好久没用的eNSP软件今天想打开条两条命令做一个拓扑配置一下,结果重新安装了软件之后打开AR弹出错误显示:错误:代码40
我百度了一下ensp代码40怎么处理,根据资料我认为VirtualBox版本不支持,在ensp手册上看到VirtualBox版本应大于5.1,排除版本原因。后面我把ensp和VirtualBox两个软件同事卸载了,然后装上5.1版本VirtualBox随后装上ensp软件。接下来打开软件同样出现错误代码:40。又打开VirtualBox软件启动了AR_Base出现报错(错误如下)
不能为虚拟电脑 AR_Base 打开一个新任务.
The virtual machine ‘AR_Base’ has terminated unexpectedly during startup with exit code 1 (0x1). More details may be available in ‘D:\软件\eNSP\eNPS\eNSP\VBoxServer\AR_Base\Logs\VBoxHardening.log’.
返回 代码:E_FAIL (0x80004005)
组件:MachineWrap
界面:IMachine {b2547866-a0a1-4391-8b86-6952d82efaa0}
我根据提示打开文档VBoxHardening.log’打开后全是代码(表示看不懂)代码如下:
**
## 跪求那位大神能帮助查找原因
**
1d38.16bc: Log file opened: 5.1.0r108711 g_hStartupLog=0000000000000090 g_uNtVerCombined=0xa047ba00
1d38.16bc: \SystemRoot\System32\ntdll.dll:
1d38.16bc: CreationTime: 2019-10-26T08:53:05.572934700Z
1d38.16bc: LastWriteTime: 2019-10-26T08:53:05.635435200Z
1d38.16bc: ChangeTime: 2019-11-15T14:27:10.483874700Z
1d38.16bc: FileAttributes: 0x20
1d38.16bc: Size: 0x1e8528
1d38.16bc: NT Headers: 0xd8
1d38.16bc: Timestamp: 0x99ca0526
1d38.16bc: Machine: 0x8664 - amd64
1d38.16bc: Timestamp: 0x99ca0526
1d38.16bc: Image Version: 10.0
1d38.16bc: SizeOfImage: 0x1f0000 (2031616)
1d38.16bc: Resource Dir: 0x17f000 LB 0x6f310
1d38.16bc: ProductName: Microsoft® Windows® Operating System
1d38.16bc: ProductVersion: 10.0.18362.418
1d38.16bc: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
1d38.16bc: FileDescription: NT Layer DLL
1d38.16bc: \SystemRoot\System32\kernel32.dll:
1d38.16bc: CreationTime: 2019-10-26T08:52:33.246997700Z
1d38.16bc: LastWriteTime: 2019-10-26T08:52:33.262624300Z
1d38.16bc: ChangeTime: 2019-11-15T14:27:09.643602700Z
1d38.16bc: FileAttributes: 0x20
1d38.16bc: Size: 0xb0570
1d38.16bc: NT Headers: 0xe8
1d38.16bc: Timestamp: 0xd0cecc10
1d38.16bc: Machine: 0x8664 - amd64
1d38.16bc: Timestamp: 0xd0cecc10
1d38.16bc: Image Version: 10.0
1d38.16bc: SizeOfImage: 0xb2000 (729088)
1d38.16bc: Resource Dir: 0xb0000 LB 0x520
1d38.16bc: ProductName: Microsoft® Windows® Operating System
1d38.16bc: ProductVersion: 10.0.18362.329
1d38.16bc: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
1d38.16bc: FileDescription: Windows NT BASE API Client DLL
1d38.16bc: \SystemRoot\System32\KernelBase.dll:
1d38.16bc: CreationTime: 2019-11-15T14:25:55.854190800Z
1d38.16bc: LastWriteTime: 2019-11-15T14:25:55.998962500Z
1d38.16bc: ChangeTime: 2019-11-20T06:47:46.678002000Z
1d38.16bc: FileAttributes: 0x20
1d38.16bc: Size: 0x2a2908
1d38.16bc: NT Headers: 0xf0
1d38.16bc: Timestamp: 0x83c3d83a
1d38.16bc: Machine: 0x8664 - amd64
1d38.16bc: Timestamp: 0x83c3d83a
1d38.16bc: Image Version: 10.0
1d38.16bc: SizeOfImage: 0x2a3000 (2764800)
1d38.16bc: Resource Dir: 0x27d000 LB 0x548
1d38.16bc: ProductName: Microsoft® Windows® Operating System
1d38.16bc: ProductVersion: 10.0.18362.476
1d38.16bc: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
1d38.16bc: FileDescription: Windows NT BASE API Client DLL
1d38.16bc: \SystemRoot\System32\apisetschema.dll:
1d38.16bc: CreationTime: 2019-03-19T04:43:54.837151500Z
1d38.16bc: LastWriteTime: 2019-03-19T04:43:54.837151500Z
1d38.16bc: ChangeTime: 2019-11-15T14:27:09.583812000Z
1d38.16bc: FileAttributes: 0x20
1d38.16bc: Size: 0x1d028
1d38.16bc: NT Headers: 0xc8
1d38.16bc: Timestamp: 0xd6ced080
1d38.16bc: Machine: 0x8664 - amd64
1d38.16bc: Timestamp: 0xd6ced080
1d38.16bc: Image Version: 10.0
1d38.16bc: SizeOfImage: 0x1e000 (122880)
