0.3ff8: 0000000076cb1000-0000000076daefff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
19837a0.3ff8: 0000000076daf000-0000000076dddfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
19937a0.3ff8: 0000000076dde000-0000000076de5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20037a0.3ff8: 0000000076de6000-0000000076de6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20137a0.3ff8: 0000000076de7000-0000000076de9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20237a0.3ff8: 0000000076dea000-0000000076e58fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20337a0.3ff8: 0000000076e59000-000000006ecd1fff 0x0001/0x0000 0x0000000
20437a0.3ff8: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
20537a0.3ff8: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
20637a0.3ff8: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
20737a0.3ff8: 000000007fff0000-ffffffffc077ffff 0x0001/0x0000 0x0000000
20837a0.3ff8: *000000013f860000-000000013f860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
20937a0.3ff8: 000000013f861000-000000013f8e7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21037a0.3ff8: 000000013f8e8000-000000013f8e8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21137a0.3ff8: 000000013f8e9000-000000013f933fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21237a0.3ff8: 000000013f934000-000000013f934fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21337a0.3ff8: 000000013f935000-000000013f935fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21437a0.3ff8: 000000013f936000-000000013f93afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21537a0.3ff8: 000000013f93b000-000000013f93bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21637a0.3ff8: 000000013f93c000-000000013f93cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21737a0.3ff8: 000000013f93d000-000000013f940fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21837a0.3ff8: 000000013f941000-000000013f98bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
21937a0.3ff8: 000000013f98c000-fffff80380347fff 0x0001/0x0000 0x0000000
22037a0.3ff8: *000007fefefd0000-000007fefefd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
22137a0.3ff8: 000007fefefd1000-000007fdfdff1fff 0x0001/0x0000 0x0000000
22237a0.3ff8: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
22337a0.3ff8: 000007fffffd3000-000007fffffcefff 0x0001/0x0000 0x0000000
22437a0.3ff8: *000007fffffd7000-000007fffffd5fff 0x0004/0x0004 0x0020000
22537a0.3ff8: 000007fffffd8000-000007fffffd1fff 0x0001/0x0000 0x0000000
22637a0.3ff8: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
22737a0.3ff8: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
22837a0.3ff8: apisetschema.dll: timestamp 0x562590e2 (rc=VINF_SUCCESS)
22937a0.3ff8: VirtualBox.exe: timestamp 0x569e6712 (rc=VINF_SUCCESS)
23037a0.3ff8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
23137a0.3ff8: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
23237a0.3ff8: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
23337a0.3ff8: supR3HardNtChildPurify: Done after 562 ms and 0 fixes (loop #0).
23437a0.3ff8: supR3HardNtEnableThreadCreation:
2353304.3124: Log file opened: 5.0.14r105127 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
2363304.3124: supR3HardenedVmProcessInit: uNtDllAddr=0000000076cb0000
2373304.3124: ntdll.dll: timestamp 0x56259295 (rc=VINF_SUCCESS)
2383304.3124: New simple heap: #1 0000000000300000 LB 0x400000 (for 1740800 allocation)
2393304.3124: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
2403304.3124: System32: \Device\HarddiskVolume1\Windows\System32
2413304.3124: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
2423304.3124: KnownDllPath: C:\Windows\system32
2433304.3124: supR3HardenedVmProcessInit: Opening vboxdrv stub...
2443304.3124: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
2453304.3124: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
2463304.3124: Registered Dll notification callback with NTDLL.
2473304.3124: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
2483304.3124: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
2493304.3124: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2503304.3124: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2513304.3124: supR3HardenedDllNotificationCallback: load 0000000076b90000 LB 0x00120000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
2523304.3124: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2533304.3124: supR3HardenedDllNotificationCallback: load 000007fefcd90000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
2543304.3124: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
2553304.3124: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
2563304.3124: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b90000 'C:\Windows\system32\kernel32.dll'
2573304.3124: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076cdb630 pvNtTerminateThread=0000000076cfdee0
25837a0.3ff8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 26 ms.
