1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86
| 136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa580000 'C:\Windows\system32\msacm32.drv'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa580000 'C:\Windows\system32\msacm32.drv'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa580000 'C:\Windows\system32\msacm32.drv'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa580000 'C:\Windows\system32\msacm32.drv'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa580000 'C:\Windows\system32\msacm32.drv'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa580000 'C:\Windows\system32\msacm32.drv'
136c.132c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f50 pwszName=\Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006baf10
136c.132c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006baf10
136c.132c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43116C5C719A4751DA70B12932084D73D7AACEA3
136c.132c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\midimap.dll'
136c.132c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
136c.132c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
136c.132c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
136c.132c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
136c.132c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\midimap.dll)WinVerifyTrust
136c.132c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
136c.132c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
136c.132c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
136c.132c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
136c.132c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
136c.132c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardenedDllNotificationCallback: load 000007fefa480000 LB 0x00009000 C:\Windows\system32\midimap.dll [fFlags=0x0]
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa480000 'C:\Windows\system32\midimap.dll'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa480000 'C:\Windows\system32\midimap.dll'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa480000 'C:\Windows\system32\midimap.dll'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa480000 'C:\Windows\system32\midimap.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff220000 'C:\Windows\system32\ole32.dll'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa650000 'C:\Windows\system32\winmm.dll'
136c.1250: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe0c0000 'C:\Windows\system32\OLEAUT32.dll'
136c.11ec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
136c.11ec: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\audioses.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006c0640:C:\Windows\System32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.11ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa590000 'C:\Windows\System32\audioses.dll'
136c.132c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004d39fa0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
136c.132c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
136c.132c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076f00000 'C:\Windows\system32/kernel32.dll'
136c.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe490000 'C:\Windows\system32\shell32.dll'
136c.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe490000 'C:\Windows\system32\shell32.dll'
136c.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe490000 'C:\Windows\system32\shell32.dll'
136c.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe490000 'C:\Windows\system32\shell32.dll'
136c.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe490000 'C:\Windows\system32\shell32.dll'
136c.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe490000 'C:\Windows\system32\shell32.dll'
136c.1278: supR3HardenedDllNotificationCallback: Unload 000007fef5400000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
136c.9e4: supR3HardenedDllNotificationCallback: Unload 000007fef5f90000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
136c.1080: supR3HardenedDllNotificationCallback: Unload 000007fef5fa0000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
136c.57c: supR3HardenedDllNotificationCallback: Unload 000007fef5fb0000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
136c.d2c: supR3HardenedDllNotificationCallback: Unload 000007fef60a0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
136c.132c: supR3HardenedDllNotificationCallback: Unload 000007feea8f0000 LB 0x008d1000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
136c.132c: supR3HardenedDllNotificationCallback: Unload 000007fef5420000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
136c.132c: supR3HardenedDllNotificationCallback: Unload 000007fef0730000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
136c.132c: supR3HardenedDllNotificationCallback: Unload 000007fef07a0000 LB 0x00051000 C:\Windows\system32\newdev.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007fef8250000 LB 0x00084000 C:\Windows\system32\netcfgx.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007fef73b0000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007fef7300000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007fef6e10000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007fef72f0000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007fef7530000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [flags=0x0]
136c.80c: supR3HardenedDllNotificationCallback: Unload 000007feed540000 LB 0x004f8000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
136c.80c: Terminating the normal way: rcExit=0
1198.1290: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 126447 ms, the end);
1090.f10: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 127290 ms, the end); |
Partager