1d38.16bc: Resource Dir: 0x1d000 LB 0x408
1d38.16bc: ProductName: Microsoft® Windows® Operating System
1d38.16bc: ProductVersion: 10.0.18362.1
1d38.16bc: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
1d38.16bc: FileDescription: ApiSet Schema DLL
1d38.16bc: supR3HardenedWinFindAdversaries: 0x0
1d38.16bc: supR3HardenedWinInitAppBin(0x0): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
1d38.16bc: Calling main()
1d38.16bc: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1d38.16bc: supR3HardenedWinInitAppBin(0x2): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
1d38.16bc: SUPR3HardenedMain: Respawn #1
1d38.16bc: System32: \Device\HarddiskVolume3\Windows\System32
1d38.16bc: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
1d38.16bc: KnownDllPath: C:\WINDOWS\System32
1d38.16bc: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
1d38.16bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe)
1d38.16bc: supR3HardNtEnableThreadCreation:
1d38.16bc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9452317f0 pvNtTerminateThread=00007ff94525cb10
1d38.16bc: supR3HardenedWinDoReSpawn(1): New child 4b4.980 [kernel32].
1d38.16bc: supR3HardNtChildGatherData: PebBaseAddress=000000000076f000 cbPeb=0x388
1d38.16bc: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff9451c0000 uNtDllChildAddr=00007ff9451c0000
1d38.16bc: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9452317f0
1d38.16bc: supR3HardenedWinSetupChildInit: Start child.
1d38.16bc: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1d38.16bc: supR3HardNtChildPurify: Startup delay kludge #1/0: 257 ms, 29 sleeps
1d38.16bc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1d38.16bc: *0000000000000000-ffffffffffa1ffff 0x0001/0x0000 0x0000000
1d38.16bc: *00000000005e0000-00000000005bffff 0x0004/0x0004 0x0020000
1d38.16bc: *0000000000600000-0000000000490fff 0x0000/0x0004 0x0020000
1d38.16bc: 000000000076f000-000000000076bfff 0x0004/0x0004 0x0020000
1d38.16bc: 0000000000772000-00000000006e3fff 0x0000/0x0004 0x0020000
1d38.16bc: *0000000000800000-00000000007e4fff 0x0002/0x0002 0x0040000
1d38.16bc: 000000000081b000-0000000000815fff 0x0001/0x0000 0x0000000
1d38.16bc: *0000000000820000-0000000000724fff 0x0000/0x0004 0x0020000
1d38.16bc: 000000000091b000-0000000000917fff 0x0104/0x0004 0x0020000
1d38.16bc: 000000000091e000-000000000091bfff 0x0004/0x0004 0x0020000
1d38.16bc: *0000000000920000-000000000091bfff 0x0002/0x0002 0x0040000
1d38.16bc: 0000000000924000-0000000000917fff 0x0001/0x0000 0x0000000
1d38.16bc: *0000000000930000-000000000092dfff 0x0004/0x0004 0x0020000
1d38.16bc: 0000000000932000-ffffffff81283fff 0x0001/0x0000 0x0000000
1d38.16bc: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
1d38.16bc: 000000007ffe1000-000000007ffd8fff 0x0001/0x0000 0x0000000
1d38.16bc: *000000007ffe9000-000000007ffe7fff 0x0002/0x0002 0x0020000
1d38.16bc: 000000007ffea000-ffff800bbdb03fff 0x0001/0x0000 0x0000000
1d38.16bc: *00007ff5424d0000-00007ff5424cefff 0x0002/0x0002 0x0040000
1d38.16bc: 00007ff5424d1000-00007ff5424c1fff 0x0001/0x0000 0x0000000
1d38.16bc: *00007ff5424e0000-00007ff5424acfff 0x0002/0x0002 0x0040000
1d38.16bc: 00007ff542513000-00007ff2c5255fff 0x0001/0x0000 0x0000000