2593304.3124: \SystemRoot\System32\ntdll.dll:
2603304.3124: CreationTime: 2016-01-05T15:15:33.635876900Z
2613304.3124: LastWriteTime: 2015-10-20T01:09:05.164170200Z
2623304.3124: ChangeTime: 2016-01-05T23:14:24.453534400Z
2633304.3124: FileAttributes: 0x20
2643304.3124: Size: 0x1a67c0
2653304.3124: NT Headers: 0xe0
2663304.3124: Timestamp: 0x56259295
2673304.3124: Machine: 0x8664 - amd64
2683304.3124: Timestamp: 0x56259295
2693304.3124: Image Version: 6.1
2703304.3124: SizeOfImage: 0x1a9000 (1740800)
2713304.3124: Resource Dir: 0x14d000 LB 0x5a028
2723304.3124: ProductName: Microsoft® Windows® Operating System
2733304.3124: ProductVersion: 6.1.7601.19045
2743304.3124: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2753304.3124: FileDescription: NT Layer DLL
2763304.3124: \SystemRoot\System32\kernel32.dll:
2773304.3124: CreationTime: 2016-01-05T15:15:33.089890900Z
2783304.3124: LastWriteTime: 2015-10-20T01:05:40.819000000Z
2793304.3124: ChangeTime: 2016-01-05T23:14:25.077514400Z
2803304.3124: FileAttributes: 0x20
2813304.3124: Size: 0x11c600
2823304.3124: NT Headers: 0xe8
2833304.3124: Timestamp: 0x56259270
2843304.3124: Machine: 0x8664 - amd64
2853304.3124: Timestamp: 0x56259270
2863304.3124: Image Version: 6.1
2873304.3124: SizeOfImage: 0x120000 (1179648)
2883304.3124: Resource Dir: 0x117000 LB 0x528
2893304.3124: ProductName: Microsoft® Windows® Operating System
2903304.3124: ProductVersion: 6.1.7601.19045
2913304.3124: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2923304.3124: FileDescription: Windows NT BASE API Client DLL
2933304.3124: \SystemRoot\System32\KernelBase.dll:
2943304.3124: CreationTime: 2016-01-05T15:15:36.615400500Z
2953304.3124: LastWriteTime: 2015-10-20T01:05:40.819000000Z
2963304.3124: ChangeTime: 2016-01-05T23:14:25.093113900Z
2973304.3124: FileAttributes: 0x20
2983304.3124: Size: 0x67c00
2993304.3124: NT Headers: 0xe8
3003304.3124: Timestamp: 0x56259271
3013304.3124: Machine: 0x8664 - amd64
3023304.3124: Timestamp: 0x56259271
3033304.3124: Image Version: 6.1
3043304.3124: SizeOfImage: 0x6c000 (442368)
3053304.3124: Resource Dir: 0x6a000 LB 0x530
3063304.3124: ProductName: Microsoft® Windows® Operating System
3073304.3124: ProductVersion: 6.1.7601.19045
3083304.3124: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
3093304.3124: FileDescription: Windows NT BASE API Client DLL
3103304.3124: \SystemRoot\System32\apisetschema.dll:
3113304.3124: CreationTime: 2016-01-05T15:15:41.841266500Z
3123304.3124: LastWriteTime: 2015-10-20T00:53:47.280000000Z
3133304.3124: ChangeTime: 2016-01-05T23:14:24.079146400Z
3143304.3124: FileAttributes: 0x20
3153304.3124: Size: 0x1a00
3163304.3124: NT Headers: 0xc0
3173304.3124: Timestamp: 0x562590e2
3183304.3124: Machine: 0x8664 - amd64
3193304.3124: Timestamp: 0x562590e2
3203304.3124: Image Version: 6.1
3213304.3124: SizeOfImage: 0x50000 (327680)
3223304.3124: Resource Dir: 0x30000 LB 0x3f8
3233304.3124: ProductName: Microsoft® Windows® Operating System
3243304.3124: ProductVersion: 6.1.7601.19045
3253304.3124: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
3263304.3124: FileDescription: ApiSet Schema DLL
3273304.3124: Found driver mfewfpk (0x20)
3283304.3124: Found driver mfehidk (0x20)
3293304.3124: Found driver mfeavfk (0x20)
3303304.3124: Found driver mfefirek (0x20)
3313304.3124: supR3HardenedWinFindAdversaries: 0x20
3323304.3124: \SystemRoot\System32\drivers\mfeapfk.sys:
3333304.3124: CreationTime: 2014-08-27T13:53:23.447070100Z
3343304.3124: LastWriteTime: 2014-08-27T13:53:11.606254300Z
3353304.3124: ChangeTime: 2015-08-26T11:18:34.144626700Z
3363304.3124: FileAttributes: 0x20
3373304.3124: Size: 0x2c030
3383304.3124: NT Headers: 0xe8
3393304.3124: Timestamp: 0x52ab7fef
3403304.3124: Machine: 0x8664 - amd64
3413304.3124: Timestamp: 0x52ab7fef
3423304.3124: Image Version: 0.0
3433304.3124: SizeOfImage: 0x29d00 (171264)
3443304.3124: Resource Dir: 0x29500 LB 0x340
3453304.3124: ProductName: SYSCORE
3463304.3124: FileVersion: SYSCORE.15.1.0.656
3473304.3124: PrivateBuild: SYSCORE.15.1.0.656 F16
3483304.3124: FileDescription: Access Protection Filter Driver
3493304.3124: \SystemRoot\System32\drivers\mfeavfk.sys:
3503304.3124: CreationTime: 2014-08-27T13:53:23.326082200Z
3513304.3124: LastWriteTime: 2015-10-22T18:41:49.066172200Z
