2b34.1a70: Log file opened: 5.2.32r132073 g_hStartupLog=000000000000001c g_uNtVerCombined=0x611db110 2b34.1a70: \SystemRoot\System32\ntdll.dll: 2b34.1a70: CreationTime: 2019-06-22T05:24:09.202909900Z 2b34.1a70: LastWriteTime: 2019-05-16T15:08:29.092007100Z 2b34.1a70: ChangeTime: 2019-06-22T08:53:51.194029100Z 2b34.1a70: FileAttributes: 0x20 2b34.1a70: Size: 0x196560 2b34.1a70: NT Headers: 0xe0 2b34.1a70: Timestamp: 0x5cdd7d10 2b34.1a70: Machine: 0x8664 - amd64 2b34.1a70: Timestamp: 0x5cdd7d10 2b34.1a70: Image Version: 6.1 2b34.1a70: SizeOfImage: 0x19f000 (1699840) 2b34.1a70: Resource Dir: 0x142000 LB 0x5a028 2b34.1a70: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)] 2b34.1a70: [Raw version resource data: 0x1420f0 LB 0x380, codepage 0x0 (reserved 0x0)] 2b34.1a70: ProductName: Microsoft® Windows® Operating System 2b34.1a70: ProductVersion: 6.1.7601.24475 2b34.1a70: FileVersion: 6.1.7601.24475 (win7sp1_ldr.190516-0600) 2b34.1a70: FileDescription: NT Layer DLL 2b34.1a70: \SystemRoot\System32\kernel32.dll: 2b34.1a70: CreationTime: 2019-06-22T05:24:20.858630900Z 2b34.1a70: LastWriteTime: 2019-05-16T15:07:06.536000000Z 2b34.1a70: ChangeTime: 2019-06-22T08:53:55.569057100Z 2b34.1a70: FileAttributes: 0x20 2b34.1a70: Size: 0x11be00 2b34.1a70: NT Headers: 0xe0 2b34.1a70: Timestamp: 0x5cdd7d44 2b34.1a70: Machine: 0x8664 - amd64 2b34.1a70: Timestamp: 0x5cdd7d44 2b34.1a70: Image Version: 6.1 2b34.1a70: SizeOfImage: 0x11f000 (1175552) 2b34.1a70: Resource Dir: 0x116000 LB 0x528 2b34.1a70: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)] 2b34.1a70: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)] 2b34.1a70: ProductName: Microsoft® Windows® Operating System 2b34.1a70: ProductVersion: 6.1.7601.24475 2b34.1a70: FileVersion: 6.1.7601.24475 (win7sp1_ldr.190516-0600) 2b34.1a70: FileDescription: Windows NT BASE API Client DLL 2b34.1a70: \SystemRoot\System32\KernelBase.dll: 2b34.1a70: CreationTime: 2019-06-22T05:24:19.691593900Z 2b34.1a70: LastWriteTime: 2019-05-16T15:07:06.536000000Z 2b34.1a70: ChangeTime: 2019-06-22T08:53:55.615932400Z 2b34.1a70: FileAttributes: 0x20 2b34.1a70: Size: 0x63c00 2b34.1a70: NT Headers: 0xe8 2b34.1a70: Timestamp: 0x5cdd7d45 2b34.1a70: Machine: 0x8664 - amd64 2b34.1a70: Timestamp: 0x5cdd7d45 2b34.1a70: Image Version: 6.1 2b34.1a70: SizeOfImage: 0x67000 (421888) 2b34.1a70: Resource Dir: 0x65000 LB 0x530 2b34.1a70: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)] 2b34.1a70: [Raw version resource data: 0x650b0 LB 0x3ac, codepage 0x0 (reserved 0x0)] 2b34.1a70: ProductName: Microsoft® Windows® Operating System 2b34.1a70: ProductVersion: 6.1.7601.24475 2b34.1a70: FileVersion: 6.1.7601.24475 (win7sp1_ldr.190516-0600) 2b34.1a70: FileDescription: Windows NT BASE API Client DLL 2b34.1a70: \SystemRoot\System32\apisetschema.dll: 2b34.1a70: CreationTime: 2019-06-22T05:24:32.749712500Z 2b34.1a70: LastWriteTime: 2019-05-16T15:06:08.558000000Z 2b34.1a70: ChangeTime: 2019-06-22T08:53:51.022153000Z 2b34.1a70: FileAttributes: 0x20 2b34.1a70: Size: 0x1a00 2b34.1a70: NT Headers: 0xc0 2b34.1a70: Timestamp: 0x5cdd7ca9 2b34.1a70: Machine: 0x8664 - amd64 2b34.1a70: Timestamp: 0x5cdd7ca9 2b34.1a70: Image Version: 6.1 2b34.1a70: SizeOfImage: 0x50000 (327680) 2b34.1a70: Resource Dir: 0x30000 LB 0x3f8 2b34.1a70: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)] 2b34.1a70: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)] 2b34.1a70: ProductName: Microsoft® Windows® Operating System 2b34.1a70: ProductVersion: 6.1.7601.24475 2b34.1a70: FileVersion: 6.1.7601.24475 (win7sp1_ldr.190516-0600) 2b34.1a70: FileDescription: ApiSet Schema DLL 2b34.1a70: Found driver SymNetS (0x2) 2b34.1a70: Found driver SRTSPX (0x2) 2b34.1a70: Found driver SymEvent (0x2) 2b34.1a70: Found driver SymIRON (0x2) 2b34.1a70: supR3HardenedWinFindAdversaries: 0x2 2b34.1a70: \SystemRoot\System32\drivers\symevent64x86.sys: 2b34.1a70: CreationTime: 2019-07-24T05:40:43.014013900Z 2b34.1a70: LastWriteTime: 2019-07-24T05:40:41.473915700Z 2b34.1a70: ChangeTime: 2019-07-24T05:40:41.473915700Z 2b34.1a70: FileAttributes: 0x2020 2b34.1a70: Size: 0x18650 2b34.1a70: NT Headers: 0xe8 2b34.1a70: Timestamp: 0x5a95cc4b 2b34.1a70: Machine: 0x8664 - amd64 2b34.1a70: Timestamp: 0x5a95cc4b 2b34.1a70: Image Version: 6.3 2b34.1a70: SizeOfImage: 0x21000 (135168) 2b34.1a70: Resource Dir: 0x1f000 LB 0x3c8 2b34.1a70: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)] 2b34.1a70: [Raw version resource data: 0x1f0b8 LB 0x310, codepage 0x4e4 (reserved 0x0)] 2b34.1a70: ProductName: SYMEVENT 2b34.1a70: ProductVersion: 14.0.6.27 2b34.1a70: FileVersion: 14.0.6.27 2b34.1a70: FileDescription: Symantec Event Library 2b34.1a70: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox' 2b34.1a70: Calling main() 2b34.1a70: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2 2b34.1a70: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox' 2b34.1a70: SUPR3HardenedMain: Respawn #1 2b34.1a70: System32: \Device\HarddiskVolume2\Windows\System32 2b34.1a70: WinSxS: \Device\HarddiskVolume2\Windows\winsxs 2b34.1a70: KnownDllPath: C:\Windows\system32 2b34.1a70: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports 2b34.1a70: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe) 2b34.1a70: supR3HardNtEnableThreadCreation: 2b34.1a70: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077b73710 pvNtTerminateThread=0000000077b99db0 2b34.1a70: supR3HardenedWinDoReSpawn(1): New child 2998.1c8c [kernel32]. 2b34.1a70: supR3HardNtChildGatherData: PebBaseAddress=000007fffffde000 cbPeb=0x380 2b34.1a70: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077b30000 uNtDllChildAddr=0000000077b30000 2b34.1a70: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077b73710 2b34.1a70: supR3HardenedWinSetupChildInit: Start child. 2b34.1a70: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms. 2b34.1a70: supR3HardNtChildPurify: Startup delay kludge #1/0: 526 ms, 39 sleeps 2b34.1a70: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION 2b34.1a70: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000 2b34.1a70: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000 2b34.1a70: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000 2b34.1a70: 0000000000041000-000000000004ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000050000-0000000000050fff 0x0020/0x0004 0x0020000 !! 2b34.1a70: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 0000000000050000 (LB 0x1000, 0000000000050000 LB 0x1000) 2b34.1a70: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [0000000000050000/0000000000050000 LB 0/0x1000] 2b34.1a70: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/0000000000050000 LB 0x130000 s=0x10000 ap=0x0 rp=0x00000000000001 2b34.1a70: 0000000000051000-000000000017ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000180000-000000000027bfff 0x0000/0x0004 0x0020000 2b34.1a70: 000000000027c000-000000000027dfff 0x0104/0x0004 0x0020000 2b34.1a70: 000000000027e000-000000000027ffff 0x0004/0x0004 0x0020000 2b34.1a70: 0000000000280000-0000000077b2ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000077b30000-0000000077b30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077b31000-0000000077c54fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c55000-0000000077c5afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c5b000-0000000077c5bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c5c000-0000000077c63fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c64000-0000000077ccefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077ccf000-000000007efdffff 0x0001/0x0000 0x0000000 2b34.1a70: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000 2b34.1a70: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000 2b34.1a70: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000 2b34.1a70: 000000007fff0000-000000013f71ffff 0x0001/0x0000 0x0000000 2b34.1a70: *000000013f720000-000000013f720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f721000-000000013f791fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f792000-000000013f792fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f793000-000000013f7d9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7da000-000000013f7dafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7db000-000000013f7dbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7dc000-000000013f7e0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7e1000-000000013f7e1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7e2000-000000013f7e2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7e3000-000000013f7e6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7e7000-000000013f82efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f82f000-000007feffe2ffff 0x0001/0x0000 0x0000000 2b34.1a70: *000007feffe30000-000007feffe30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll 2b34.1a70: 000007feffe31000-000007fffffaffff 0x0001/0x0000 0x0000000 2b34.1a70: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000 2b34.1a70: 000007fffffd3000-000007fffffdbfff 0x0001/0x0000 0x0000000 2b34.1a70: *000007fffffdc000-000007fffffddfff 0x0004/0x0004 0x0020000 2b34.1a70: *000007fffffde000-000007fffffdefff 0x0004/0x0004 0x0020000 2b34.1a70: 000007fffffdf000-000007fffffdffff 0x0001/0x0000 0x0000000 2b34.1a70: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000 2b34.1a70: apisetschema.dll: timestamp 0x5cdd7ca9 (rc=VINF_SUCCESS) 2b34.1a70: VirtualBox.exe: timestamp 0x5d28530e (rc=VINF_SUCCESS) 