1d38.16bc: *00007ff7bf7d0000-00007ff7bf7d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf7d1000-00007ff7bf83ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf840000-00007ff7bf840fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf841000-00007ff7bf884fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf885000-00007ff7bf885fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf886000-00007ff7bf886fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf887000-00007ff7bf88bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf88c000-00007ff7bf88cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf88d000-00007ff7bf88dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf88e000-00007ff7bf891fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf892000-00007ff7bf8d9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
1d38.16bc: 00007ff7bf8da000-00007ff639ff3fff 0x0001/0x0000 0x0000000
1d38.16bc: *00007ff9451c0000-00007ff9451c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff9451c1000-00007ff9452d7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff9452d8000-00007ff94531efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff94531f000-00007ff94532afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff94532b000-00007ff945339fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff94533a000-00007ff94533afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff94533b000-00007ff94533dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff94533e000-00007ff9453affff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1d38.16bc: 00007ff9453b0000-00007ff28a76ffff 0x0001/0x0000 0x0000000
1d38.16bc: VirtualBox.exe: timestamp 0x57850418 (rc=VINF_SUCCESS)
1d38.16bc: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
1d38.16bc: ‘\Device\HarddiskVolume3\Windows\System32\ntdll.dll’ has no imports
1d38.16bc: supR3HardNtChildPurify: Done after 305 ms and 0 fixes (loop #0).
4b4.980: Log file opened: 5.1.0r108711 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047ba00
4b4.980: supR3HardenedVmProcessInit: uNtDllAddr=00007ff9451c0000 g_uNtVerCombined=0xa047ba00
4b4.980: ntdll.dll: timestamp 0x99ca0526 (rc=VINF_SUCCESS)
4b4.980: New simple heap: #1 0000000000a40000 LB 0x400000 (for 2031616 allocation)
1d38.16bc: supR3HardNtEnableThreadCreation:
4b4.980: supR3HardenedWinInitAppBin(0x0): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
4b4.980: System32: \Device\HarddiskVolume3\Windows\System32
4b4.980: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
4b4.980: KnownDllPath: C:\WINDOWS\System32
4b4.980: supR3HardenedVmProcessInit: Opening vboxdrv stub…
4b4.980: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk…
4b4.980: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk…
4b4.980: Registered Dll notification callback with NTDLL.
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
4b4.980: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001: [calling]
4b4.980: supR3HardenedDllNotificationCallback: load 00007ff942420000 LB 0x002a3000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
4b4.980: supR3HardenedDllNotificationCallback: load 00007ff944630000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
4b4.980: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
4b4.980: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff944630000 ‘C:\WINDOWS\System32\KERNEL32.DLL’
4b4.980: supR3HardenedDllNotificationCallback: load 00007ff7bf7d0000 LB 0x0010a000 D:\软件\eNSP\VirtualBox\VirtualBox.exe [fFlags=0x0]
4b4.980: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9452317f0 pvNtTerminateThread=00007ff94525cb10
1d38.16bc: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 76 ms.