3523304.3124: ChangeTime: 2015-10-22T18:41:59.236070500Z
3533304.3124: FileAttributes: 0x20
3543304.3124: Size: 0x54e98
3553304.3124: NT Headers: 0xf8
3563304.3124: Timestamp: 0x558ddc3c
3573304.3124: Machine: 0x8664 - amd64
3583304.3124: Timestamp: 0x558ddc3c
3593304.3124: Image Version: 0.0
3603304.3124: SizeOfImage: 0x50580 (329088)
3613304.3124: Resource Dir: 0x4f700 LB 0x758
3623304.3124: ProductName: SYSCORE
3633304.3124: ProductVersion: 15.4.0.674
3643304.3124: FileVersion: SYSCORE.15.4.0.674
3653304.3124: PrivateBuild: SYSCORE.15.4.0.674 F15,F16,F19
3663304.3124: FileDescription: Anti-Virus File System Filter Driver
3673304.3124: \SystemRoot\System32\drivers\mfefirek.sys:
3683304.3124: CreationTime: 2015-10-26T20:59:00.916917600Z
3693304.3124: LastWriteTime: 2015-10-26T20:57:28.083102900Z
3703304.3124: ChangeTime: 2015-10-26T20:57:28.083102900Z
3713304.3124: FileAttributes: 0x20
3723304.3124: Size: 0x794f8
3733304.3124: NT Headers: 0xe8
3743304.3124: Timestamp: 0x558ddc7b
3753304.3124: Machine: 0x8664 - amd64
3763304.3124: Timestamp: 0x558ddc7b
3773304.3124: Image Version: 0.0
3783304.3124: SizeOfImage: 0x74880 (477312)
3793304.3124: Resource Dir: 0x72000 LB 0x388
3803304.3124: ProductName: SYSCORE
3813304.3124: ProductVersion: 15.4.0.674
3823304.3124: FileVersion: SYSCORE.15.4.0.674
3833304.3124: PrivateBuild: SYSCORE.15.4.0.674 F17,F18
3843304.3124: FileDescription: McAfee Core Firewall Engine Driver
3853304.3124: \SystemRoot\System32\drivers\mfehidk.sys:
3863304.3124: CreationTime: 2014-08-27T13:53:22.847130100Z
3873304.3124: LastWriteTime: 2015-10-22T18:41:49.016172700Z
3883304.3124: ChangeTime: 2015-10-22T18:41:49.016172700Z
3893304.3124: FileAttributes: 0x20
3903304.3124: Size: 0xd5d98
3913304.3124: NT Headers: 0x108
3923304.3124: Timestamp: 0x558ddbf8
3933304.3124: Machine: 0x8664 - amd64
3943304.3124: Timestamp: 0x558ddbf8
3953304.3124: Image Version: 0.0
3963304.3124: SizeOfImage: 0xd0880 (854144)
3973304.3124: Resource Dir: 0xcd980 LB 0x758
3983304.3124: ProductName: SYSCORE
3993304.3124: ProductVersion: 15.4.0.674
4003304.3124: FileVersion: SYSCORE.15.4.0.674
4013304.3124: PrivateBuild: SYSCORE.15.4.0.674 F14,F15,F16,F18,F20
4023304.3124: FileDescription: McAfee Link Driver
4033304.3124: \SystemRoot\System32\drivers\mfewfpk.sys:
4043304.3124: CreationTime: 2014-08-27T13:53:16.103804500Z
4053304.3124: LastWriteTime: 2015-10-26T20:57:27.817908000Z
4063304.3124: ChangeTime: 2015-10-26T20:57:27.817908000Z
4073304.3124: FileAttributes: 0x20
4083304.3124: Size: 0x54280
4093304.3124: NT Headers: 0x100
4103304.3124: Timestamp: 0x558ddc06
4113304.3124: Machine: 0x8664 - amd64
4123304.3124: Timestamp: 0x558ddc06
4133304.3124: Image Version: 0.0
4143304.3124: SizeOfImage: 0x4f980 (326016)
4153304.3124: Resource Dir: 0x4ef00 LB 0x380
4163304.3124: ProductName: SYSCORE
4173304.3124: ProductVersion: 15.4.0.674
4183304.3124: FileVersion: SYSCORE.15.4.0.674
4193304.3124: PrivateBuild: SYSCORE.15.4.0.674 F17,F18
4203304.3124: FileDescription: Anti-Virus Mini-Firewall Driver
4213304.3124: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
4223304.3124: Calling main()
4233304.3124: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4243304.3124: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
4253304.3124: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4263304.3124: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4273304.3124: SUPR3HardenedMain: Respawn #2
4283304.3124: supR3HardNtEnableThreadCreation:
4293304.3124: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\apphelp.dll)
4303304.3124: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\apphelp.dll
4313304.3124: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
4323304.3124: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4333304.3124: supR3HardenedDllNotificationCallback: load 000007fefc7f0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
4343304.3124: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4353304.3124: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc7f0000 'C:\Windows\system32\apphelp.dll'
4363304.3124: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076cdb630 pvNtTerminateThread=0000000076cfdee0
4373304.3124: supR3HardenedWinDoReSpawn(2): New child 3a60.288c [kernel32].