2b34.1a70: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports 2b34.1a70: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports 2b34.1a70: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports 2b34.1a70: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x2 cPatchCount=0 2b34.1a70: supR3HardNtChildPurify: Startup delay kludge #1/1: 525 ms, 21 sleeps 2b34.1a70: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION 2b34.1a70: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000 2b34.1a70: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000 2b34.1a70: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000 2b34.1a70: 0000000000041000-000000000017ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000000180000-000000000027bfff 0x0000/0x0004 0x0020000 2b34.1a70: 000000000027c000-000000000027dfff 0x0104/0x0004 0x0020000 2b34.1a70: 000000000027e000-000000000027ffff 0x0004/0x0004 0x0020000 2b34.1a70: 0000000000280000-0000000077b2ffff 0x0001/0x0000 0x0000000 2b34.1a70: *0000000077b30000-0000000077b30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077b31000-0000000077c54fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c55000-0000000077c5afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c5b000-0000000077c63fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077c64000-0000000077ccefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll 2b34.1a70: 0000000077ccf000-000000007efdffff 0x0001/0x0000 0x0000000 2b34.1a70: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000 2b34.1a70: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000 2b34.1a70: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000 2b34.1a70: 000000007fff0000-000000013f71ffff 0x0001/0x0000 0x0000000 2b34.1a70: *000000013f720000-000000013f720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f721000-000000013f791fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f792000-000000013f792fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f793000-000000013f7d9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7da000-000000013f7e6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f7e7000-000000013f82efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe 2b34.1a70: 000000013f82f000-000007feffe2ffff 0x0001/0x0000 0x0000000 2b34.1a70: *000007feffe30000-000007feffe30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll 2b34.1a70: 000007feffe31000-000007fffffaffff 0x0001/0x0000 0x0000000 2b34.1a70: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000 2b34.1a70: 000007fffffd3000-000007fffffdbfff 0x0001/0x0000 0x0000000 2b34.1a70: *000007fffffdc000-000007fffffddfff 0x0004/0x0004 0x0020000 2b34.1a70: *000007fffffde000-000007fffffdefff 0x0004/0x0004 0x0020000 2b34.1a70: 000007fffffdf000-000007fffffdffff 0x0001/0x0000 0x0000000 2b34.1a70: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000 2b34.1a70: supR3HardNtChildPurify: Done after 3037 ms and 1 fixes (loop #1). 2b34.1a70: supR3HardNtEnableThreadCreation: 2998.1c8c: Log file opened: 5.2.32r132073 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100 2998.1c8c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077b30000 g_uNtVerCombined=0x611db100 2998.1c8c: ntdll.dll: timestamp 0x5cdd7d10 (rc=VINF_SUCCESS) 2998.1c8c: New simple heap: #1 0000000000280000 LB 0x400000 (for 1699840 allocation) 2998.1c8c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox' 2998.1c8c: System32: \Device\HarddiskVolume2\Windows\System32 2998.1c8c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs 2998.1c8c: KnownDllPath: C:\Windows\system32 2998.1c8c: supR3HardenedVmProcessInit: Opening vboxdrv stub... 2998.1c8c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk... 2998.1c8c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk... 2998.1c8c: Registered Dll notification callback with NTDLL. 2998.1c8c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll) 2998.1c8c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll 2998.1c8c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000: [calling] 2998.1c8c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust] 2998.1c8c: supR3HardenedDllNotificationCallback: load 0000000077a10000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0] 2998.1c8c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust] 2998.1c8c: supR3HardenedDllNotificationCallback: load 000007fefd800000 LB 0x00067000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0] 2998.1c8c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll) 2998.1c8c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll 2998.1c8c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a10000 'C:\Windows\system32\kernel32.dll' 2b34.1a70: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 164 ms, CloseEvents);