4b4.980: \SystemRoot\System32\ntdll.dll:
4b4.980: CreationTime: 2019-10-26T08:53:05.572934700Z
4b4.980: LastWriteTime: 2019-10-26T08:53:05.635435200Z
4b4.980: ChangeTime: 2019-11-15T14:27:10.483874700Z
4b4.980: FileAttributes: 0x20
4b4.980: Size: 0x1e8528
4b4.980: NT Headers: 0xd8
4b4.980: Timestamp: 0x99ca0526
4b4.980: Machine: 0x8664 - amd64
4b4.980: Timestamp: 0x99ca0526
4b4.980: Image Version: 10.0
4b4.980: SizeOfImage: 0x1f0000 (2031616)
4b4.980: Resource Dir: 0x17f000 LB 0x6f310
4b4.980: ProductName: Microsoft® Windows® Operating System
4b4.980: ProductVersion: 10.0.18362.418
4b4.980: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
4b4.980: FileDescription: NT Layer DLL
4b4.980: \SystemRoot\System32\kernel32.dll:
4b4.980: CreationTime: 2019-10-26T08:52:33.246997700Z
4b4.980: LastWriteTime: 2019-10-26T08:52:33.262624300Z
4b4.980: ChangeTime: 2019-11-15T14:27:09.643602700Z
4b4.980: FileAttributes: 0x20
4b4.980: Size: 0xb0570
4b4.980: NT Headers: 0xe8
4b4.980: Timestamp: 0xd0cecc10
4b4.980: Machine: 0x8664 - amd64
4b4.980: Timestamp: 0xd0cecc10
4b4.980: Image Version: 10.0
4b4.980: SizeOfImage: 0xb2000 (729088)
4b4.980: Resource Dir: 0xb0000 LB 0x520
4b4.980: ProductName: Microsoft® Windows® Operating System
4b4.980: ProductVersion: 10.0.18362.329
4b4.980: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
4b4.980: FileDescription: Windows NT BASE API Client DLL
4b4.980: \SystemRoot\System32\KernelBase.dll:
4b4.980: CreationTime: 2019-11-15T14:25:55.854190800Z
4b4.980: LastWriteTime: 2019-11-15T14:25:55.998962500Z
4b4.980: ChangeTime: 2019-11-20T06:47:46.678002000Z
4b4.980: FileAttributes: 0x20
4b4.980: Size: 0x2a2908
4b4.980: NT Headers: 0xf0
4b4.980: Timestamp: 0x83c3d83a
4b4.980: Machine: 0x8664 - amd64
4b4.980: Timestamp: 0x83c3d83a
4b4.980: Image Version: 10.0
4b4.980: SizeOfImage: 0x2a3000 (2764800)
4b4.980: Resource Dir: 0x27d000 LB 0x548
4b4.980: ProductName: Microsoft® Windows® Operating System
4b4.980: ProductVersion: 10.0.18362.476
4b4.980: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
4b4.980: FileDescription: Windows NT BASE API Client DLL
4b4.980: \SystemRoot\System32\apisetschema.dll:
4b4.980: CreationTime: 2019-03-19T04:43:54.837151500Z
4b4.980: LastWriteTime: 2019-03-19T04:43:54.837151500Z
4b4.980: ChangeTime: 2019-11-15T14:27:09.583812000Z
4b4.980: FileAttributes: 0x20
4b4.980: Size: 0x1d028
4b4.980: NT Headers: 0xc8
4b4.980: Timestamp: 0xd6ced080
4b4.980: Machine: 0x8664 - amd64
4b4.980: Timestamp: 0xd6ced080
4b4.980: Image Version: 10.0
4b4.980: SizeOfImage: 0x1e000 (122880)
4b4.980: Resource Dir: 0x1d000 LB 0x408
4b4.980: ProductName: Microsoft® Windows® Operating System
4b4.980: ProductVersion: 10.0.18362.1
4b4.980: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
4b4.980: FileDescription: ApiSet Schema DLL
4b4.980: supR3HardenedWinFindAdversaries: 0x0
4b4.980: supR3HardenedWinInitAppBin(0x0): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
4b4.980: Calling main()
4b4.980: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4b4.980: supR3HardenedWinInitAppBin(0x2): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
4b4.980: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe)
4b4.980: SUPR3HardenedMain: Respawn #2
4b4.980: supR3HardNtEnableThreadCreation:
4b4.980: supR3HardenedDllNotificationCallback: load 00007ff944510000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
4b4.980: supR3HardenedDllNotificationCallback: load 00007ff943380000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
4b4.980: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 ‘rpcrt4.dll’.