4383304.3124: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd9000 cbPeb=0x380
4393304.3124: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000076cb0000 uNtDllChildAddr=0000000076cb0000
4403304.3124: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000076cdb630
4413304.3124: supR3HardenedWinSetupChildInit: Start child.
4423304.3124: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
4433304.3124: supR3HardNtChildPurify: Startup delay kludge #1/0: 525 ms, 53 sleeps
4443304.3124: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4453304.3124: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
4463304.3124: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
4473304.3124: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
4483304.3124: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
4493304.3124: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
4503304.3124: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
4513304.3124: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
4523304.3124: 0000000000051000-fffffffffffa1fff 0x0001/0x0000 0x0000000
4533304.3124: *0000000000100000-0000000000003fff 0x0000/0x0004 0x0020000
4543304.3124: 00000000001fc000-00000000001f8fff 0x0104/0x0004 0x0020000
4553304.3124: 00000000001ff000-00000000001fdfff 0x0004/0x0004 0x0020000
4563304.3124: 0000000000200000-ffffffff8974ffff 0x0001/0x0000 0x0000000
4573304.3124: *0000000076cb0000-0000000076cb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4583304.3124: 0000000076cb1000-0000000076daefff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4593304.3124: 0000000076daf000-0000000076dddfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4603304.3124: 0000000076dde000-0000000076de5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4613304.3124: 0000000076de6000-0000000076de6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4623304.3124: 0000000076de7000-0000000076de9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4633304.3124: 0000000076dea000-0000000076e58fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
4643304.3124: 0000000076e59000-000000006ecd1fff 0x0001/0x0000 0x0000000
4653304.3124: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
4663304.3124: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4673304.3124: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
4683304.3124: 000000007fff0000-ffffffffc077ffff 0x0001/0x0000 0x0000000
4693304.3124: *000000013f860000-000000013f860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4703304.3124: 000000013f861000-000000013f8e7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4713304.3124: 000000013f8e8000-000000013f8e8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4723304.3124: 000000013f8e9000-000000013f933fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4733304.3124: 000000013f934000-000000013f934fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4743304.3124: 000000013f935000-000000013f935fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4753304.3124: 000000013f936000-000000013f93afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4763304.3124: 000000013f93b000-000000013f93bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4773304.3124: 000000013f93c000-000000013f93cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4783304.3124: 000000013f93d000-000000013f940fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4793304.3124: 000000013f941000-000000013f98bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
4803304.3124: 000000013f98c000-fffff80380347fff 0x0001/0x0000 0x0000000
4813304.3124: *000007fefefd0000-000007fefefd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
4823304.3124: 000007fefefd1000-000007fdfdff1fff 0x0001/0x0000 0x0000000
4833304.3124: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
4843304.3124: 000007fffffd3000-000007fffffccfff 0x0001/0x0000 0x0000000
4853304.3124: *000007fffffd9000-000007fffffd7fff 0x0004/0x0004 0x0020000
4863304.3124: 000007fffffda000-000007fffffd5fff 0x0001/0x0000 0x0000000
4873304.3124: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
4883304.3124: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
4893304.3124: apisetschema.dll: timestamp 0x562590e2 (rc=VINF_SUCCESS)
4903304.3124: VirtualBox.exe: timestamp 0x569e6712 (rc=VINF_SUCCESS)
4913304.3124: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4923304.3124: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
4933304.3124: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
4943304.3124: supR3HardNtChildPurify: Done after 572 ms and 0 fixes (loop #0).
4953304.3124: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000300000 LB 0x400000)
4963304.3124: supR3HardNtEnableThreadCreation:
4973a60.288c: Log file opened: 5.0.14r105127 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
4983a60.288c: supR3HardenedVmProcessInit: uNtDllAddr=0000000076cb0000
4993a60.288c: ntdll.dll: timestamp 0x56259295 (rc=VINF_SUCCESS)
5003a60.288c: New simple heap: #1 0000000000300000 LB 0x400000 (for 1740800 allocation)
5013a60.288c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
5023a60.288c: System32: \Device\HarddiskVolume1\Windows\System32
5033a60.288c: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
5043a60.288c: KnownDllPath: C:\Windows\system32
5053a60.288c: supR3HardenedVmProcessInit: Opening vboxdrv...
5063a60.288c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
5073a60.288c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
5083a60.288c: Registered Dll notification callback with NTDLL.
5093a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
5103a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
5113a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
5123a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5133a60.288c: supR3HardenedDllNotificationCallback: load 0000000076b90000 LB 0x00120000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
5143a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5153a60.288c: supR3HardenedDllNotificationCallback: load 000007fefcd90000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
5163a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
5173a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
5183a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b90000 'C:\Windows\system32\kernel32.dll'
5193a60.288c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076cdb630 pvNtTerminateThread=0000000076cfdee0
5203304.3124: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 46 ms.
5213a60.288c: \SystemRoot\System32\ntdll.dll:
5223a60.288c: CreationTime: 2016-01-05T15:15:33.635876900Z
5233a60.288c: LastWriteTime: 2015-10-20T01:09:05.164170200Z
5243a60.288c: ChangeTime: 2016-01-05T23:14:24.453534400Z
5253a60.288c: FileAttributes: 0x20
5263a60.288c: Size: 0x1a67c0
5273a60.288c: NT Headers: 0xe0
5283a60.288c: Timestamp: 0x56259295
5293a60.288c: Machine: 0x8664 - amd64
5303a60.288c: Timestamp: 0x56259295
5313a60.288c: Image Version: 6.1
5323a60.288c: SizeOfImage: 0x1a9000 (1740800)
5333a60.288c: Resource Dir: 0x14d000 LB 0x5a028
5343a60.288c: ProductName: Microsoft® Windows® Operating System
5353a60.288c: ProductVersion: 6.1.7601.19045
5363a60.288c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
5373a60.288c: FileDescription: NT Layer DLL
5383a60.288c: \SystemRoot\System32\kernel32.dll:
5393a60.288c: CreationTime: 2016-01-05T15:15:33.089890900Z
5403a60.288c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
5413a60.288c: ChangeTime: 2016-01-05T23:14:25.077514400Z
5423a60.288c: FileAttributes: 0x20
5433a60.288c: Size: 0x11c600
5443a60.288c: NT Headers: 0xe8
5453a60.288c: Timestamp: 0x56259270
5463a60.288c: Machine: 0x8664 - amd64
5473a60.288c: Timestamp: 0x56259270
5483a60.288c: Image Version: 6.1
5493a60.288c: SizeOfImage: 0x120000 (1179648)
5503a60.288c: Resource Dir: 0x117000 LB 0x528
5513a60.288c: ProductName: Microsoft® Windows® Operating System
5523a60.288c: ProductVersion: 6.1.7601.19045
5533a60.288c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
5543a60.288c: FileDescription: Windows NT BASE API Client DLL
5553a60.288c: \SystemRoot\System32\KernelBase.dll:
5563a60.288c: CreationTime: 2016-01-05T15:15:36.615400500Z
5573a60.288c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
5583a60.288c: ChangeTime: 2016-01-05T23:14:25.093113900Z
5593a60.288c: FileAttributes: 0x20
5603a60.288c: Size: 0x67c00
5613a60.288c: NT Headers: 0xe8
5623a60.288c: Timestamp: 0x56259271
5633a60.288c: Machine: 0x8664 - amd64
5643a60.288c: Timestamp: 0x56259271
5653a60.288c: Image Version: 6.1
5663a60.288c: SizeOfImage: 0x6c000 (442368)
5673a60.288c: Resource Dir: 0x6a000 LB 0x530
5683a60.288c: ProductName: Microsoft® Windows® Operating System
5693a60.288c: ProductVersion: 6.1.7601.19045
5703a60.288c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
5713a60.288c: FileDescription: Windows NT BASE API Client DLL
5723a60.288c: \SystemRoot\System32\apisetschema.dll:
5733a60.288c: CreationTime: 2016-01-05T15:15:41.841266500Z
5743a60.288c: LastWriteTime: 2015-10-20T00:53:47.280000000Z
5753a60.288c: ChangeTime: 2016-01-05T23:14:24.079146400Z
5763a60.288c: FileAttributes: 0x20
5773a60.288c: Size: 0x1a00
5783a60.288c: NT Headers: 0xc0
5793a60.288c: Timestamp: 0x562590e2
5803a60.288c: Machine: 0x8664 - amd64
5813a60.288c: Timestamp: 0x562590e2
5823a60.288c: Image Version: 6.1
5833a60.288c: SizeOfImage: 0x50000 (327680)
5843a60.288c: Resource Dir: 0x30000 LB 0x3f8
5853a60.288c: ProductName: Microsoft® Windows® Operating System
5863a60.288c: ProductVersion: 6.1.7601.19045
5873a60.288c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
5883a60.288c: FileDescription: ApiSet Schema DLL
5893a60.288c: Found driver mfewfpk (0x20)
5903a60.288c: Found driver mfehidk (0x20)
5913a60.288c: Found driver mfeavfk (0x20)
5923a60.288c: Found driver mfefirek (0x20)
5933a60.288c: supR3HardenedWinFindAdversaries: 0x20
5943a60.288c: \SystemRoot\System32\drivers\mfeapfk.sys:
5953a60.288c: CreationTime: 2014-08-27T13:53:23.447070100Z
5963a60.288c: LastWriteTime: 2014-08-27T13:53:11.606254300Z
5973a60.288c: ChangeTime: 2015-08-26T11:18:34.144626700Z
5983a60.288c: FileAttributes: 0x20
5993a60.288c: Size: 0x2c030
6003a60.288c: NT Headers: 0xe8
6013a60.288c: Timestamp: 0x52ab7fef
6023a60.288c: Machine: 0x8664 - amd64
6033a60.288c: Timestamp: 0x52ab7fef
6043a60.288c: Image Version: 0.0
6053a60.288c: SizeOfImage: 0x29d00 (171264)
6063a60.288c: Resource Dir: 0x29500 LB 0x340
6073a60.288c: ProductName: SYSCORE
6083a60.288c: FileVersion: SYSCORE.15.1.0.656
6093a60.288c: PrivateBuild: SYSCORE.15.1.0.656 F16
6103a60.288c: FileDescription: Access Protection Filter Driver
6113a60.288c: \SystemRoot\System32\drivers\mfeavfk.sys:
6123a60.288c: CreationTime: 2014-08-27T13:53:23.326082200Z
6133a60.288c: LastWriteTime: 2015-10-22T18:41:49.066172200Z
6143a60.288c: ChangeTime: 2015-10-22T18:41:59.236070500Z
6153a60.288c: FileAttributes: 0x20
6163a60.288c: Size: 0x54e98
6173a60.288c: NT Headers: 0xf8
6183a60.288c: Timestamp: 0x558ddc3c
6193a60.288c: Machine: 0x8664 - amd64
6203a60.288c: Timestamp: 0x558ddc3c
6213a60.288c: Image Version: 0.0
6223a60.288c: SizeOfImage: 0x50580 (329088)
6233a60.288c: Resource Dir: 0x4f700 LB 0x758
6243a60.288c: ProductName: SYSCORE
6253a60.288c: ProductVersion: 15.4.0.674
6263a60.288c: FileVersion: SYSCORE.15.4.0.674
6273a60.288c: PrivateBuild: SYSCORE.15.4.0.674 F15,F16,F19
6283a60.288c: FileDescription: Anti-Virus File System Filter Driver
6293a60.288c: \SystemRoot\System32\drivers\mfefirek.sys:
6303a60.288c: CreationTime: 2015-10-26T20:59:00.916917600Z
6313a60.288c: LastWriteTime: 2015-10-26T20:57:28.083102900Z
6323a60.288c: ChangeTime: 2015-10-26T20:57:28.083102900Z
6333a60.288c: FileAttributes: 0x20
6343a60.288c: Size: 0x794f8
6353a60.288c: NT Headers: 0xe8
6363a60.288c: Timestamp: 0x558ddc7b
6373a60.288c: Machine: 0x8664 - amd64
6383a60.288c: Timestamp: 0x558ddc7b
6393a60.288c: Image Version: 0.0
6403a60.288c: SizeOfImage: 0x74880 (477312)
6413a60.288c: Resource Dir: 0x72000 LB 0x388
6423a60.288c: ProductName: SYSCORE
6433a60.288c: ProductVersion: 15.4.0.674
6443a60.288c: FileVersion: SYSCORE.15.4.0.674
6453a60.288c: PrivateBuild: SYSCORE.15.4.0.674 F17,F18
6463a60.288c: FileDescription: McAfee Core Firewall Engine Driver
6473a60.288c: \SystemRoot\System32\drivers\mfehidk.sys:
6483a60.288c: CreationTime: 2014-08-27T13:53:22.847130100Z
6493a60.288c: LastWriteTime: 2015-10-22T18:41:49.016172700Z