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
4b4.980: ‘\Device\HarddiskVolume3\Windows\System32\ntdll.dll’ has no imports
4b4.980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘rpcrt4.dll’…
4b4.980: supR3HardenedWinVerifyCacheProcessImportTodos: ‘rpcrt4.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll’ [rcNtRedir=0xc0150008]
4b4.980: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4b4.980: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
4b4.980: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9451c0000 ‘C:\WINDOWS\System32\ntdll.dll’
4b4.980: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\apphelp.dll)
4b4.980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\apphelp.dll
4b4.980: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000: [calling]
4b4.980: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4b4.980: supR3HardenedDllNotificationCallback: load 00007ff940200000 LB 0x0008f000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
4b4.980: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4b4.980: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntdll.dll [lacks WinVerifyTrust]
4b4.980: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
4b4.980: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9451c0000 ‘C:\WINDOWS\System32\ntdll.dll’
4b4.980: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff940200000 ‘C:\WINDOWS\system32\apphelp.dll’
4b4.980: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9452317f0 pvNtTerminateThread=00007ff94525cb10
4b4.980: supR3HardenedWinDoReSpawn(2): New child 15dc.13f4 [kernel32].
4b4.980: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
4b4.980: supR3HardNtChildGatherData: PebBaseAddress=0000000000931000 cbPeb=0x388
4b4.980: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff9451c0000 uNtDllChildAddr=00007ff9451c0000
4b4.980: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9452317f0
4b4.980: supR3HardenedWinSetupChildInit: Start child.
4b4.980: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
4b4.980: supR3HardNtChildPurify: Startup delay kludge #1/0: 258 ms, 29 sleeps
4b4.980: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4b4.980: *0000000000000000-ffffffffff9cffff 0x0001/0x0000 0x0000000
4b4.980: *0000000000630000-000000000060ffff 0x0004/0x0004 0x0020000
4b4.980: *0000000000650000-0000000000634fff 0x0002/0x0002 0x0040000
4b4.980: 000000000066b000-0000000000665fff 0x0001/0x0000 0x0000000
4b4.980: *0000000000670000-0000000000574fff 0x0000/0x0004 0x0020000
4b4.980: 000000000076b000-0000000000767fff 0x0104/0x0004 0x0020000
4b4.980: 000000000076e000-000000000076bfff 0x0004/0x0004 0x0020000
4b4.980: *0000000000770000-000000000076bfff 0x0002/0x0002 0x0040000
4b4.980: 0000000000774000-0000000000767fff 0x0001/0x0000 0x0000000
4b4.980: *0000000000780000-000000000077dfff 0x0004/0x0004 0x0020000
4b4.980: 0000000000782000-0000000000703fff 0x0001/0x0000 0x0000000
4b4.980: *0000000000800000-00000000006cefff 0x0000/0x0004 0x0020000
4b4.980: 0000000000931000-000000000092dfff 0x0004/0x0004 0x0020000
4b4.980: 0000000000934000-0000000000867fff 0x0000/0x0004 0x0020000
4b4.980: 0000000000a00000-ffffffff8141ffff 0x0001/0x0000 0x0000000
4b4.980: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4b4.980: 000000007ffe1000-000000007ffd8fff 0x0001/0x0000 0x0000000
4b4.980: *000000007ffe9000-000000007ffe7fff 0x0002/0x0002 0x0020000
4b4.980: 000000007ffea000-ffff800b05f03fff 0x0001/0x0000 0x0000000
4b4.980: *00007ff5fa0d0000-00007ff5fa0cefff 0x0002/0x0002 0x0040000
4b4.980: 00007ff5fa0d1000-00007ff5fa0c1fff 0x0001/0x0000 0x0000000
4b4.980: *00007ff5fa0e0000-00007ff5fa0acfff 0x0002/0x0002 0x0040000