6503a60.288c: ChangeTime: 2015-10-22T18:41:49.016172700Z
6513a60.288c: FileAttributes: 0x20
6523a60.288c: Size: 0xd5d98
6533a60.288c: NT Headers: 0x108
6543a60.288c: Timestamp: 0x558ddbf8
6553a60.288c: Machine: 0x8664 - amd64
6563a60.288c: Timestamp: 0x558ddbf8
6573a60.288c: Image Version: 0.0
6583a60.288c: SizeOfImage: 0xd0880 (854144)
6593a60.288c: Resource Dir: 0xcd980 LB 0x758
6603a60.288c: ProductName: SYSCORE
6613a60.288c: ProductVersion: 15.4.0.674
6623a60.288c: FileVersion: SYSCORE.15.4.0.674
6633a60.288c: PrivateBuild: SYSCORE.15.4.0.674 F14,F15,F16,F18,F20
6643a60.288c: FileDescription: McAfee Link Driver
6653a60.288c: \SystemRoot\System32\drivers\mfewfpk.sys:
6663a60.288c: CreationTime: 2014-08-27T13:53:16.103804500Z
6673a60.288c: LastWriteTime: 2015-10-26T20:57:27.817908000Z
6683a60.288c: ChangeTime: 2015-10-26T20:57:27.817908000Z
6693a60.288c: FileAttributes: 0x20
6703a60.288c: Size: 0x54280
6713a60.288c: NT Headers: 0x100
6723a60.288c: Timestamp: 0x558ddc06
6733a60.288c: Machine: 0x8664 - amd64
6743a60.288c: Timestamp: 0x558ddc06
6753a60.288c: Image Version: 0.0
6763a60.288c: SizeOfImage: 0x4f980 (326016)
6773a60.288c: Resource Dir: 0x4ef00 LB 0x380
6783a60.288c: ProductName: SYSCORE
6793a60.288c: ProductVersion: 15.4.0.674
6803a60.288c: FileVersion: SYSCORE.15.4.0.674
6813a60.288c: PrivateBuild: SYSCORE.15.4.0.674 F17,F18
6823a60.288c: FileDescription: Anti-Virus Mini-Firewall Driver
6833a60.288c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
6843a60.288c: Calling main()
6853a60.288c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
6863a60.288c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
6873a60.288c: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
6883a60.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
6893a60.288c: SUPR3HardenedMain: Final process, opening VBoxDrv...
6903a60.288c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000300000 LB 0x400000)
6913a60.288c: supR3HardNtEnableThreadCreation:
6923a60.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
6933a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
6943a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000795640:C:\Windows\system32 [calling]
6953a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6963a60.288c: supR3HardenedDllNotificationCallback: load 000007fef8220000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
6973a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6983a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6993a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
7003a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8220000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
7013a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
7023a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
7033a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8220000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
7043a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8220000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
7053a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7063a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
7073a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
7083a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
7093a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\wintrust.dll)
7103a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wintrust.dll
7113a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7123a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7133a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll)
7143a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
7153a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
7163a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
7173a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msasn1.dll)
7183a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msasn1.dll
7193a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
7203a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
7213a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7223a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
7233a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\crypt32.dll)
7243a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\crypt32.dll
7253a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7263a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7273a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msvcrt.dll)
7283a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
7293a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
7303a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
7313a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
7323a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7333a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7343a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7353a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000795640:C:\Windows\system32 [calling]
7363a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
7373a60.288c: supR3HardenedDllNotificationCallback: load 000007fefcd20000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
7383a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
7393a60.288c: supR3HardenedDllNotificationCallback: load 000007fefce90000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
7403a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7413a60.288c: supR3HardenedDllNotificationCallback: load 000007fefcb50000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
7423a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7433a60.288c: supR3HardenedDllNotificationCallback: load 000007fefca60000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
7443a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
7453a60.288c: supR3HardenedDllNotificationCallback: load 000007fefdbb0000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
7463a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7473a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcd20000 'C:\Windows\system32\Wintrust.dll'
7483a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\bcrypt.dll)
7493a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcrypt.dll
7503a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000080b490:C:\Windows\system32 [calling]
7513a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7523a60.288c: supR3HardenedDllNotificationCallback: load 000007fefc340000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
7533a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7543a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc340000 'C:\Windows\system32\bcrypt.dll'
7553a60.288c: bcrypt.dll loaded at 000007fefc340000, BCryptOpenAlgorithmProvider at 000007fefc342640, preloading providers:
7563a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
7573a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
7583a60.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll)
7593a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll
7603a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
7613a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
7623a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7633a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
7643a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
7653a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7663a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
7673a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\advapi32.dll)
7683a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\advapi32.dll
7693a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7703a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7713a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7723a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7733a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7743a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7753a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
7763a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
7773a60.288c: supR3HardenedDllNotificationCallback: load 000007fefbde0000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
7783a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
7793a60.288c: supR3HardenedDllNotificationCallback: load 000007fefea70000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
7803a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
7813a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
7823a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
7833a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\sechost.dll)
7843a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\sechost.dll
7853a60.288c: supR3HardenedDllNotificationCallback: load 000007fefdb70000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
7863a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\sechost.dll [lacks WinVerifyTrust]
7873a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbde0000 'C:\Windows\system32\bcryptprimitives.dll'
7883a60.288c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000080cb70)
7893a60.288c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000080fa30)
7903a60.288c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000080fb50)
7913a60.288c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000080fd60)
7923a60.288c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000080fe80)
7933a60.288c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000080ffa0)
7943a60.288c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000008101e0)
7953a60.288c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000810300)
7963a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptsp.dll)
7973a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
7983a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7993a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8003a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8013a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8023a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8033a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8043a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
8053a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
8063a60.288c: supR3HardenedDllNotificationCallback: load 000007fefc1f0000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
8073a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
8083a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc1f0000 'C:\Windows\system32\CRYPTSP.dll'
8093a60.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8103a60.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\rsaenh.dll)
8113a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rsaenh.dll
8123a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8133a60.288c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8143a60.288c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8153a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
8163a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8173a60.288c: supR3HardenedDllNotificationCallback: load 000007fefbef0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
8183a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8193a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbef0000 'C:\Windows\system32\rsaenh.dll'
8203a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
8213a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
8223a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea70000 'C:\Windows\system32\ADVAPI32.dll'
8233a60.288c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptbase.dll)
8243a60.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
8253a60.288c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007965d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files (x86)\ActivIdentity\ActivClient\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio\;c:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files\Microsoft SQL Server\110\Tools\Binn\;c:\Program Files (x86)\Microsoft SQL Server\110\DTS\Binn\;C:\Program Files (x86)\Google\Chrome\Application;C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services;C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Online Services;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\TortoiseGit\bin;C:\Program Files\TortoiseSVN\bin;C:\Users\574790\AppData\Local\Programs\Git\cmd [calling]
8263a60.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
8273a60.288c: supR3HardenedDllNotificationCallback: load 000007fefc850000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
8283a60.288c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
8293a60.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc850000 'C:\Windows\system32\CRYPTBASE.dll'
8303a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'rpcrt4.dll'.
8313a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'version.dll'.
8323a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
8333a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
8343a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
8353a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shlwapi.dll'.
8363a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'userenv.dll'.
8373a60.3424: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\privman64.dll)
8383a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\privman64.dll
8393a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
8403a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume1\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
8413a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8423a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
8433a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
8443a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\userenv.dll)
8453a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\userenv.dll
8463a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
8473a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
8483a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
8493a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
8503a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