4b4.980: 00007ff5fa113000-00007ff434a55fff 0x0001/0x0000 0x0000000
4b4.980: *00007ff7bf7d0000-00007ff7bf7d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf7d1000-00007ff7bf83ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf840000-00007ff7bf840fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf841000-00007ff7bf884fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf885000-00007ff7bf885fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf886000-00007ff7bf886fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf887000-00007ff7bf88bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf88c000-00007ff7bf88cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf88d000-00007ff7bf88dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf88e000-00007ff7bf891fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf892000-00007ff7bf8d9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
4b4.980: 00007ff7bf8da000-00007ff639ff3fff 0x0001/0x0000 0x0000000
4b4.980: *00007ff9451c0000-00007ff9451c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff9451c1000-00007ff9452d7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff9452d8000-00007ff94531efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff94531f000-00007ff94532afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff94532b000-00007ff945339fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff94533a000-00007ff94533afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff94533b000-00007ff94533dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff94533e000-00007ff9453affff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4b4.980: 00007ff9453b0000-00007ff28a76ffff 0x0001/0x0000 0x0000000
4b4.980: VirtualBox.exe: timestamp 0x57850418 (rc=VINF_SUCCESS)
4b4.980: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
4b4.980: ‘\Device\HarddiskVolume3\Windows\System32\ntdll.dll’ has no imports
4b4.980: supR3HardNtChildPurify: Done after 293 ms and 0 fixes (loop #0).
4b4.980: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000a40000 LB 0x400000)
15dc.13f4: Log file opened: 5.1.0r108711 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047ba00
15dc.13f4: supR3HardenedVmProcessInit: uNtDllAddr=00007ff9451c0000 g_uNtVerCombined=0xa047ba00
4b4.980: supR3HardNtEnableThreadCreation:
15dc.13f4: ntdll.dll: timestamp 0x99ca0526 (rc=VINF_SUCCESS)
15dc.13f4: New simple heap: #1 0000000000b00000 LB 0x400000 (for 2031616 allocation)
15dc.13f4: supR3HardenedWinInitAppBin(0x0): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
15dc.13f4: System32: \Device\HarddiskVolume3\Windows\System32
15dc.13f4: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
15dc.13f4: KnownDllPath: C:\WINDOWS\System32
15dc.13f4: supR3HardenedVmProcessInit: Opening vboxdrv…
15dc.13f4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk…
15dc.13f4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk…
15dc.13f4: Registered Dll notification callback with NTDLL.
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001: [calling]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff942420000 LB 0x002a3000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff944630000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff944630000 ‘C:\WINDOWS\System32\KERNEL32.DLL’
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff7bf7d0000 LB 0x0010a000 D:\软件\eNSP\VirtualBox\VirtualBox.exe [fFlags=0x0]
15dc.13f4: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe
15dc.13f4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9452317f0 pvNtTerminateThread=00007ff94525cb10
4b4.980: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 91 ms.
15dc.13f4: \SystemRoot\System32\ntdll.dll:
15dc.13f4: CreationTime: 2019-10-26T08:53:05.572934700Z
15dc.13f4: LastWriteTime: 2019-10-26T08:53:05.635435200Z
15dc.13f4: ChangeTime: 2019-11-15T14:27:10.483874700Z
15dc.13f4: FileAttributes: 0x20
15dc.13f4: Size: 0x1e8528
15dc.13f4: NT Headers: 0xd8
15dc.13f4: Timestamp: 0x99ca0526
15dc.13f4: Machine: 0x8664 - amd64
15dc.13f4: Timestamp: 0x99ca0526
15dc.13f4: Image Version: 10.0
15dc.13f4: SizeOfImage: 0x1f0000 (2031616)
15dc.13f4: Resource Dir: 0x17f000 LB 0x6f310
15dc.13f4: ProductName: Microsoft® Windows® Operating System
15dc.13f4: ProductVersion: 10.0.18362.418
15dc.13f4: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
15dc.13f4: FileDescription: NT Layer DLL
15dc.13f4: \SystemRoot\System32\kernel32.dll:
15dc.13f4: CreationTime: 2019-10-26T08:52:33.246997700Z
15dc.13f4: LastWriteTime: 2019-10-26T08:52:33.262624300Z
15dc.13f4: ChangeTime: 2019-11-15T14:27:09.643602700Z
15dc.13f4: FileAttributes: 0x20
15dc.13f4: Size: 0xb0570
15dc.13f4: NT Headers: 0xe8
15dc.13f4: Timestamp: 0xd0cecc10
15dc.13f4: Machine: 0x8664 - amd64
15dc.13f4: Timestamp: 0xd0cecc10
15dc.13f4: Image Version: 10.0
15dc.13f4: SizeOfImage: 0xb2000 (729088)
15dc.13f4: Resource Dir: 0xb0000 LB 0x520
15dc.13f4: ProductName: Microsoft® Windows® Operating System
15dc.13f4: ProductVersion: 10.0.18362.329
15dc.13f4: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
15dc.13f4: FileDescription: Windows NT BASE API Client DLL
15dc.13f4: \SystemRoot\System32\KernelBase.dll:
15dc.13f4: CreationTime: 2019-11-15T14:25:55.854190800Z
15dc.13f4: LastWriteTime: 2019-11-15T14:25:55.998962500Z
15dc.13f4: ChangeTime: 2019-11-20T06:47:46.678002000Z
15dc.13f4: FileAttributes: 0x20
15dc.13f4: Size: 0x2a2908
15dc.13f4: NT Headers: 0xf0
15dc.13f4: Timestamp: 0x83c3d83a
15dc.13f4: Machine: 0x8664 - amd64
15dc.13f4: Timestamp: 0x83c3d83a
15dc.13f4: Image Version: 10.0
15dc.13f4: SizeOfImage: 0x2a3000 (2764800)
15dc.13f4: Resource Dir: 0x27d000 LB 0x548
15dc.13f4: ProductName: Microsoft® Windows® Operating System
15dc.13f4: ProductVersion: 10.0.18362.476
15dc.13f4: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
15dc.13f4: FileDescription: Windows NT BASE API Client DLL
15dc.13f4: \SystemRoot\System32\apisetschema.dll:
15dc.13f4: CreationTime: 2019-03-19T04:43:54.837151500Z
15dc.13f4: LastWriteTime: 2019-03-19T04:43:54.837151500Z
15dc.13f4: ChangeTime: 2019-11-15T14:27:09.583812000Z
15dc.13f4: FileAttributes: 0x20
15dc.13f4: Size: 0x1d028
15dc.13f4: NT Headers: 0xc8
15dc.13f4: Timestamp: 0xd6ced080
15dc.13f4: Machine: 0x8664 - amd64
15dc.13f4: Timestamp: 0xd6ced080
15dc.13f4: Image Version: 10.0
15dc.13f4: SizeOfImage: 0x1e000 (122880)
15dc.13f4: Resource Dir: 0x1d000 LB 0x408
15dc.13f4: ProductName: Microsoft® Windows® Operating System
15dc.13f4: ProductVersion: 10.0.18362.1
15dc.13f4: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
15dc.13f4: FileDescription: ApiSet Schema DLL
15dc.13f4: supR3HardenedWinFindAdversaries: 0x0
15dc.13f4: supR3HardenedWinInitAppBin(0x0): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
15dc.13f4: Calling main()
15dc.13f4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
15dc.13f4: supR3HardenedWinInitAppBin(0x2): ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox’
15dc.13f4: ‘\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe’ has no imports
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VirtualBox.exe)
15dc.13f4: SUPR3HardenedMain: Final process, opening VBoxDrv…
15dc.13f4: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000b00000 LB 0x400000)
15dc.13f4: supR3HardNtEnableThreadCreation:
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\软件\eNSP\VirtualBox\VBoxSupLib.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VBoxSupLib.dll
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff93edc0000 LB 0x00005000 D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff93edc0000 ‘D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL’
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\软件\eNSP\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff93edc0000 ‘D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL’
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff93edc0000 ‘D:\软件\eNSP\VirtualBox\VBoxSupLib.DLL’
15dc.13f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 ‘msvcrt.dll’.
15dc.13f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 ‘msasn1.dll’.
15dc.13f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 ‘crypt32.dll’.
15dc.13f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 ‘rpcrt4.dll’.
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘rpcrt4.dll’…
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: ‘rpcrt4.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll’ [rcNtRedir=0xc0150008]
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘crypt32.dll’…
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: ‘crypt32.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\crypt32.dll’ [rcNtRedir=0xc0150008]
15dc.13f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 ‘msasn1.dll’.
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘msasn1.dll’…
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: ‘msasn1.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\msasn1.dll’ [rcNtRedir=0xc0150008]
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘msvcrt.dll’…
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: ‘msvcrt.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\msvcrt.dll’ [rcNtRedir=0xc0150008]
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘msasn1.dll’…
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: ‘msasn1.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\msasn1.dll’ [rcNtRedir=0xc0150008]
15dc.13f4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff944d40000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff942110000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff942270000 LB 0x000fa000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ucrtbase.dll
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff942950000 LB 0x00149000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff944510000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff9428f0000 LB 0x0005c000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff942420000 ‘api-ms-win-core-synch-l1-2-0’
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff942420000 ‘api-ms-win-core-fibers-l1-1-1’
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff942420000 ‘api-ms-win-core-fibers-l1-1-1’
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff942420000 ‘api-ms-win-core-synch-l1-2-0’
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801: [calling]
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff942420000 ‘api-ms-win-core-localization-l1-2-1’
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9428f0000 ‘C:\WINDOWS\system32\Wintrust.dll’
15dc.13f4: supHardenedWinVerifyImageByHandle: -> -626 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
15dc.13f4: Error (rc=0):
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume3\Windows\System32\bcrypt.dll: Grown load config (192 to 264 bytes) includes non-zero bytes: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 ba 01 80 01 00 00 00 00 00 00 00 00 00 00 00
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
15dc.13f4: Error (rc=0):
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: rejecting ‘C:\WINDOWS\system32\bcrypt.dll’ (C:\WINDOWS\system32\bcrypt.dll): rcNt=0xc0000190
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 ‘C:\WINDOWS\system32\bcrypt.dll’
15dc.13f4: Warning! Failed to load bcrypt.dll
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff943250000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
15dc.13f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 ‘bcrypt.dll’.
15dc.13f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
15dc.13f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing ‘bcrypt.dll’…
15dc.13f4: supR3HardenedWinVerifyCacheProcessImportTodos: ‘bcrypt.dll’ -> ‘\Device\HarddiskVolume3\Windows\System32\bcrypt.dll’ [rcNtRedir=0xc0150008]
15dc.13f4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status -626 (0xfffffd8e)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
15dc.13f4: Error (rc=0):
15dc.13f4: supR3HardenedScreenImage/Imports: cached rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
15dc.13f4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001: [calling]
15dc.13f4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15dc.13f4: supR3HardenedDllNotificationCallback: load 00007ff942240000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -626 (0xfffffd8e)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
15dc.13f4: Error (rc=0):
15dc.13f4: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -626 (0xfffffd8e) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
15dc.13f4: Fatal error:
15dc.13f4: supR3HardenedDllNotificationCallback: supR3HardenedScreenImage failed on ‘C:\WINDOWS\System32\bcrypt.dll’ / ‘??\C:\WINDOWS\System32\bcrypt.dll’: 0xc0000190
4b4.980: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 81 ms, the end);
1d38.16bc: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 562 ms, the end);