8513a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\shlwapi.dll)
8523a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
8533a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
8543a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
8553a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8563a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
8573a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
8583a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
8593a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\shell32.dll)
8603a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shell32.dll
8613a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
8623a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
8633a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
8643a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
8653a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
8663a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
8673a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\user32.dll)
8683a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\user32.dll
8693a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
8703a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume1\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
8713a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
8723a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\version.dll)
8733a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\version.dll
8743a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8753a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8763a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8773a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8783a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8793a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8803a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8813a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8823a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
8833a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
8843a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gdi32.dll)
8853a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gdi32.dll
8863a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8873a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8883a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
8893a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
8903a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
8913a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
8923a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
8933a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
8943a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
8953a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8963a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8973a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8983a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8993a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9003a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9013a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
9023a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
9033a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
9043a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
9053a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
9063a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
9073a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
9083a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
9093a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9103a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\profapi.dll)
9113a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\profapi.dll
9123a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9133a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9143a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9153a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9163a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9173a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9183a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9193a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9203a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9213a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
9223a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume1\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
9233a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
9243a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
9253a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
9263a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\lpk.dll)
9273a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\lpk.dll
9283a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
9293a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
9303a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
9313a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
9323a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume1\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
9333a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9343a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
9353a60.3424: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
9363a60.3424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\usp10.dll)
9373a60.3424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\usp10.dll
9383a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
9393a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
9403a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
9413a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
9423a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
9433a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
9443a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
9453a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
9463a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
9473a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
9483a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
9493a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
9503a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9513a60.3424: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9523a60.3424: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9533a60.3424: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\privman64.dll (Input=privman64.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
9543a60.3424: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\privman64.dll [lacks WinVerifyTrust]
9553a60.3424: supR3HardenedDllNotificationCallback: load 000007fefc890000 LB 0x0002d000 C:\Windows\system32\privman64.dll [fFlags=0x0]
9563a60.3424: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\privman64.dll [lacks WinVerifyTrust]
9573304.3124: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 47 ms, the end);
95837a0.3ff8: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 688 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette